{"_id":"@redwoodjs/auth-providers-web","_rev":"202-71c8a83c4a81b40ac84bd39daee584c9","name":"@redwoodjs/auth-providers-web","dist-tags":{"latest":"0.0.1","canary":"4.0.0-canary.370"},"versions":{"0.0.1":{"name":"@redwoodjs/auth-providers-web","version":"0.0.1","license":"MIT","_id":"@redwoodjs/auth-providers-web@0.0.1","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"9e873abbb463eab1efad6813fc58e49b097b828c","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-0.0.1.tgz","fileCount":47,"integrity":"sha512-rX4LNtpJAJdtRhq2MEZa2rEOSTaU2l4Hv84LTudOESgd5OnS2s5sGIR0RyYbW97AMMQAKuIeFptxNO5fRroqSQ==","signatures":[{"sig":"MEUCIGf/m5NPGN3s7vMJhT5LkQ1gb1Umh24wEDr0ri9IcNulAiEAwFZeiZNkTElZle0R7Z7k0tJ3v9/6RYJnz4BnFXMQHNM=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":73910,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjSISoACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpJKw/+IrZ2yvyLy9o05jItjF2edHUcu/UszmU8ZKslQfZiwu7JJCap\r\nXfuYDZZXp2tR2LyB5kqPq4VHsfuvjk4DbCsQujyHIDDqEIEIFRyrcxrzQRib\r\nkP6ylH647JyhmmP8ea6fzSskUsupCdfwTE/4gUwHmWKEaCo2C9avYInhwBk4\r\naW0BY2bQu1bY6j6KL/m2JD5ZWVzGC68tHsVVX2kylQ9MMBJu/DZ5lbp1hy4E\r\n0yVqsuJZsP05WkSensQTUr7m9sRsV9ICNxVBr5MvX/ZBu6CuLval6zJ9av+j\r\nz5Gw2ryVZi9kYLMzZyK+9LZ2GOK/knQeQi7scprdzg8cptKr01vZhVRJ75+j\r\nqooGd/9HDW742/+k/A0xBlPrwLGGLapKFlpTf6tThNKvXu8Us40aj3HLiwW+\r\njrB5UwNs4rZoepWJwYy/+FDMV8gibe2OLn0LDitaBpOenpBQYCjOOErQXy7d\r\nSdxg0C0JttzXf4AUCzJHA6eyh8vnpf/uJlvP+e8fnBEM9K1mjXfuFvrehdHy\r\nROA4BJ3s2rWAg729Z/+Mqd2CiQWtziZUannzPyrI3RBQBdIrz1zhX/tWg0do\r\nJDwKXo4FRa0m3R5az0mkcNyN4jCTO1AEIxPGjrqlWb1kCqUEOuLbxPkuqw38\r\nVXIxnzu79/nZf4xDGFtzfn6u+M8HUuc1Xc8=\r\n=YJM1\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","gitHead":"3905ed045508b861b495f8d5630d76c7a157d8f1","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"jtoar","email":"dominic.saadi@hey.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"8.15.0","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"3.2.0","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_0.0.1_1665696936211_0.22709734543126525","host":"s3://npm-registry-packages"}},"3.2.1-canary.123":{"name":"@redwoodjs/auth-providers-web","version":"3.2.1-canary.123","license":"MIT","_id":"@redwoodjs/auth-providers-web@3.2.1-canary.123","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"b09a146e68f2a1298c1f9771a116eea5f6c24ed8","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-3.2.1-canary.123.tgz","fileCount":49,"integrity":"sha512-GWh11ueR30IT8RrCJwVWJj+/T/7w8/SPZWhYmSfIbMB47MSaEnsuvzCip0PLEOFVVoa0bS/D52EUcQmTxchyhw==","signatures":[{"sig":"MEUCIQDBabknLBDT/0g0fLCsJffG7h0GvATw8hiHSENEberkgAIgRRiW7RQDPToWEoMjiIuBn18ly9CTLC0T0fL8dIoXsxo=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248294,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjSI8hACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqP4w/9E5vijxw0YzYDXUndSn9v+2R6mvQKbbBIdsBpXgU0C0NR8Le8\r\neeEW/JxOs3eYMb7tJbnvEaR7KoaWON5ayz78jahge79aus/GTaWG1IH9j7Vw\r\nSlK0DMx8B356Z0sP5f4G7Zj/zptfW6rG7Mmy2i9l1igqgRoiRqw6UBOKXVFj\r\nvgNxps3h/v1bCR4FEVg/R+66EDfG9i8b+BmpS3RdeGk2O/IfLCb8hf3QUDP/\r\nXs6UGGIOQ42R9NyPzXP4bqFq36I2QgB+2mlV4uZl0zxI4+BjxTseydzP1hqH\r\n3Y0fAwxnBBjpj3nzaDjMubPXa9YoXlHhl0kU8HlEZ6/6rZHjX6hjhj9VVMss\r\nWMl+T6sbKZYcG0Or1ZvW6aZi7f5zka6OxdVfuP5nh4ExmOdJmI5FjtieE2+I\r\nYSrIUlWIEV9hFZin9yjrldIPsRoc6GKIeq3HaMTed74VKACtYm8mZb9pGn6J\r\nu6AxBzKIJIbQ+XNkc4EEApXIsM+KYjxsyEAOWn5G3fLWASEp+ZnG4DxfB39Q\r\nzb3KIFoF64RLfLlJAnY0haG9WjlYiVPJtWqwW5BGIYPQBBA3cPNh+AgmJUsM\r\nJi99aeR6ar6YYYIJI52G5eBV/y50aecrTpdtIWLztNsFynKZgMVLW8rrgrQb\r\nhCKaotwYwndAnfdQv70zC1jC3ziikOEhMfw=\r\n=vomp\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"79adb685eed4a01a79abb4b24ce17b312b4c79a9","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.123+79adb685e","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_3.2.1-canary.123_1665699617154_0.20872207942396082","host":"s3://npm-registry-packages"}},"3.2.1-canary.124":{"name":"@redwoodjs/auth-providers-web","version":"3.2.1-canary.124","license":"MIT","_id":"@redwoodjs/auth-providers-web@3.2.1-canary.124","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"6245b89bc72ccaefcf669821d3636aba23dd7df7","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-3.2.1-canary.124.tgz","fileCount":49,"integrity":"sha512-wV+SUD8muDaAuLXDL9itFQE/zQwOctWbGOMji5I+s9nfaGnKmESjzqcEWMjn8gvE9aXF4lRRUqNNuAKQZLhy1g==","signatures":[{"sig":"MEUCIEkqcVMJyQbv2nvFC0ghoFHCorOj/FOd1HwpaG/K+DCAAiEA7k3V8KIK0GiuEpTM5x42prpID4ZEVzDPo8VoeOjcNJk=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248294,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjSJ+FACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmqkng//Z4+CmN9+y+hs56oTyp2d1acPZmrQEV3GZbDtJdgwl+q3iBnh\r\nrixViSTz1TF7MoTISgci2yIqz0+GMRwmHTPGWAI08J6rJyaZjvcSSXcSCXdj\r\nSr4ZW+BJ262WlMPUDXVaSby9O5R2d6vH6/DV2hTlJ9eTmeRfTP6vpWM+RxPW\r\n5vQYM1UJnEt3eBNLxPK3J5lbfxwkdXO0WEvm+2kYtohpzU/tHnV0HRCS2a29\r\n4OogrSGp+JcArOtuvqqyXfmGWCcpEKcbC2sFQusJGUBMVrtfKFoP2HOcEqlQ\r\nZ4JvQ67oEiB4g8XK9W4ibHhuOGsPHPmZZe1O3QYGcKwZGDuOY2OdHSmDBIqe\r\nTWs11qFr3LsFociKHhLAO37kW03BXEaX40BMJbAGBluLQEdqZmdFj8jIBNec\r\nDDzi4gMwL3cXB+rB4owt25WdqjXmUqSkQ0Zaf/fv0xmv6MeGYLrqME5ksMlW\r\nAVTXBweF0XZVv9r4MBts7+sE+LfWXP/sMouUOCL4sDj6kN/aA0Qteh4/nD41\r\naZ4pPy6SWbmPZvR3niCn+mrv5vNCGRz2VKnZkR+FyPCgjBh+qkl+6GJUytZI\r\nGL171KCnTueUujyWex9wuIOP5Hv+m70VYSNCysRmMEet2rgsbVzrfAqKwgyj\r\nmzPYY+0wv9tvRUng9JenyOfs60UW3waWruA=\r\n=HQJ+\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"c2f863d680f1d6bc1582676a46bb51605f9afbf5","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.124+c2f863d68","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_3.2.1-canary.124_1665703812949_0.8578406298628376","host":"s3://npm-registry-packages"}},"3.2.1-canary.125":{"name":"@redwoodjs/auth-providers-web","version":"3.2.1-canary.125","license":"MIT","_id":"@redwoodjs/auth-providers-web@3.2.1-canary.125","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"0b59945b89375d925309469b3d6aa8f036620b08","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-3.2.1-canary.125.tgz","fileCount":49,"integrity":"sha512-0nmg7YB+Fzd8e5nj1PfR/H9p1CLWcXG5m+ql+b+vAfYPR6Qp6HuL8mHUPKTR1li4ih/wYZDvx/IBrNFQ+6CE6w==","signatures":[{"sig":"MEUCIGA5O4LaWb+uh8xXut+h7Zg/nG7iOYJz5QJUYilFdx0cAiEA5ZjU2cMVTg5oaXaVE2bOvX9oI/F+waEhnTbKjIHeATs=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248294,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjSKsMACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmo53A//d/2RFzkb5oRj6mtaFfOxcB+iP6ABHziiQSp/M6KLfz7jIWT4\r\n1Qy9gXIizfH6l3FERWrIYevXmIXTZ3J425Ovqwu9mZ9e3MzlHIqFCJrLXUSm\r\n90Wl18XS4RKJkpk51AGtb4NrVYeUJK0bVVJHmJgjb4fUPZx8WNlk3yEQv+3c\r\nxOkSOOm4VrAzc5ZV9pNEQ91950igElqM8BJUZqrfqXcXOSHIOQehBnRxioP3\r\nBfWthoYdXysxmUSGjeadVG5wWzxVx+FLYR1UHE66NpPC9Ut7PYUW5xxBr0ue\r\n+5ylf6Ugx8T4Ahxvct+uuiQyEeQWs/QGHfCWeW/Zfv7keA3ABELx7KZ95io+\r\nf3ODl+icgSzponY5o7/0C4wK94a/unkok85tkMXS3iHDehIUDDMWlQmUhvxW\r\nfg0SufJWNrTdfjI6SbUtQa9q45B+4ukGJF1hDWNinujwrJGFAGAY6a8DCnHQ\r\nVDRk76c4d+6H33wbJ7AFNH+MhcAsPuuRXw0CwDLP7fxdz0ePK02ugsgR4FdK\r\nDlHSyafDlqHHcAip4tQdhndbn1zAlCp3ZYJoXLQYcL+qUatIyHZt+P/KdU4P\r\nA2fivCxuFLmwgjEouFaMgXrb4+KMk28LoLY7woIVO/BTK/P5EZMIEWecvFFN\r\nFiRzvK2pJRBJC8zt5qcdqjXYDF6cDMb3xjo=\r\n=R85e\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"fa6546440e2b97519b030817cd89a613d0076769","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.125+fa6546440","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_3.2.1-canary.125_1665706763884_0.728701200424523","host":"s3://npm-registry-packages"}},"3.2.1-canary.126":{"name":"@redwoodjs/auth-providers-web","version":"3.2.1-canary.126","license":"MIT","_id":"@redwoodjs/auth-providers-web@3.2.1-canary.126","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"7b462a549045e2d17bc5b58077039ba206bbdbce","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-3.2.1-canary.126.tgz","fileCount":49,"integrity":"sha512-vPBgocU/H4V0j3M56Wf/63beG6NAeWKZpQdqYq6WBaQ8p1Xo+0anWVTKpPESW/GwDvkGIxdnbvjqMSTGhLd+sQ==","signatures":[{"sig":"MEUCIEynf3F695M4Vh+PrWbiLm0jq1BV2dvt0ixWSrQF2iEgAiEA3bjsn7eqojMVQDx89kbA+7Axcd/e+Q3lSVHkVXrVSD4=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248294,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjSLLtACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmrl7A/9F+2aAz5kJccKAPMcQ+fpzskcLv1fHr9C314/lC2BmxX+591n\r\npBA9RVntJXTfsBlAp7GN+KmK+qWyXYwJMbhW6i7M3NlTuOHQWRn5ZfRTQ7AA\r\n9sovfea2fzOMZ+ISAP3G2v9OrljVAXmV/Txe9k9qUIpZSY8Kd3kWxFRsThbD\r\nYHKKVW/SQjqpYsBKkO11oNljNlpxD6zx8mW61QiA4ZSsqGAPho6WYHDuqhDI\r\naJDrvnRM/821dquYplbasjOVmJY9ENk7T9EKZ8r786L22KPH9FtzI0TE4/dA\r\ntsnF2u/Tlxp9upKu8xA4p3C5L8pnzHga7A7LxiJX2B4Ozcisu6TC7oBGR54n\r\ndjeVm0p3AMxBU9A5odOgy8yYFP9NlQLy37VrUV9vgsBubR9ZzrzL7cQFsHmU\r\ngbX7LcXfl7tc3BLx9h0Kxw3wSRqAp0GBu7FAOfFipyPM+xZlY5GEbLofQbkv\r\nQZcaoGBNgoZekybEMbOYl4Bi04D7phqC2w1nIQZUnSiHKZI2gUZ0i/UlOTHK\r\nGMBeMn1tr+AqVao6EkdvU3xWnYp28UmvAWytMoj6BAzqRM/V0xo1nTdZS7ql\r\nOKwEoUdu+BrPyuBiyC394GeeDu1kaTv8VDqDBkY/wZVXdgJk8lO/O5LYKl8b\r\nRS0x6ZhDorlnm4D6k2h8Ki6POLS4gY5hYz8=\r\n=qgZy\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"8a107fff29f3da11ee218e741eb4131d60ec217f","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.126+8a107fff2","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_3.2.1-canary.126_1665708781435_0.05360380126382003","host":"s3://npm-registry-packages"}},"3.2.1-canary.127":{"name":"@redwoodjs/auth-providers-web","version":"3.2.1-canary.127","license":"MIT","_id":"@redwoodjs/auth-providers-web@3.2.1-canary.127","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"3e2637ea51800267fc6bce9ff2fc7579ee567cf5","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-3.2.1-canary.127.tgz","fileCount":49,"integrity":"sha512-GpQYtKJwMt6OTKRZlXf+Y8gjih8U34l9d95lgMorAEyHVLpI2/OaJGzfof/d3swQj6lauQwBNgZQVhm1aWNevw==","signatures":[{"sig":"MEQCIELHQDaZdVKfUsxRfSXEn4rfSWmsFkGVL7p+JwgmUyV9AiAw4h2xjAHM22BgPIXgJAIYgWGPqletxbJxa+DSX3SJqg==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248294,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjSLqdACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmq8MA//ZiUCpMgeG7HpTKCw/x8ntPSc5G7xH9QgHcTU3j7sTgyESHxs\r\nxPjc42ZDhIVrqH04htYL/fsfIQZ2Euhux8jdKUJPCajMWn+N8hXrOJ4fnst/\r\nd0baM7CFuX7q/+RCP8MgwMT5jzh4SAK3pwKumGeUs2DhvPwGrVjv9R95xAYD\r\nXNh8n7NGQnO+FOOxqsiXta+73qisiG+BMya9Hox+qjNu+9l5ZEQLOx2H5Vli\r\nmtFoRtPrzGJie1DTA1US95tAZqLqTybdXAAt0vKgRoHGCamh5txpKcSUyfOn\r\nmTWYd4/w34Xk7rFKtLLOUvrBA8Ofj2CqNwV092faHXSAuXxs6NrurO7GoQ+2\r\nIv0yf82mTQrdQA5GRu3hQnYSCgA1TvyJZiSPeXLxyqqTsWwdHP025bdzjS4w\r\nhyw4W0io38X54Qw7t5LFo2n9oUuFF7G4GzEJgzHcqW9DUDG1y0hmuE0eYdmD\r\nvgTj5C8YjMJL5WehcfuIYs72QxZFpqfkLEKFSmBaQDmHKsKyz9w316KwXmsx\r\nytp7ZL9gRQTDmgK2XWc3+LX97BzSQAawKfodDkzOovVkSXctad3tkXIz6Lzm\r\nCFAStbPWt2UMJNhPpyXuls16ZQaZMzu1hoj5T4bcC22nTGxdCuE5ULd1w6S5\r\nAuRwuN7YcwM0L+a2NvPRrwCGA8cA1bFUL1w=\r\n=0iHX\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"48725cea55ebad9914a748a9a45b60d360697682","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.127+48725cea5","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_3.2.1-canary.127_1665710748598_0.4458488286513067","host":"s3://npm-registry-packages"}},"3.2.1-canary.128":{"name":"@redwoodjs/auth-providers-web","version":"3.2.1-canary.128","license":"MIT","_id":"@redwoodjs/auth-providers-web@3.2.1-canary.128","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"6440127837b37ad593f2f042005a9289be0d7eb6","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-3.2.1-canary.128.tgz","fileCount":49,"integrity":"sha512-bBJ82GPlJVxn1Ip96nyZUNCa4Y4rX6so+6zMdaXs7sL1Et8q/zhxfBl+N8gMwa1siQ0En2cDXstuPYaKNUkN0A==","signatures":[{"sig":"MEQCICULPQ1duJU6fsZCkQ98NI/esN3BkQpVubbIUObr/vHXAiAIlz3pkaTbjRVDfU8X44+JYtUsa1g1xertw3HUqAAepw==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248294,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjSPaXACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqOjg/+PmYH8xT8EDOV2GcmiJ0C5DDw1fazElz8YnIWcbM+YtIiVMQJ\r\ngs4nHwU7140qyhcjC2jGlBrbccBw7GcgV3P9GBuAAKGA0bgO/Hezqo3hdLZk\r\nwY5yT8mWN8CMwdXT6wYz6hSRUm20gWtcKDYKhXfsIc6iyNUOi6N/uHtqEbpv\r\nrrfxAKoll6BRGG/4jDOI+I7NsEkVQcpxIfOjgXn5ShHxI1wkYg9upW/G+p3N\r\niq1kYDLmDjZdGqbNiPEoyGv3I/Syydb/ORQsRPYsZKxofW8TiEUbQ/5i/2O7\r\nHG6SLq/DFKqUCVkX8JCPPttxQzawtbn/usYA0Ob85G+ruQbwvH3havcc+mNI\r\n8uuyAEiELGrGwkBAiS/rf8qPy6PaMYSqcl61SxDD1We80TCh4lLGZvA4/Y0t\r\nb+B8rmlsdjLD55SKl6WK2w9fVoiJEknb4az4hewLjVJ07eVWq3G7WAs+ik5V\r\n01aRaReRKURuB23g0+tTwtT+i2uVkbjJeGcZmKvy7mLTtjaw4Bbk6E7bAP8u\r\nB1jpd9ACOB6MhvnE3qKdYbm+CWj7qRHKr0g6PuYNAou3ghaXOl2ZQ1lhIzau\r\nrRxCLiGSLOTUxXljgLmk3XtjvNPzcsCSpglyYnzlAtCSP6A2q1PfGORqy9v3\r\nHZAbBbIEwVaI15ze04PcS7nNFLRIbcsrsV8=\r\n=0EHZ\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"e956bf37219af9c767c099bbbe27c772521e93d3","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.128+e956bf372","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_3.2.1-canary.128_1665726103617_0.5210341194571877","host":"s3://npm-registry-packages"}},"3.2.1-canary.129":{"name":"@redwoodjs/auth-providers-web","version":"3.2.1-canary.129","license":"MIT","_id":"@redwoodjs/auth-providers-web@3.2.1-canary.129","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"dd2823cd52ea7026a294c1f9c3e04631b1771ff7","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-3.2.1-canary.129.tgz","fileCount":49,"integrity":"sha512-uDfP6egbgC4od4pcumdwCBVGui6/fphHEABBqld08ko15rxB30sLnmS+V7cnXG1I4UOReubem7il3sdQOfCwzg==","signatures":[{"sig":"MEUCIQCz2YqdNLoxT3gNLS9Do+c0Ha1N3pwkDGN4rAQLVPfpCAIgDJjbzLqVglgY6hAMHP+z8wLVlIG9VNJ5JKHZcWhREM8=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248294,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjSRjPACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpEkA//Tn9KEgqE9LF81RbAy2HeXXD43IU26wVZeTKAOGZGTa/3z7lv\r\nmD1KWYslsTU56JRzeLd0JL4Ml6QUS9wRDlJyDi4LyFAU9YdtUdxJm2uX8wIw\r\nWsw+pYu6YEStIogwZU8KgYP8s3u3QoVfitqw5azHPHGt13oANOU/6Sm+NCoG\r\npOA/NqTWO0Z41xdPSjCevRLZ62EpDTmD5He6JvvD5ODFe4hlEQQieWzuJWgy\r\nA1+IMgAIL4Y/+hEDcj0jQ4vzHoXPgkLrw+cj+M+rYT7sVo5c/qlPa2+jk76V\r\n28tAGn7lv1Vu83JGbdbHJD//t63FfkRKqIlUWV54dl9b3HCV/Ql/q7qn5as/\r\nF9x/kJsCjsFh7YNM5HNMqShfMcWQUAoFGtMEzpK42lZwlR+aWdsRCBKVkYGS\r\nELsGfuHrz9q6S6g/6VBL0RM8BTKX2EMv1Jno+kF8+sUzxOqMgJw8nhCJw1lT\r\nhNaLu7tYLGUESRj+u3xuDdECiN19TihLVT/lGGqFmrE8K9HskxyTdSq9y/49\r\n+abaNfWrbTZCj6SzdA3cap/xF1hXNyGIWKhD+6xlvvLr3PUCB2atK7ead5Fu\r\ngqc4cG04fVx8HdMfunl6z5K0zIu9k0ZzN7sOmmTDNcbjo8RlrVhQ9yU0LIfr\r\nnXW3hUFDdAQTJsQwDnVfLnaUYJ6TRzAR1dE=\r\n=hpn4\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"53945158ca21301989511e287d1f3779eb66166e","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.129+53945158c","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_3.2.1-canary.129_1665734863182_0.8809989071218594","host":"s3://npm-registry-packages"}},"3.2.1-canary.130":{"name":"@redwoodjs/auth-providers-web","version":"3.2.1-canary.130","license":"MIT","_id":"@redwoodjs/auth-providers-web@3.2.1-canary.130","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"e163bc438d2c0fc7262e1f37142c0ce56dc6eda4","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-3.2.1-canary.130.tgz","fileCount":49,"integrity":"sha512-o4pWsFzn+IJdmaXJ5GdyhuqIUwNevsPpTyAx0abmMHOurxpIm7oSFV1JxOGB1+errRyR25n0GnE/z2D3Nxj2ZA==","signatures":[{"sig":"MEQCICxS4Ka1sE4B8NsXd02rFgVnSCu5hPG1Q2x68PJNO8lQAiBxSVnnFKdJXKuhSE9K9U4z5YGjb6FRV9DRy5fckl14iQ==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248294,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjSVPoACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpbBBAAkbAIBMHZTE9CPSlO7ki3IfY6C1Dx95WfVThmM4V1SQzSY381\r\n3zRCHT1HED2fbcuMcADGg3gIjDTfObXu8xbw72AcEOAIMmdgM3sgQGLy7g4L\r\nLLE0sFDRLAk+S944c/j+h40T7SgvHjfvhwP9bci3qs2/1712/bO7szyeuLk1\r\nkOswn4qLTmXqMOQ1oKzWTNIucs1iNoIqVsJMF6KTwF03WpGuXZnuPh+Otda0\r\nb6YNp55MO47pZe8KbGE/H6Oktc5JQ+xisRWZWEHKRxvxnk3bq9QCjer3CrYc\r\n548ZS3V83Ys3x1qgAh594YL9khYmjWg29EB1VDawJevB3icVPKG/gI1D/Uqr\r\nJFg0uSsAuZb9fVnxfCwHv3YitQHypMZYv/iEaA1t3NgvUqNaWZ5S5/XNne2P\r\neuRIWGvQCouktMVzREQtqCoLMHhyCgvQ9GM2KnMY4eieB5Wtz4Jq3iEBG6Os\r\ndiIA8iz7LwnXi5KmTXX/YDyw/CsuR+Sf/jXjevk/kFNFiozfNYuWQl/ktmCL\r\nkH3GF/FI14Fzek/hFpSPL9MgbSNEmo7yRjRsOjkLW3wFAU7aNJefCD6VUrgU\r\nsNJqPzIPvCicUXFL/FBsKWmkY3Brqf4elVrMtKX7gXLXwWlv/JSnnK+SXrXS\r\nlX0MPWDci1DI+hiF/WmFSXegCVYYdR9Tw1E=\r\n=EqF5\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"e01750d967682b8117374b0b8b96a31f56ebf426","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.130+e01750d96","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_3.2.1-canary.130_1665749992637_0.3027628197436074","host":"s3://npm-registry-packages"}},"3.2.1-canary.131":{"name":"@redwoodjs/auth-providers-web","version":"3.2.1-canary.131","license":"MIT","_id":"@redwoodjs/auth-providers-web@3.2.1-canary.131","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"6819cee2d61a02986733784f0aa88769a645c4fa","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-3.2.1-canary.131.tgz","fileCount":49,"integrity":"sha512-LOGQ7DSwIou7U/lFzq086CB6DmmNJwzv9iaaW+tbnVe63DGz/A6+fG35Pg4Rq/UUk6VwOwMQLwV8cOPYOtWNCQ==","signatures":[{"sig":"MEUCIQDngJLypZACyHa+j57I3g5XWl3BtjCj2MKhQrU8e3zuIAIgdL5PljRbTKt5s+rHo4SRYk7V49thRKh0r6Nz1j7P9aE=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248294,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjSVzMACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmr5AxAAmVDjuti5z3bBxebuHe3bbPVizunA8ms2xSuDOobYigD0ORqb\r\nVjSeskhDIgkpveB53CTIMeY3k4pF8PxYm0W19w28/foET5JExukMhjj+v0l5\r\ni3zWh4hxVaEAXaWixJaIZZa4wLd9KjHV4cbqSNSDUlH5b9wpbAUg58P288kx\r\nuGZa+ncZsHLr1OwMrIIDkfkyF0+SV8as8TFnhdh4oDBHvlLxLojFGpJv4dXj\r\n4Hv9ivyRLqiVfyT6ATKXMs+p1iY4eB+S9q35HksLYhQE92pN1MImIBzjUYM3\r\nskjy/HWWbmpqPKezOfdI571cKu9USSxfD1YFiI17sqpcPFOZVgfiv7uOu5IC\r\nTgLfl/mhlk2Fey5DN6/c47/JasOa19HOEcfS5SfqIXTJf7AHwV3xlPtyQX35\r\nQW1CEWoqQvxvj48/JEm+4tTQ3EsgLYSk4EAvSJr6GTn7hqXV2KRFQ/KkDRdp\r\n+osKO4kzvpEV2pEXcKGP422rMq1Hqaft8JSukbZoW3HvPDZDonL9AQEwKutm\r\nVEc/Y1AaSznnKPfi2Nw9bMzZRj77kwwn10V9KLpvGxq2BGahyf+Ry4zXqq3Y\r\nwX0yNzqzTueI7iitvja4NoMGQhHRBabD38/CrUXROQKMBY1dxPKSoiExIGvU\r\n2ot6d3fhOchY6KoFnbjyUhEkmQt/e5k1C8E=\r\n=ov0q\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"7fbd6ba32b4ff4f9170ec51d5e7744e308094b9b","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.131+7fbd6ba32","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_3.2.1-canary.131_1665752268214_0.5711228686448808","host":"s3://npm-registry-packages"}},"3.2.1-canary.138":{"name":"@redwoodjs/auth-providers-web","version":"3.2.1-canary.138","license":"MIT","_id":"@redwoodjs/auth-providers-web@3.2.1-canary.138","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"a8899a483dbd0c241d35eb6fd850ebcd30d9aad8","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-3.2.1-canary.138.tgz","fileCount":49,"integrity":"sha512-q9C4lvJ4GhkpSosybRNQsCzevwSon6q6g3g9v1aihCh1P6rRFzLh3rxHKfue9nK2XU2rS690C88R+UsB9ac4NQ==","signatures":[{"sig":"MEUCIQCC2pRDiiZZa4l8jyubGCfij1ZXxyr7jaS0n5KmJcjMbQIgbK6vfZmTfUaVGKKsP9noS5/amPl0RxCKCBgBbTMe3YY=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjS04NACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrkmA//fyQVtaGauvd/eZ7xi+eTgvS2lgFmu2A7SrSZ+Mbr0cPPQkBJ\r\no39ci4ka28Jl0KICrjHWZTl7IBh2Uh6/uyMOoeg5C8nRMtOFoXbutAGZd8gd\r\ngcWeOOpRlrqGGIPJvQ7iEW2IbI/dI2XIjDTbHL5uU+q80Dke0eprD5fJ6mu+\r\nRfI1BXMTak41QGb5vGXBLsamvTseTNDu9Wlp/uw2mcdNJdoW+a9wc2Ac+Gq1\r\nn79TwAHrhVZkuBDtBI5pxyGCLkchk6dvnpmQr6rln531NQxtELIU2Y5TYhk8\r\nLffHdF72kmCLHGdPoY7n0vJbP5hAVop9SP0bFdcLEro7IDyvDnOnk1pmnydp\r\n+/UlYUP5m8DtOwFPlz49cD4V+q3g1NGfxfYMSe6/vmME+KIioSjbM/T/0O5Z\r\ntrByhnZNmR52+lUMbzwqD5j9bdnQo0ZkjzKlvbflHKaxsvVZkPPvhJsc+YqZ\r\nA1dYydMJCv/oR38SeD+YWjRx2+7ku5kpTBWaMpmqV2MFOpKHRp8fN/G05rPC\r\ndCPx1UmFb81887HbNAeGcqHfHZV96uY/YZu+YxKUjUMGOCtbtIkShYqL4uHz\r\ne8qUkB7wRuYO7BoezIwX2CrMS1zt4bEnFUsjoTRTMdpFHrx3aKpfmFZRZhVd\r\nn8FLuuHHPG/WljFwk+nmE+1tWKNB1uPa9UU=\r\n=dh1u\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"7b877e56647c5b5baa5eaa888b35e942e4500e0b","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.138+7b877e566","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_3.2.1-canary.138_1665879565380_0.6794482847168533","host":"s3://npm-registry-packages"}},"3.2.1-canary.139":{"name":"@redwoodjs/auth-providers-web","version":"3.2.1-canary.139","license":"MIT","_id":"@redwoodjs/auth-providers-web@3.2.1-canary.139","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"5817af7f97222bdb6bcf5f93debf95f082ecc630","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-3.2.1-canary.139.tgz","fileCount":49,"integrity":"sha512-p9X2WUTHDebO6x78T8tO/GjJeiSnIeLnHkO2agXxn9JKlXmFDOkZBKdwKSOYNoP/hmvv5uFchN1mAW20MqJW7w==","signatures":[{"sig":"MEYCIQCr4ZebE+DBcKUZ5kRcWvbkB/teOcdy7yyh6/uscLHyBgIhALH+0TNCAlVzw6WJH7Y/gtdhMDW/VfnB8/YWt8N6PetV","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjWF4gACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpRpA//XC46j4jzPYzLN1Es9oCBMCGWv4xq5UiAFU04xdR65lDSGX97\r\nuOs5Q+B7d95j57bRpiIBfhDwVuey/u+9MEArWGLJlaEEtlKWyjvT+LaRAJz2\r\nXrGjaZsSQw9Rg2vL0+fIKXiCRFnK1OX7qJzdDNBmXShrRlkZtSwLGrdDADMj\r\nSxP3OTxR0KXraKYal4dlXgMKhSFH+v4bzYLwXieLBiH7flzf0YDfTKIMkUv1\r\nV000aMgdiroRNZMeZhGGybItyG2fPknZH31AmqEHlLLs44EKKnL3ve491JzN\r\n6xME3KCKRtr157+9fMGjXhugPYdrHmpJBgtTPqc/OtSNpkAZvd0La5bYwTGS\r\n6ADQOrqfx4FV4/SgbPf//k6QmgmrOSZoIqPwlb+jeEkPY/JTrHz9nzmEivDK\r\nbOTPRsDHR0kircMPPgUq2jTXtgXF2WvthjuT2Rms0VGJFoX3SgjZTyUUcf6O\r\noAWggIOgAswXrtj3dWQGYiA0/Clf6UB8Jdhhb6sA/qIA5dzrkewYXNcsISbU\r\n8CoDbR9Ki8WIyudh+Zz1VPkpDxymKpvpHCzwoDa03dVfPOPrRxOPNM+aE68j\r\nIDDSuFM8ZmRwYKgZj7FWdI0/Wd9TDSZYl3BiyT8ew5Lenfnh7kp6INauPAXs\r\nbuwfW4j56plHn0jJvePvcfiF8tlMR+HsKNY=\r\n=4+cp\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"c604f3899275a47bad0fe63f5d97f335dd7b36c6","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.139+c604f3899","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_3.2.1-canary.139_1666735648612_0.9383165175371135","host":"s3://npm-registry-packages"}},"3.2.1-canary.140":{"name":"@redwoodjs/auth-providers-web","version":"3.2.1-canary.140","license":"MIT","_id":"@redwoodjs/auth-providers-web@3.2.1-canary.140","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"1f99ca7c48f60293fd9d3aed6de84cd0a93eb0b6","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-3.2.1-canary.140.tgz","fileCount":49,"integrity":"sha512-Fo3Cyk0rDS0MA+NzLCz+kq5brOEM6uu2vAb+IgbubyMyZneeyZb2GlMwE+Y/xF2OcAgEkibP/ihL5tiyI1hiUg==","signatures":[{"sig":"MEYCIQDkDPY6B2v/lnO7pt9LXMOUp3RmbZXEWNy3ukrBUjUvdAIhAO9goZTe2T4zlk9SUTZph1b1dc/P1ZXnWcHcsmxckRDW","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjWcE0ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmqq4BAAj2s5n/atPgMX5Q97gdcCmrvKxD9fWWT5RujiIYOzoryU8X6U\r\n/pOz8HD0vqT52NAomeUst4GTT4O9bp19wlbUD5VXOLTEB9BZ1mg125Tn2/h4\r\nkTgx6T0AuH8pRIXgKURwyXC1YKptNvgDKm0d/NOMnS3bALhmfd0IbdDovqSL\r\nQX0MNZwpyWzTob7GUjfvsnQAvppNNVgNv9j0z/QouUp2rN2pTw28PnRKQ1ES\r\nyMc74WeqhayYlb5rU7cPTWycnxj8Hi2FWnzjVHzFLRGEPO4Z5iI2B93E/N6/\r\nCCP2QYpgTE59V4N8jANZDkM7sT9viTP8wbtCzJ8bRPkJvpEMW9p0tpuG3peO\r\nFT6qjv032Q1xg2ezJ4UnRdWmRYSl2BR7Dj0qZP2w5P4eG8sGDoNibaZQYUKe\r\n25nTfEoxDE5vKkBLGdSUbd0PK4USpnVaI+vZf0D9MpA2m1oN7A35gba0a7BU\r\nbb+T7zWNz44/HuUIzi1fImfhu3gtkgJLoHlSrbuCmsZvhRAXWh6n4YxfGxCM\r\nS8jetbqBlU+kT5eqfSuHu/U06OYt070dWhUOVzHxcR8iwPcNJNRWEphBUrqw\r\nGJL13BWAuQO1Xi7V2Tsc69yc9eBJuSrDVgcN7Zz9gcJsvYll9+B64y5D/Y3i\r\nElmywVt84YbKbN9G8PQWgQh2HIuJHyHgRKg=\r\n=o76u\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"971d22370910bcd7b7a484dd98a3a08029604206","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.140+971d22370","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_3.2.1-canary.140_1666826548220_0.07454772560206036","host":"s3://npm-registry-packages"}},"3.2.1-canary.141":{"name":"@redwoodjs/auth-providers-web","version":"3.2.1-canary.141","license":"MIT","_id":"@redwoodjs/auth-providers-web@3.2.1-canary.141","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"63156a55fb24bf8c0f0e67cfe47706e3c4b569a8","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-3.2.1-canary.141.tgz","fileCount":49,"integrity":"sha512-htai1ShM0tSXXid08Fy8jkX/GQpOAhue3N5l81ol51xprwOVtUNtF2MtIqu0YtGwUKoYaUJOofl/gpKOZdXeFw==","signatures":[{"sig":"MEUCIB8n6QKrrGoD+aFVjiwOV9eE2oyXr5qbHTlneqReREouAiEAhyD1h6vs+fobu+gShroWajJeZn9A/u6M5Qo054LUjD0=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjWcdBACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqNrRAAjHwo682abDb4Uix/QKRA6m39XNDbhWSRQurU0kgolZevtXB5\r\nTyVgelO6/uy/JasYAQISMuaPWOHYl3mfqIRs+n+QOkUHBq+sA97J9frSYy4t\r\nTdLtZXsAtkWbft/29ViZ3/GJu3ITABYw8/3Yxkmg31lNu5ynfIuowJtzOaUK\r\ngn9t7GkC8Yjj01yfv40LIlE2ulY7NumgsCeSXaStr3NCzK27pVbmyD6SVQ5t\r\nye/rqV5cIRfQfMJHfTn9YHK2il8mNy5lgkk1lQiNYJ+eWX5IRaMYYI46RmcV\r\naDrniQMy7+qgcENdACCiAJgA0tcCC7G9AebzxdS04oepsch1V0g0fIFO9/KO\r\nMevvOqfmihOrxmgXnjjMlOS8XUQucnFyKsc0SSwbDohQ6Ewnm6S2eIkFvZV9\r\nNHzeYXiTo6eq524kgE6UG4phDnYaFqd/h5y+UfWkn3aToMHCSlyICGJL1r+m\r\nFHbCr+7PtAwRyCphctxrxDW7Ar6MJdNxQYXzUKkL9U0IsrE4z/V1ivFXdZ08\r\ndhd7m1rqXishDj5PvdN0c7KgHl+1pkIPKQm9yz/VVbNpOB2tHlQYgic81Sbm\r\ncdCjDMOEQjvs4tP3kCABNnhK/V0/0npmSEcLlDWhWIbxl7XVZa7yrtNQuqFc\r\ng4aWzRzcXYz7oqupNouOOFkD/yUz170eQqg=\r\n=LGrg\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"570d7b49d1284194802d627278911fdd9881db0c","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.141+570d7b49d","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_3.2.1-canary.141_1666828097314_0.13981542292844118","host":"s3://npm-registry-packages"}},"3.2.1-canary.142":{"name":"@redwoodjs/auth-providers-web","version":"3.2.1-canary.142","license":"MIT","_id":"@redwoodjs/auth-providers-web@3.2.1-canary.142","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"109fdb6b42d33d8ee590be4368a6ff0a850c1e0a","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-3.2.1-canary.142.tgz","fileCount":49,"integrity":"sha512-R2jenNcLNlvtur9Xf41splr7H9DP6TRb+gu7TgZM4uDJO6PB0Ln+RlgFo7HO0naJw31eIZG3FovNxZ6WErpN6Q==","signatures":[{"sig":"MEUCIQCSFQZPA3yMK1JYzOEdrBYGKu5mGvdh3CP/tZJDpTL+yAIgecuO+XGxLRNBF/4DPS8ELTzpL+SzkKXkSLHO9TN4fvg=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjWdVFACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmr4ww/8CFr1Olf3kKY7yjS3HIK5UpbdQtkqrzkrpkxbIm6OVlPYrrdu\r\nhEYK4RMvLu0Vm97M5VweHf24Unp+A+bNPSUuXDN32HU/whe8Q73KL65zN0vC\r\ncXYZZzYMD1bNWODK3HF3ckYHqqs18179HFNUSR/muNyjvoGHHqr9mq+NMkHp\r\nCHXz6fP+GYJyUlKLXdxUUmnIDwRHolxxLVg65B0qRQ9ggkTrma8LWvkrc3Xm\r\nO1khnbT+uEkIx8yKr4KVTmkQtl8htXKQ5QbQ3SyTavew8Ze+Mf0I9W2GHvfc\r\n/vhYAbbxsOmEyHTX0tmnwANiFMaYZmrzslz5tepOk1UZc5qkSX1BsFndntTK\r\n0t+/aEqbyu3uoNZtzqzrboUCXyXDPTde2n+xAd1fhJ3i5HXW2ZEIBGyR2MOq\r\nDvjtDoFoN6hoeeUscBxwceZfqIy/0aWKUdQyNwqpuolyGGptwX0ChGSCfOVr\r\nt6CE+J44uqY2WxwGphJ+6GQVKd2wsaujJQF7lHAI499W5gbfbwzuGvRQpC+F\r\nccgbsK0SAKsHpw01MHi5nt+OiQxFbIA6O1xKdlWCPWHkmpGAfqOlLkuClT4T\r\n98L0E6NeS6gpPc2T8Hl6k+7zNFZgDf/+b74jj9dIfEZ6nriTxcXGy6ReEuFW\r\nRgAGOCrXLE2RGR00SzdltLGsgtoFskxtoBI=\r\n=/0kt\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"af8970fd52f22a25a9379289c70630370e616fad","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.142+af8970fd5","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_3.2.1-canary.142_1666831685225_0.604212448601624","host":"s3://npm-registry-packages"}},"3.2.1-canary.143":{"name":"@redwoodjs/auth-providers-web","version":"3.2.1-canary.143","license":"MIT","_id":"@redwoodjs/auth-providers-web@3.2.1-canary.143","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"793218e8a3f6c42b0fbfe80d07d054eebc8615c1","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-3.2.1-canary.143.tgz","fileCount":49,"integrity":"sha512-cC/krXVWDG4vAEn4/iCB4f9WrKv4EG1w9FyhXNhTcXKIFDSzhoaqTrO5i9RDklrnr7pxG/GgZESRkRbaBZtm6g==","signatures":[{"sig":"MEUCIQDQDE+P83+rBvzRveJmVBDbOIfYZyU2naAxS6CWCyt2vgIgHiXJ6i23Mzydow/V+MCUXjKS7X6yRBrNpoceEtiIMmk=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjWdeSACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoQhQ/+NYZKv7iyGZDWB9JsZGwcDNv93z4noj8VNS6Uk3VkXVGuDk1b\r\nf6EKtgnvHRvOqdE0Hk8lA2NTn/chJpN1sfXNDv/4TkqzbVM0aqm23KZuiD5/\r\ntfZ8uD0D8uStzdHLMG58Sr1mT5PD6jrOTQWdK5dTk8DFc8UidWRz7NaaNyTY\r\nw8g5Ko8rTnTf4PP8hQQ3DFJvbWuDrjUGAyqhONea7GU0dsks2+9vuUNBGIjT\r\nGx9e8NHPDIIoa1/b5myo4nzVo29q9+yjzPHn6M2GUS/jb0uHfc97KmfiP+0Y\r\nutlhtHDOqxs4RWwVWhW5VCDgIYa8KvOJML976zsBHh+0utgr4G1PizTiQlh6\r\n3drY5J9cfLDosHgJHzhladv60gQG9/kVEPsgWS/W/Ytwy5xJbWJP1HKhToPN\r\nCqs0mB3N/NBbbjcJ6HueaoDVaZqN1zrx8DWspPJbA25BkaT8btcvOOI6pW3i\r\ntVtx/Tf0JgVzmdEkq5QoqfM5mnc4pobmt6eHSzs21QgnlpbNMb5+IRD7srvX\r\n3/L+yyDd1BhZJ3+qoJn0dGjkEi7dbTog1FXpXoCc4XyZ4G9zpCpt8eibW7d+\r\nZwYs1Kxc7j/6JYsnq5N2jyw7EGRm8EyI8XQlqfpbM5pciRZfsQzopsBKpeyp\r\n1qvhSEuOx0geOlFfzjCQEX1QZyU78OOM27w=\r\n=duK2\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"204ad9a8c659187debee48eef0861b18cea36ad2","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.143+204ad9a8c","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_3.2.1-canary.143_1666832274072_0.8178453740572929","host":"s3://npm-registry-packages"}},"3.2.1-canary.144":{"name":"@redwoodjs/auth-providers-web","version":"3.2.1-canary.144","license":"MIT","_id":"@redwoodjs/auth-providers-web@3.2.1-canary.144","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"12c5b15b5864900e8a2b65f8467b595c0acca1e7","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-3.2.1-canary.144.tgz","fileCount":49,"integrity":"sha512-ruwgAFx/YwErn+2dDRY7xV8KL6F7/E7n80kDqJqJqMjwP7DYHgnDwMEFHqINSa3xC6ghrAIRC7nOWc5i2g9sUA==","signatures":[{"sig":"MEUCIHbK0Omg1bd1E8+/WwuJ5tM78In0JZT1rrJ/ZMUcmRa1AiEA4Sp6U3F1DerZPvsU8ILhpZmgN9xEKcaPRG6BAGEjK0c=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjWdfHACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoB2Q//TyrdR3rjhwtsmwFf6Jxu3ZJawTOxcMO682I1QeMMJkdY4LET\r\nPG0MbyoC7eV5YvPvJsyZp78xjXtJ04BEj71loeCXyqn8BTm9zfkmLscWDsrh\r\nLr6U9WJfwzVIp0vJvtusW3Pwo9KZQNbqgLBDNsuY2Lo0PIoJ2chei+QRIy+G\r\nW1QjAi/w9QHcy4Wygfs4kXqdi/pvmWvth9WCCluCsr8RTygVzZc/pp3DZ54I\r\nDlMwU5S6U6kSLslFvLUpKYALzRi5/QlXfw/9oviVYxIQgch6Sk7DNI4cJ/z9\r\ne4j4SWd1YadbnnBK7HUwVy2zoEBXNiRtBk+lX67snDebsTpYUPQOV+UQK91I\r\nL/M8+aTadHkBDApb/Vh3cFUtBodtZ73xv/2Nf4P9w6RwRU0JCHM0jm6GM0zP\r\nV7hxuYt4iv+2T6MYju75j74pqI1CpXahRmiF2XHL+KB8ihvkMncalwMrutw+\r\nuTFV1xbrK1sCZnJ7qhI1Qoonjvwo7YFCv5qwFmIndqG4/IEY2Td8PE7/27/N\r\nhNr3P4gmkhPFdJB5vo5sY2Nu8ZUTweW5vXxEEFpDeDm57rJyyzRCfXqrFaLK\r\nUqcRUFm41EJ0LVP0xKHEt5b55pp/ACNqSMA8MJ5wgxdK/k7V9tT4eUsMmhZ5\r\nsP3NuEk07e21hpzLzOogaVgIncGXyU0+Uh8=\r\n=wLgr\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"9a2609355954864802bb6075bb64e56e69918bc5","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.144+9a2609355","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_3.2.1-canary.144_1666832327135_0.046590172709199296","host":"s3://npm-registry-packages"}},"3.2.1-canary.147":{"name":"@redwoodjs/auth-providers-web","version":"3.2.1-canary.147","license":"MIT","_id":"@redwoodjs/auth-providers-web@3.2.1-canary.147","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"e9d9d5d986d81e5847b76a846e759f05dc54c24a","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-3.2.1-canary.147.tgz","fileCount":49,"integrity":"sha512-7lK1m44/ZkSqy0KYxLcqDRhoa7M28IGT4p+rozad3GLE5WW8IQH3aqDrrGaYF3Uhywx5RP3kV3++kIC55tZFVg==","signatures":[{"sig":"MEYCIQCJDOd77JVMrRvte4GxE1Nv1LICPkCNclY2wI74PvTHdAIhANlM3gRqk4KMBIcbyiXQJ1igWiVn6tv1Lb0ia/R4YEnM","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjWdl9ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmprCg//QkMWaqPErkU5DywtgTE4pxBzRUxAr47RQEo6naGDz04gX0pE\r\npVIYoCoeItwZnCHozRyZY/YSsqS9QBttEauAZuEMbKkKlQPQiI8cFaZNmAIh\r\nU8j5JRpyCi8SxG27eRj3Ytp0tgL9SOJVon0WGhCNdzeTRERTM3+wLbeu/0ku\r\nVQNtHHU+GGxFDc6nYjAV4TCSmaKOxbxgM/YSsIvg7F8s5t64uTO428ez0gqt\r\ntTpLx24vtZc7zVUVpdlh/in2DFK5YEbWnF+elBFKnxUE/GUDVOudcDggJkm5\r\neAFRNMSpj8bRxxi/SOfDDdv9YRfbpZcA9Fjl94ecPVpZ6AN3jf0pYCNXPYCC\r\nj8pJb61RU+3aC8DZdqXA4+6KKkycHkuc74AjTwPq+CIZ+xjf9l7VX1usTJRe\r\nmXF3GUERn7GKdRSD8XHs9VMXTyb7DLWoU887BLGCrf7tGg9Gc/3pkDZf9ie2\r\nMLBTqG+rQVyDVjiFU3QOVCzTjHuqxNDeIYIdlzst7oZpA45Xr9nqE2/AS0pk\r\npgkBtrwU7jvS7+6jCO36Z7nxybhRb1Da+f8JtcB3sAqrFVBQ99kyLvQLbl7t\r\nn32LAVOn/g+tsQEOcjryrLjoWD2/PvFrJUPLI06Lk9T5yp+oqcR+eyKA/iHx\r\nYEjavdHnXarLXlWikh79ddFGXImuh4r6d8c=\r\n=sBOa\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"e05e08071548f30f8020012a23d7439b7b71c58c","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.147+e05e08071","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_3.2.1-canary.147_1666832765494_0.05305222527721076","host":"s3://npm-registry-packages"}},"3.2.1-canary.145":{"name":"@redwoodjs/auth-providers-web","version":"3.2.1-canary.145","license":"MIT","_id":"@redwoodjs/auth-providers-web@3.2.1-canary.145","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"09382485c74dbd1f701fdf5c1f337846bfc5b68e","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-3.2.1-canary.145.tgz","fileCount":49,"integrity":"sha512-+IszoqPQOLsFZw2GuxvG85d1Pa8pDOonliRPWQeTOKs01UsID1L/U2xSZctnSr9+RkY+KLW9C7C9mzpdyKnXlQ==","signatures":[{"sig":"MEQCIFUkAnUaPcgop04JRDqkQfydg2PEGSpW2TFOxTa0ii+FAiBiRL6nmd+lCUnYaJJ10oyEepl6HoenlIdXwmQwYkruAA==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjWdm0ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrC1w//Yc0KReJfgioeBTXM9jNVnpQ2cOH9CCkAsQ8UXN41fMtu1IDw\r\nMq4WtrUhhSc7hXahI896XSXu36Hic4O8UkpTFCw5cdRYAFfmasSyxzI05V/R\r\nfafiVKCemHuvZzcdDlAnfctyuu+QAXPZ+0fx8dBna6LTgcENuhQze9UgnNIT\r\nGlFIz5dbevZbvgiR2HKEgmafCA+wTQPl+FKUajTGwO/hWncqI3wgtXCkzWJr\r\nDRGgD3yDEBCQwQIVNdwmRgcn2A0udGgqLIqYDmBFA42WcZ7pRQNC3djtdLvU\r\nV37Fc9tHoFnbmIkvDB/xs9i8MPo81afz9jeNCXQq+r+RfITd9uF3A5VphxFk\r\nCK8LWHQwN+GNOkPtMWqNjERWyR5y3DMEDUO/aLwrkFGDmgVk3n639c/wJRdG\r\nlf9YMF5fbwyxj+toCLc/6WrFoPpAoy732lzVBvb0rSnGzxoVVpdT91A+nrON\r\noB/brwGzd16ipcNgcwDKf3G8z0uUFAbaN9LXH5RM3r7IWyInlq1ra4AK96mc\r\nkqLPFvTy1QP2mIw9GDIyFX5W2tLldwclrpN7plw14BCsBEKvy/w3ptxaaGl8\r\nPu1cMqgw7WsYb/RHsC0OEdLz0kn3c+m11RXVeT3PIen5Q8ACnP7pc80eyxvo\r\nEwrDzdY6SbAP+Y5sGVSuYfyct/T/s/Q8eHo=\r\n=gwL7\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"50586ea0be78655a89adc88da8194129f2a9dabc","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.145+50586ea0b","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_3.2.1-canary.145_1666832819719_0.15221723042173996","host":"s3://npm-registry-packages"}},"3.2.1-canary.146":{"name":"@redwoodjs/auth-providers-web","version":"3.2.1-canary.146","license":"MIT","_id":"@redwoodjs/auth-providers-web@3.2.1-canary.146","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"3a15e877ca98c54e3ffa32e19d9d652bb3084d1a","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-3.2.1-canary.146.tgz","fileCount":49,"integrity":"sha512-PEevvA40so37jXWrOh3S4glnqXgJgcEjzcxK8AOvq1s/4rq9r14Q8CRLNHRcGOgapMLdKKfS/ZMPFCkxz9u3jQ==","signatures":[{"sig":"MEUCIQDK6DUmmGAMAVcsMZ/Lg8hLJ4lZjuONUydP+lzaPRoCqAIgJns/ZWa3RLUEvtL7CSjgGbIp7HtT/ARmg8cTthWSF+o=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjWdnrACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqZyg/8Cy1M03rrGklWxf6/EAVzmqgVA/J1gz+mXb79Uj31/FHquUwe\r\nKhXEYJmjD118BIwyov9tRoYVk9cnC5G96gGlb3cV1isgauYzUCulejp8+Iml\r\n8VN4abHDnlY8BizXkYPzDBctDKCJ0JW/WeW/NWHEu/BrbH64kBDR37ZTYU6/\r\nKnYNIS4eU24Zz6cYu2RvkWrMho3NzrsGGLzK4bEE+hYoo3kd58yf27BqOMjw\r\ntLQ6LyIeRHb74jsiUpkaEo8/7q/Gg8c8eKMd4jOU6RK0sKEixIOnVrA22Z+e\r\nL3Xn8yqXZvq5pDIPzUy04tosZN2GmPOORZxyGRB3b2dxAmcxb0uC2aj/dp5i\r\ntSPz3o9eQlumWEzvKdcB/kVOFXNsXqzVFW25zr2Qt+np6hHpnFE1FIGwbyns\r\nLhkkYpDgV40yeWq/oDVwU/iZejc6tal9Do0pK1VJkQvshQuhA+1goUkXpxVi\r\nqwwRC7aGwQ1u7Cwzn/9xEdiy8WQB2luO1eEtYVnvWTbvGoucIqhqMFrg1TxF\r\n/FcmiohJ1Mf2Emn/GrLMpk/BJTA4prPqkKnJ1tk69fIzLm+G6aH102mKYvCf\r\n64fhGalqvTW5bcee+WxZp9YKaEIQh3dPCturtrtkyDLlb9B3kuoUkmkHd5Bo\r\nzEMFp68V5hwheha5d5SVBay1GW0txQrPwwk=\r\n=k56+\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"d0be5e823d45510852bad067f541f2605ba1e5cf","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.146+d0be5e823","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_3.2.1-canary.146_1666832875012_0.08778774602523298","host":"s3://npm-registry-packages"}},"3.2.1-canary.149":{"name":"@redwoodjs/auth-providers-web","version":"3.2.1-canary.149","license":"MIT","_id":"@redwoodjs/auth-providers-web@3.2.1-canary.149","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"287b29c8f84dacc5ad54bbba2f4b4aa64aa26c20","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-3.2.1-canary.149.tgz","fileCount":49,"integrity":"sha512-CHg3cbbvJwwvM2z6x3wg9F/Fhyu48uY94cap54VUL77LxuZ/rwk6+fjtnOIFF2boE0s+9YUnhxEkl76M0FtGjw==","signatures":[{"sig":"MEUCIDZwcBeBt53CcS64RQIqLnbc6LvKfNEJWfaD7X5kHk02AiEAklo5yg+dwUqbIa61kq3CIFATblxQYzKEiCsqGhkUfMM=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjWdtVACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqWaA/9GrSdi0Cr7VXyL6ge+by3V5jWFf+k44CjLEiwE39c7ZP++Rsz\r\nKiOyVN6cAc8E+GOsN+u5ww+ojOMUKxNzTi8Fn4kuS5U+r4+an48zuzYVhZgE\r\nQKT9XPaAYmYB2BN6a56nrO1cl06ILpyRZ1+2nr0b6y/GvQqui6ik0zChRXWE\r\ns2A4m8FciRCbbaOnQDYZNORnT9YOfciUvqWYdl6W0+9PYHl3iZJXTFPFnyes\r\nGDxT6tBHzjtSDfaO1jOSLKph69UvWwCf7qIhGJGrOnHkhNlNM56H1Qz/SCPA\r\nJRBIcIHT0mi4yOD/UFLJckC+JCtx2+Og5VRnAFtby7RjqNcutARQhUJ9oFiS\r\nPO6ie1Blvc/37PqA9H6gEcqcKqU3TA2Ks3yBbtI252Tan5I/dUlZhlBCv/5t\r\nSId1evcVBrqbLVVqU6hM7kOgU5V+87n2X88GEmmB1gmkhLUT1AK3J3RfWI1L\r\n1WBHORo2qzVJG1m/1m98VEXIglHWVI4qhchRzXWrftRFuPTFygzj8X5Z03Wx\r\nZcx2naiB9qOv893lpRAJ883iGNjQ/YWTBLXsRkP08NmrqGgbPgAYDTk6pej+\r\nccYfGylDLq5x/W+9yE1THLrF5RNUcZVEvqJmdXvVJQdx45d06f/v70Hm9GoE\r\nwxnU1aD9K7kri77FXA+WsaMuv5rWOYWEEaw=\r\n=VfwD\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"810f1fecf815c111f0ebf095d07d7455e60fb657","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.149+810f1fecf","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_3.2.1-canary.149_1666833237248_0.4996858242048432","host":"s3://npm-registry-packages"}},"3.2.1-canary.148":{"name":"@redwoodjs/auth-providers-web","version":"3.2.1-canary.148","license":"MIT","_id":"@redwoodjs/auth-providers-web@3.2.1-canary.148","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"327725fd1781fb329008415451d3a3958e909dda","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-3.2.1-canary.148.tgz","fileCount":49,"integrity":"sha512-Z5u7fQtye2Ixv5UEa435KVeU31JiHPJTNphQM0o86GG6s2nUWyQpK+2JVZPNPdG8zT3vBI6aj26oaj0P10h1RQ==","signatures":[{"sig":"MEQCIAPXtUyVfQp09kpQVt6e/6k9xPMdNNX29bu5MB1KILlyAiBL30jzHe1FarbWBbnFGJhuHGoKSHR4kuHXBpyE64McDw==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjWdvqACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmo56g/+IxZiawWxxKZqCv8Bc+jhhoGdV7JjlFWVNScAf0ZCIAjAeQO/\r\nkraMAbh9LcmPcTn6vlOhfmlI1j5uFXAHNbqU33EusZumfZG33RFv735cSt7b\r\nrq8MXulDNeOm/gliZEFwViPiy75zwZFGB27i447Dw811Bsay4A+wp2w/8U99\r\nv7xBUv8NnLM5L1G1xZbEh3aR7r00jZyRk5AHXjBPw1T27XXdmTRVShnrSbgs\r\nc65bQ7RBaQTm+YJag6TxvtLTq1QWRXDjtOlrQYtvbLyNM1llna7aExvEj3MO\r\neK5yB79LGckp0xe98VFf7LRNB0gYZ62g2bkqmK8tplUbnBsX23Zz0WhOx9Su\r\n7IbOzdQMz5EE2inNeetRtybWzu0RYEB8LFyzxssWM178iblSVp6p1d3dN+NM\r\nkns0jrxE18EcYwjAQGL3srcPYJvb7mTcaZN5RrGFNxhtAZfVgs7Q92pp2Neu\r\nxE0JN6sX7TD8+vg0fHRs8G8KV0sIt7Rt5ZWaHAFPCoRFmY3xNp375Qubl1e4\r\n8UJmzf6BS2Q78k4NNY+7Oe4BgAJHtM2ZrFlKF1dMkjLSI9+GyXEvx/SwaCeD\r\nd/yxVq2aJx94UBefK91vpxp6QRv6g+QVVF8lRqS9luDS8jIPByHzMY+CzcZk\r\nAb8870nnLmKORLuIKS5OplyaZA1PcYu/fc4=\r\n=ofiX\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"c7cb9d975742ea392704a6cfccf1b42cddbc6a6d","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.148+c7cb9d975","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_3.2.1-canary.148_1666833385962_0.5408565752766181","host":"s3://npm-registry-packages"}},"3.2.1-canary.151":{"name":"@redwoodjs/auth-providers-web","version":"3.2.1-canary.151","license":"MIT","_id":"@redwoodjs/auth-providers-web@3.2.1-canary.151","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"3ca23026a1164e95fe8672dcd671b11c873ae9c3","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-3.2.1-canary.151.tgz","fileCount":49,"integrity":"sha512-KfTIBzgmUjvHa4ZIcgDdOQDHAsmod92j/8q9RYfEzWhjR9N+sbFt2dut9gLGXVNPZnmgp3yBJDgemO+f78mesQ==","signatures":[{"sig":"MEUCIQClng5QF8J4Ii6gWizJfuMJfZAVyCGY6MXskqFP3mT4mAIgEthbqM/MmAUuFp8FdJWak3p5PqsdJ82Ith155nyQZ8M=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjWd7YACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmqv9w//VAgsBRPcAMipZYW8wcJanUO0dNUVo2oGBBuI7eLg18QHCqqT\r\nvKpN34W7W8yI/L41Hzo4OCzVFPjcO5HtVG+uTFb3/KpGGhg5qgLZdOJACUg0\r\nm8LC81I93TMrl3FYpevDk8f8YCKYzrZCbjXUm03xPzdmfp8Fbw7eSFwo3qEv\r\nQth+8LSGh0agxVd6g6gPNX1CHRELQ5PSn8aWiOVr1fbtwCJKgMf+/ox9tzgU\r\nouEZJVIPUWiL5uQ2MqNd9bDKs8OvOZhdgQNBPO3LEJ2TJJAkcxEoumJiuKH0\r\nt3e86RsVdEpIqTgraF8nxzDxd8oyD3olQiq6tREwwTFwKTjGYzi4PpBWkcB2\r\n9d3NACCljxy/bYji7oC5d7DRrIsasf0/EIWWeM54AIq6r/MGJjJbYPzDb0Xu\r\nhebI1WIJ5hbSm7QRUabH57sqbULOcdu8HeWIqqX+aSO4Il9osIuyKOAO0XKO\r\nbJ6w9rVS/FQSHrqjPefykvfc/8iLLDfSYZR6Qf+mOoRvtiyMCLmYvb0mNfJZ\r\n7295AVhDJco9fu2QGqIBNtAciApJg4DcFOT/KPZ9FGPk9IQV2VetLHThhiRg\r\nrwLnxY3GY8Nzf3IikB189thujNSRJYPdtrOrwrxVwV3dJ5/qRELlGSrip8EH\r\nHmrgqhH2llm1shtlY1x+OR1odOG9xQqR5/c=\r\n=XeBz\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"2f5a120062f82651e5a010067a0bf57e22be4369","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.151+2f5a12006","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_3.2.1-canary.151_1666834135957_0.22091370496246632","host":"s3://npm-registry-packages"}},"3.2.1-canary.156":{"name":"@redwoodjs/auth-providers-web","version":"3.2.1-canary.156","license":"MIT","_id":"@redwoodjs/auth-providers-web@3.2.1-canary.156","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"2bbbc6178c39c44fe480a847b02a571d4e734a13","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-3.2.1-canary.156.tgz","fileCount":49,"integrity":"sha512-EJuBjr4y4mwgzAL4NdDHEBLrRTJTsi+22Sgk3PWsd1OzjZKScRpOixSyuF5pMwYfn41kQ4SXJwtQWmA7sFRUTQ==","signatures":[{"sig":"MEQCIDtMJ3d/B9ViLMfD7t+1pQ4Huhy7c3vC8EhZh7x8IBhmAiBedKA0622R+2N+UGhH/naV2qMoFyuPOV+ruJAsSnnYkg==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjWt8BACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrFyQ//Tu/2XoN7HUAywa1mQoTldXWhPW1NtyW2c2tFy34lSYS0fDrW\r\ns2dgbkjfTNWh/ZXyzNABf7q1pmgKM8LsrDfipntvZ/gV0uTth9gekMo7HMki\r\nxScG7RBgaFJxyLYxd71zHWStjg5MZbOPKa+xOyGBZydkR+ooStDxumcy0kZs\r\nNQaWUTN9QjlvWXjrJW0HS57CSksrsYqBvevurKvnC0m5s3UrLKyBVyqbgG3V\r\noYmMSFSd0mc6X0DKZ33VYBugq5eAseU7zdvOleIkzFGNtfuq9zjshQhTzdnd\r\nTru78RG+/bCboRc5E6+tcMMiXGKOKzPEauemwvLsI/rQ3aUrjv725lXXUan1\r\nqSydV2VL6FlY2CCpT5eU1eKIwC6AcaWbtNXgurDUpr0yVgD68Aw3Cd/Ws69G\r\nfyLIYjlRGu82UamfHVsTQg0fVI052HT2QKN8ai/Xl2MbAgMqKaJmxtca/aMb\r\nohejKILm77ygYvOEGAIMcn8H1Prqc30kF7amiCfnuJvw5ezm4k8G1x5FhJ37\r\n0Cw15hkt0BEPXG4aWA5/ilx8hP5z2UddwVzzJ0pdH2e/qlIhj0J3vrOl0kEu\r\n1S+xCNeuZN+pIMjRXMeI0R/piujoAjD85N1bxnn3oQfRkcXhSbgUjEkhFJwP\r\nZGopqGAZ0a2V+yJyJtAt3/3VeKkAdNCTGfo=\r\n=g8f9\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"113b91b269f939e47bd3c2f4b7029c58b981e078","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.156+113b91b26","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_3.2.1-canary.156_1666899712891_0.412419294813942","host":"s3://npm-registry-packages"}},"3.2.1-canary.158":{"name":"@redwoodjs/auth-providers-web","version":"3.2.1-canary.158","license":"MIT","_id":"@redwoodjs/auth-providers-web@3.2.1-canary.158","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"a02fb21f2b713e90581ba280fb896515da564418","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-3.2.1-canary.158.tgz","fileCount":49,"integrity":"sha512-B44ii6LbdNKwJ5zyb+HgBiImNyzd2uITmAcF68damq3los2ozcEGDUueL2xGFYI+twdwLwCohwNWONxEAEY+sA==","signatures":[{"sig":"MEUCIQCDm2Q4EkNGk9axldzZ0SaAUURsCk+I45i2IzC7isR1LQIgAaFPnCcjxmZRFa4+3ZjJJchhdHXvjFiRpZF96szJzGM=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjWyXkACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmq6ng//cAeEVXj7fO4nXBcdMNCTRfAal+SzrXUHV70ijxQXnsFmx+EC\r\nBr3ZCr4TmMyPs2bkG/JHUY2IPDGB7nnk/364ztH6eM3aF37NyYAH5Y+2HeB5\r\nmcqv7nDqm5bB3kQ19uGzrSlYYeLZvGZXOzKf3arAYO37KR/pI5eG8Wg4Khe/\r\nUuLrBLmNqZM2kx/0jHDe8K1nAbY9JEw/hMA1yomHenMsRDmkFaHtR3wVExk/\r\nB12ycH/Vo4/zcpbuluPWLiZ/lv8DSGWRU8ZHAOlKOQwEEEcTZ7bGkalwnQaD\r\nYt7mqlxTCANBFkN0D9VBhTH5Wbl8fv4xDsbEfNbtxqb6imM8cIWqmHJ+4E7v\r\nEvXHPrtDWU+LB3Uh/hHGhGSjtqq8I5k8Ku9FKtzo5GDK896Yv6wOrGjbQuG1\r\nNcvw18xqLjp4qi1T6qJiOqA5XMArmsUEvnV2HRj/adBY5hg1KIfYi++QEGvd\r\nSqlT/5YVXbZnPYf7w6w4YGZFbR33hR6bp9eBeykORz8wXwApUW2AwExWGfgk\r\nUY4iVLB2SPJ+8WuEpksA8xZS55UsCr5/wI8t6xfFLoT0GgwGG1mINZnRinS/\r\ned8raH0BLYJBIzqeLZ/Y1bOo8H6DBAXJlPV+2dzvDa7m2PX3LpajrsQBLUGW\r\nMY6MywLQTYIHuiUiHnDKzTqBnuGAcOF1S40=\r\n=/sdf\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"90a9f125daf07352d9c834727d7cfb0d0ace3fd5","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.158+90a9f125d","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_3.2.1-canary.158_1666917859655_0.4264884647929088","host":"s3://npm-registry-packages"}},"3.2.1-canary.159":{"name":"@redwoodjs/auth-providers-web","version":"3.2.1-canary.159","license":"MIT","_id":"@redwoodjs/auth-providers-web@3.2.1-canary.159","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"46ad996a4b2feceddb573e81509317f82bcf5965","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-3.2.1-canary.159.tgz","fileCount":49,"integrity":"sha512-iCT7wtt5JskkKDwx0l6zCRdLsduPY1tm7ULyjZTH+SMBSadmSGnxL7SXEQIDGWl999aHq7fhpLNQp7i78BlsFA==","signatures":[{"sig":"MEUCIGH82xKFUddcR6hGiteYdFeqm2zmbP926zN9zzQXm/8BAiEAqHsXDjqCKRUV8d2UAS/F7sE5coZpuW2vZIaVLVTm29o=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjXcIyACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqhRBAAjhxoV4BTF2jjJYVVHfxNTo6124ljBktjI4sG38MKjP9Uhn7n\r\nSq6b3ULWFkZVzzN8GaxyCQhgOUmIDzbilnalI7q5u0X10iZUApxqZt+CsBYV\r\nuKcfdmKqVpBuriFaUrzFmhA/RqufvCyAG9DO73CyqwkfyoKtIEwAguCQNhR4\r\nTZiHUWveX8bBJOKk0o7+mcxet339sVe8ZOEv9psaXJiqobuOpqnNhoYOW19i\r\nE7KThuHA84eAOjlomrWKnXpNTXo1R/uSNbHXzaWeHx4RYhKStCKzc7YdkkXf\r\nVgPa+7SXVwQm+jEoNpXZzhHLnEjX2uXfWPMT3x6qNi8FbEetXeCSsh8aKMiS\r\nlQpibbX6/5lS2sytl/Rz8xVG0/UFdUZXswQgLxy8bgjK6HchORZAlA93wWhH\r\nL+j4F2JKjRcvsZK33d0nZ2am/SLlllF2DRdVzEqWU4il9fBFWjDZD9yNWD4L\r\naMJUT6Q9WvIcBBcqPTw6sNr4TWwNddzKnH07sA3simsG9u8jPFOl/nX15dkj\r\n8icYGNhnfthOrimwUZwqo5b1MXXA5NScZMCQAW55h+WXP/1pssTyj8jO5a6D\r\nevZcoWpsCxEb9EmJd1634U4/2NWGztDNmFZzgOfFf+B8finOGwDX4iKILHRC\r\naR+mJzNllXTwPsVPifMtWeQl0Zvcw6GoNGc=\r\n=rmwM\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"8935b209437a7342d571ef12dacf437ae248ecd3","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.159+8935b2094","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_3.2.1-canary.159_1667088945988_0.7780685584445426","host":"s3://npm-registry-packages"}},"3.2.1-canary.160":{"name":"@redwoodjs/auth-providers-web","version":"3.2.1-canary.160","license":"MIT","_id":"@redwoodjs/auth-providers-web@3.2.1-canary.160","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"0d844ae1373cccb04ad365e2789c3273582775cd","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-3.2.1-canary.160.tgz","fileCount":49,"integrity":"sha512-hcdP8Njb/gs3rzlvGgq3icphbHZneo4rMq/rWvlyuEYIPbAPTBfKXvAf5l7xcFf3Hd0ACb/7hWjxz8J6sly5RQ==","signatures":[{"sig":"MEUCIAwWUMKJc7cYQGuqrkCp2dkPw6d7742stdTQ8arMXZMLAiEAh/24xVnAfvP9DfuqjDphFzLUaWxVBlLXHL2CA8zkY9s=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjXvDMACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoF/A//VVd9ntwOYxmFwR7e5ITZLB9wiaSA4duFPXdlEOvAsrNO+fy8\r\n3Z0fQ2TZ0v/6ojD2Qvimwf2S8b9S7lF5cemD/D/AGy5tBjc+pYgImcFar8Q9\r\nhJvpZjmzpJBLQ0expLk/bmLQx5MN3fl/RcrWLyOX1iR55dTZdk2sla3zlrfk\r\n8LkTG/xZhnhilOzyKyGDw0aLOWi2WRlOpVhwxPkW2DdULAyH0IVUnILyjgRC\r\nUKC6FvRioC73R32xxqiLZU44V+QhjxFunVSoQRUE0683Ak3GHDjV6wZ3b25n\r\n1xOdKs1DHLqs+E7oqWxisXhRRMQ9JyFBz1LdG7vohARS7md2dQDZgQdF5q+n\r\niVl1bCPr37T66CPYFTDyS1XRybEHwr/xL5b4HqwW246aPhlMStS+ZZvdmkjU\r\n92wOw6wOWywGTvWayVyHCqERTVBK71w9qud41GSq+R6sE407C45MZxqdW2e0\r\n64bCPZ9fBeSCrbkwJm+N0P5jCiiCd7OjYmkRbiZy6IAgFNmd3hO3y4htaZGO\r\neoHu+ehZqLXWJakgGHoKnHxh7oKPfgjw/acCkLVxsPCR7ZykHrDv5u2pfCny\r\nYtOt/emlFuDlvvsC00DRoDUIWIUMu2CMB7z1ux0jJ6agvi1gcpwMoqXEB2IT\r\nSZ4+n3QAFtxgQRJ59xcQMl9HmM6e1/ZSrDY=\r\n=QHmH\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"97f6f622e06e34e6a88f167cfffa1c1d78a33b92","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.160+97f6f622e","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_3.2.1-canary.160_1667166412330_0.8910818509804652","host":"s3://npm-registry-packages"}},"3.2.1-canary.161":{"name":"@redwoodjs/auth-providers-web","version":"3.2.1-canary.161","license":"MIT","_id":"@redwoodjs/auth-providers-web@3.2.1-canary.161","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"78eb99c1d69fddc9210e86feca7baef5429ed08b","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-3.2.1-canary.161.tgz","fileCount":49,"integrity":"sha512-wUr5pUpxjZduPYscS6bmnDrF+xl4METJd8NhnETv0ArHBm5sw42EkYtOfqwGpjJqZy4W27BV5wmdNWrrnpMdyA==","signatures":[{"sig":"MEQCIEIL5rJHQJG2xc3rOkkw3/aIVwXL8hpHEswNyAo6amWKAiBmVlg7K0TYTpqqlxH8c4Dmmv48Md0gKFvqbF6EwWEnKg==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjX79hACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmp/YQ/+NM0bz7cqnGjGdSJk4KQpIQoPm0ZDW/PWVE9/zEl773s7Zq5G\r\nm7S3XJTdDzUzta7fWsEJ95R+n8q3h6JokfaNErAJBRdEifpsh/svqrY4IRfa\r\nwXsrh407GOI5ZdsagYrP/yXhL6Iu96QJIX6acEsw/z8VLFM50UiURkqLCTum\r\n+xjBmEKAfm6BVJk29Is2ApTZXm7vKigLVFCVg7RRqpKdRRX+UBH1tSBQXvm9\r\nk95V0fxc5nHHjqsW4KyqwxfQbgCPC2eRk0sp1IW1UNcXOJJI63uj2i5zovmb\r\nFZCiUs+VehGxX+XYY86jhlRvgfQoBTHucbfZh7K87FPiCi+Pg5L1gM3L8zAk\r\na6l0LM1X7/wDkkIDt/RjbtLbOU0pnQ6/lWRfcfNyvFO/nXuvrdnDLKIN1Wdx\r\nWMyFVckg4ASPTBUfpuvSu79+YWlqHLPOyd+/0fUHQ1nAin9kQrAiDjBZfvH2\r\neDmgu5/8dlUB3cnt1a+S1TFJWvNWq0muhW5S2la/b0gfWfOycMEc0pxqf9Gl\r\niS9iLkLZBT0KUCUE7XAtMeQH2GL1lfOP4yW7owThq3N8o4YzcWHPluIBKubL\r\ngTJGvYbpT2JcNhq/AWkEPbdPq0zj6u8cjXg8tFWPYZs8GEX6BmBjnXvIscrg\r\nmRtMrD9TsIrbzt0wQqAkFIV+j+RnDOthpeI=\r\n=WVtP\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"7f6b94ea6c11c8dbeb1b432c061fcb90ee938d68","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.161+7f6b94ea6","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_3.2.1-canary.161_1667219297672_0.23215213692126513","host":"s3://npm-registry-packages"}},"3.2.1-canary.162":{"name":"@redwoodjs/auth-providers-web","version":"3.2.1-canary.162","license":"MIT","_id":"@redwoodjs/auth-providers-web@3.2.1-canary.162","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"53658cbd58f8d6c4b38341aa31cfbb762e96c240","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-3.2.1-canary.162.tgz","fileCount":49,"integrity":"sha512-Vdqfhd4ez2HjzDPMFvWZAMa8++Yv3pZ36oak7k0NWcevJiYiVL0iTNPoBalCGNOdxn5OBskV3mcK71A3SwoWrw==","signatures":[{"sig":"MEUCIQCDAydQMBWJRlWfQ3LIYf6jk7Z+v4iZ64hPYEt/sz0iRgIgAxwHG2P4CE+P36Gty3oFQlh+Jyr9TZAzRE8unI0aCH0=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjYBNiACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpZzA//bdhzqF0KimZ+H0mjNpd9o9b3VWCE9UI5Vhvb9q4gmZkbuVvv\r\nz5gRGYC73V7mhwEjFLGGSAM9+O2sKuSA6w8/lAUzEYvv2WoOIf1LskISuqhe\r\ncoDIXTSsEjuTZ+PoQMh/ODPdp7Sx+1g/p6JgIP1BysmlcvTyRGdRdK+XDnx3\r\n80Q1JfEsn8HvXIMpScOyW1K/t5T/gog7RFXUxmnlC5ruu4bN2gHmaGGKVyY7\r\njw4sf8B4qolAqw/x81LehZ8DHjcZUQDC/oq9gdQAdBFzoXHmYqj2AUYIZy3V\r\nONF2Vfnu7eKrSD6CW+IEa2Rgo7VmDsWFwKEGKnep85izGMG5q/TkEwG0Haib\r\n110lrlezAv97ayKpJWn91J8Q+m4NRBhsc9dWhSE7DcsAGpFfrUFUWU719S9+\r\noGS6TWARD4rz+Vojf27rJERj2LMo+PaSEOrE067UCLH7VL9KSqndPfIZwj6p\r\nttLiknKL4laSuREJnall17a8zPIjNdLb6A4h3A3chyHbJv3Uy8N6Ymuul6nf\r\nd+bA5YArouY9ArVzqASZY5N7kCLGqFwkLFQqK6nc3rQcGcpNzS84Podr+MLj\r\nlPWEPdyrQ0gP4Nr2jEM/wU5Q9aztUG+Tv9SWv7P3bJvlEBJL3yHQQCywhvR7\r\nF3UGRoxA9QiDgt376wGexJhaFQi11y1tiCA=\r\n=t+zM\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"544374612d6664d8b0ef4ff54dbc2a43c4e000a2","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.162+544374612","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_3.2.1-canary.162_1667240802505_0.07503019324555504","host":"s3://npm-registry-packages"}},"3.2.1-canary.163":{"name":"@redwoodjs/auth-providers-web","version":"3.2.1-canary.163","license":"MIT","_id":"@redwoodjs/auth-providers-web@3.2.1-canary.163","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"3c08b7e28246ce78a92005f480eec878e653fecc","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-3.2.1-canary.163.tgz","fileCount":49,"integrity":"sha512-knCd5/Zy5fYlgxm4V/LFU7qSz92vjCSWFXsZeDxwLch4IICm446ThMkT04RUnSsi/mRzHzvmhhn/ns4OW/fYVg==","signatures":[{"sig":"MEYCIQDaktZKSq5esh69N1RBgjr0tczQXHfT9R//62A3yj8huAIhAMDZXBXK16bMPakoJzoJKClChBkhs/iSuZmTavDYbCu5","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjYEjRACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoVSw/5AdUat5y8dNCpgUbloDfA/U9Q6Qmsu5IIoJJV/sM/ZFUuqmKc\r\n0fPalb3kKjGXIJBI0S0vkox9NVEURMUVzarne/4Eb7azoxCUI7JlJbWhDHhz\r\nhWvH8jWZ7QIlV1Mck9F5yNB1YWNKCepc+ayF1tjtEw7iGI4WCImPeQO0Q2ts\r\nZiCIbO2/ag2ILbgpOhtiKlse6RYCcz68SL8A0FN9OE9ffefeRjFcVXg7pPET\r\nAI2db0c0FPT8GWJNYizXHKE5ABpDvQuV4mcbGDfiXy+dh2rfrC6/Vfli9chP\r\n791fjQCdut6Zh6LigTnke2Islwb+FoVFnRTqXq77jRtdK6GCEFDyQci6/AL3\r\nXwQLvhe1fCvddtp3ae10+M49JeKhugPD8P7Vd46KPTgXhGvd94pctdqSiQNg\r\nzeExpG3VgFZ4KRJD4bNZYVnTfalskzVYRDk0ZMhmD0S1q8/YbmRz2cW0/QKo\r\nAYkR3vBiyShA48XipKi8z7trLhQIxKNz2oWJtJ6B6mlI69xW8yo2TOwdD96a\r\nT7gcEK1JB4Xj6fTw3yO1auc8/4Oui8vA0Q6BuhKD7XPnZNGy5cYv3FjW/SY9\r\n8OeWeBBL95u9gFCYIyzUUAXVPV6UKwjCz8Ug4abkcCMlVbQmIMZ8ElHeNtND\r\nqlG9+G2QFPh+o2pTP6YvTlG7Fwqz0icyyX0=\r\n=NrLJ\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"a388889c084a22abed631ed4bc80451474da965a","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.163+a388889c0","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_3.2.1-canary.163_1667254481123_0.6583034151692937","host":"s3://npm-registry-packages"}},"3.2.1-canary.164":{"name":"@redwoodjs/auth-providers-web","version":"3.2.1-canary.164","license":"MIT","_id":"@redwoodjs/auth-providers-web@3.2.1-canary.164","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"2d046f64a43a02c01482346c0738e5bd784188c5","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-3.2.1-canary.164.tgz","fileCount":49,"integrity":"sha512-qTEsYISk31ZF61twHpazI39uSbPSx39CcP6upXBJf7kGMlucJErxjDCDG95Al3OtrNawj/Tn0Ti9zl137mpXOA==","signatures":[{"sig":"MEUCIQDZ2TSPVbZf22FEn2C9XpauCGxvsKzz40D3Ig0OFOBLvAIgcn2YO20U+kyAmi7K3O1XoAxTz/lKcjWb/bv5HESS+/Y=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjYdQxACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmq3bg//QDcmJ0UtA5+JM4gpgphhQgZXMlq8e6KDMYAMbGhtk1J2gUjq\r\nY+dvjNy9LbaAzpofFyDzhiMhzDH9E3rRfd4M+dwclrB6GY6tzwClXlfZFb7E\r\n+d9jrsmXls7jOjeJJfv4Ns4PC3vnNtBjDOZHbfnCyjZneTh21BR5Xe2sySNx\r\nc6u2LEVqKS7Twr1uimE52+kETzbMqlrcRI5Be9zc7IwSQraL8ir+Boslnd0z\r\nDP+oiZpSEpNXjI/EYCCGRmQxSCDKsWcSzq7Ke6HSU6pZ2JLSC1wYVstt+nWC\r\nSGNIJzR/bpbPzG0aooSom4yC4LSbp6wOKC0TWB6ULyPp5D94WxRnDY/wM4gW\r\nfCXnV/XlBvX7ZPqY7nO53udn1pt5wZUM8OKDsRAaIKxDkQlxJNWVj6W21tyA\r\nRWpCjSxNtDH0t12hnAHe4rR2SH9LdBiheehjxaVPc2K056HS7sXI9Gym8Stu\r\nfToeBpFI3cYo5J6I/Xsn0iuuvoNOCmq7Z7ABInIJNoxBNYNHuNZtkMwLQfS8\r\nILpVrWIdYNpWkgvNL6GHAZkU3M17i+l8Utp4K31O0FvaFbf91+CARGNmbYko\r\nTyVA47BTyfAji2nI2Nwf9cBmBJ5/v9HwO4XBwnydUN3kPauxj7e6bUKOHS+n\r\n/49Yorde1OLcGZUPlZTKV6T2lBw2AHZlkp8=\r\n=vO69\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"4437e21b631119ae406eb5de38ea1f38b0bfcee1","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.164+4437e21b6","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_3.2.1-canary.164_1667355697460_0.47631098845127307","host":"s3://npm-registry-packages"}},"3.2.1-canary.165":{"name":"@redwoodjs/auth-providers-web","version":"3.2.1-canary.165","license":"MIT","_id":"@redwoodjs/auth-providers-web@3.2.1-canary.165","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"008cfb9962ae9e036e93084b9a82fb9a216b6c01","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-3.2.1-canary.165.tgz","fileCount":49,"integrity":"sha512-uCQO114AqupRV6SJFumHHve+YbyStgqPGrA5O3HjspIAsmu2my7hoAyQ/IiaW2/MtEvviizV9geh90FapxBvkg==","signatures":[{"sig":"MEUCIFhxCxUeLqIbh2ZRrqIjjfsZGm3/ixfwzwbBC6uiSD/sAiEAncNArzdavEwnA2Nixh6s5wYdU/cawAIUOpPos5V8U2U=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjYrneACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqxcRAAo6v8Dxz+nSi5yYI1Hi0khT+f9q0PUTdd9xuVD97v3Mao510M\r\nPCxLrehVxETHPEBQ8oqIT9E0EZhzLVSq/YFRKWIID3Ya/Zv7wPsNx8Qsi90w\r\n6lgvHBgnsf688YXu7mo2fpbV4gdnDMaFxzE1zC9K8OiAShGGnpYNzdEDYARS\r\n1tTxHHKQWFxvB0jICroeXM7hUI5lhcoOZurJcGuptz9PKhJ8kl/mBoI1a1mP\r\nyUO/BnI3nhztq7bZkABMfGysISmarJUaeC7jnFqcTUr7qfWgXZBZX28TVpBY\r\nrg9N+tbeTfmBGHAl2UDLz9Ku9pneBWdBNs9tADmC4j6cjKR8sd0Ic70BF+z6\r\nKpD3zDQfRk1M+egP3PbdyWsfWnl7kgPUtaSekyJRWOussgsNnUbU4YKK/G/j\r\n/xrgjHa/9dDnsfz4UmGfBfPjF1FblpBtEDAGS6NDzDVIimI91Zx+A+sxx8DZ\r\nh395Ggf/RDPN9M3T99w20uqLGUHYaWLXnzJvu4TWRNDf8gsBKrYhHFKT33Hq\r\n1ttqG1UlnU5gkQ2Y3ez/t9ixuAuprK4jOpbpDBoXUg1QIVPu76B6fqRG01B8\r\ntUfvkg1UHvUO+VHgyB3AX6HvuawYxdeqGZRFKvYWM7t35jZl9gWqJLkSdjgI\r\n5mt7uo5IVc2q57tZI8YxU1kIZlLNYa1Zw/A=\r\n=hfDA\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"4d506cd87984dd6390355b98b8a47ae26d7f9773","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.165+4d506cd87","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_3.2.1-canary.165_1667414493821_0.4683861677760943","host":"s3://npm-registry-packages"}},"3.2.1-canary.166":{"name":"@redwoodjs/auth-providers-web","version":"3.2.1-canary.166","license":"MIT","_id":"@redwoodjs/auth-providers-web@3.2.1-canary.166","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"4c3748f0600a7855451f8dcfb52834bcb7cb766c","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-3.2.1-canary.166.tgz","fileCount":49,"integrity":"sha512-r2pKkcCc41pYkQuW3YaVeU2h4zhsXRPoAz9AHnFSDOr1zjLEqz3pY/8dQvHpqXHZpK6uHZml/QGLaEVOUYO6gg==","signatures":[{"sig":"MEUCIQCQ8256Zoi4+2aTtP+vMklpaUcvyHE4x9JE6poN/iLCpgIgT3CWiJwmJqCMwpkn+Kyh8EPdljKJJOfmSsGzNvvGFxw=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjYy6tACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmox/w/8CCHxwXlWELuWMDcExz1BJb7fu/YcOkqG1i8k7/91sVIBpD7+\r\noI1uSXGWzCbGmdW2G/efbda1B5nyazfSy8wgJF6D2GwlKMXSSM+Re3TiCK2q\r\nrGZKpRnRBJ2XDgZYXwhFkQ594EMCALp2cHs6JzY7Vc0Fl6nnZLHCVp1aqaZx\r\nA/PPFYO4ERMDNG5lDs9nqEPjVOwauGPdzN41/94uAIrMGDAOWQH5CNYBDddq\r\nawZJ+9m0hCHC7p+Whe0r+tdJPguQsvi+9jIFyqL0U79tbWblRdaqDyTU1zWf\r\na6f0loljFI5KBG2KFh5mOKGsqiKCsIzIhWiEzjndWv9ZQe67L5M2bOw/pdtQ\r\nWI/lMW7OjW85KG4yi5ELl2p2Cose/wo5sVEXJDm/xylrpV3CO+EhVczBUJ/D\r\nKlqQpliZh+ZCyow73v4kCzqO+Ojc0JXzOXHD/yLekEZW0hc4VwUqUTfmQnmd\r\nskRwxDXNWdqdMPtDCeEVOH8KAF9dv+GM/aaLuUFOXF0gDbPkytshSLG6CLQz\r\nO+H2IHJcawVdB07aKlMDAXgUFoInz4sb7dhgjkXX531sMmcn37vk4MEfWGkB\r\ni/ScCW3GhKIK8297itWOOTMFRCgg8Y7Dvp1yk3/+IewFywkPhxdI49yM7BJf\r\ncVcRjv293zLuy/+PBqB/1naGEGD0dfl9Pnc=\r\n=0LMH\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"95a8702fffc942f07a2ff861e6910204d00179fd","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.166+95a8702ff","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_3.2.1-canary.166_1667444397695_0.285197277860316","host":"s3://npm-registry-packages"}},"3.2.1-canary.167":{"name":"@redwoodjs/auth-providers-web","version":"3.2.1-canary.167","license":"MIT","_id":"@redwoodjs/auth-providers-web@3.2.1-canary.167","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"a6ea184943ca3b6f85006dd55422a72faf0be5c7","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-3.2.1-canary.167.tgz","fileCount":49,"integrity":"sha512-68v1oX7eLa2VaUhoTuhd8fEgGVvFi5ICgrwKG893yFdzfbkEqyd7gM8D7pHWeAL2NqNvI66DI2jBMr2dQDp8IA==","signatures":[{"sig":"MEUCIQCKpYdJE+tA+iQxweZx10ndRZS3osiaZwqgjsXNZzYaBgIgSxhsbFUhqES6h7lioBz+gttkgU/DOjDvK/eMZ6kYK94=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjY3RmACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmogcg/9Gh7oCQ17yJjeSxvAfZWz2V+dF+NE3Q/uc7TxG9f/w+aBo1yg\r\nfgkXSbKj5UdvJtwwH7NqWsOEVU2PhLavZldvJgKYG6hrkIXvHsCsClnPv23d\r\n8XMcLprYVx7shS9AFiybnRH3qgQXoSafMXDPXtix0pFY4DeaaCx1A5bgOZNe\r\nb1BMhQDTG7CTAbfSDOpHnBgg5yuf2Ipt45h54Y25fj8KBh3faLmrzRv0kLws\r\nN4UmBysU7mMQJb6toCqlRYu74Ul+k+Eoj7sMvNoRQc1qAGGWcgvCTP+I46sT\r\nByRApSEyLR3fZIdFP3zaT8eY7GLgkemWvUzargnPggx6/ionCIlXcFn/gWpo\r\nDXgeP+5zcEfVJgXWXAqCK7e2qJnFsQBphM80Y8zSXPHD7k/TgzD1IxKpUbUN\r\nA7/9bfFEwFW/tv2WJwcciaq0rxyk6/fhC2HQe4iO4oKnot5gKxRKaaUeVw8N\r\nzeUujoZs4PaM+88yA6eoWg0O2HOxlwcQM2aPynHI2VODQCBhGJORaEBASQFm\r\n4S6K4tdEmCmNN2m1TAQn1zMSdMditgOcxZ8QofFY2PU/g4EiKD4n2PubNVai\r\nuZNtSMJwVXaaEYoYOGEOoXFHy2pWUsMr3VlE1e6JXD2ofrP6gLuIMEosTIZi\r\nkQ4ssaGbmOoG9it8NLLld0WjbmkYtYQs3CU=\r\n=95Ix\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"424fc08c773c5000151731bee5fac3022ae7e08e","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.167+424fc08c7","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_3.2.1-canary.167_1667462245793_0.5135237957640768","host":"s3://npm-registry-packages"}},"3.2.1-canary.168":{"name":"@redwoodjs/auth-providers-web","version":"3.2.1-canary.168","license":"MIT","_id":"@redwoodjs/auth-providers-web@3.2.1-canary.168","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"b0e956857f561bf7fc589b48e9723420f63e8f1d","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-3.2.1-canary.168.tgz","fileCount":49,"integrity":"sha512-HzbqAO+LDK6dt6xx0yzv2omweJXYBgOyDmMbAxlNPioL03Izo5mRsq2HriSDuK6W32xxgigeDGHnMKWxvqE1dQ==","signatures":[{"sig":"MEYCIQC+50eVatH2kDiJ63cATrzzxBwlv9nHT3NOQiEc1fk8fgIhAIrIZWra4B05EB0yuxFvULp9IfOeLUGjz5o+Gcj7q7tx","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjZCrNACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmooCBAAighXlDAw8bbDz6I1BrzaPQYUsoWiYtG2eSp+T9+rM9zfzirw\r\nTKEckTlKLxv+6iVZzwuwoI2wLtyyETym04T7MLxs8e4U0TQWQRzRFQgmMs1Y\r\np8T17IrUPbxM8C3vU0vetddDK+kguECVkdhGMkP2bBxwGHHd7IfIQQofUfKW\r\nuRHOOtF8glI3dmmQ4GdMVL4BLjmJHuBhQz55h425vOrlyCGZ6Cdr+5v8GY9j\r\nv+/zvObuPmVb+QSs5kU/rL970sXScM4ksXBXAtE8H9FnAjmfMXxt3I3oPJ9J\r\nZB0jpk1TZhqvsUF/MyAoG5Ye3eNHL0bIWkeAIvcwIxzaMm7UziGJe14rtyoF\r\n5hUTdnbjArN/MyhoL115ClZlY9qEuvLbjbWzBEDY6Jh7PzDkHY5kBDv1XFx3\r\nLHfc6bJmi56A410SG2dB2WLeVHPawhntDO5XdZTztV9sVcZqQZ3FRJR2Ta84\r\nqoSg+2NnA0105G7i6/v6okebavlBdoEA/dxW6Gc/T766oicgiaQpN7msugC5\r\neOO2RwbmvUCFyKPCM4b1xUClJuXfM8wxOI071m1Crcbwya+oXz7ZcRdfHyl9\r\nie1ONQF1N8J30qNeg0OEgPpjJOilxvXT0OmBNED+u3Dz74zsxry8Tp0H8EQL\r\nsMD5YvYnV5+3F1WBVMu+9RAtyc94tNl0McQ=\r\n=nWZ9\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"b051e6f1a00a0fcd6e65f735f63abab23d637255","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.168+b051e6f1a","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_3.2.1-canary.168_1667508941071_0.8872797897373985","host":"s3://npm-registry-packages"}},"3.2.1-canary.169":{"name":"@redwoodjs/auth-providers-web","version":"3.2.1-canary.169","license":"MIT","_id":"@redwoodjs/auth-providers-web@3.2.1-canary.169","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"fd95aa8f1b08079e39b25b92adc2d9e56b0ff2d2","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-3.2.1-canary.169.tgz","fileCount":49,"integrity":"sha512-jYPRq+BDRjANLxqNm2/gISXvoi6E2TRbNhbMaQGc9W6WNrRvp6y6eE2mIGkB8UoE3LZH/dMMwDkwppfMhDg9IA==","signatures":[{"sig":"MEYCIQCZ/+jIt1vwbQ3BEHiiwvnxHDIgJqR9w763CRX3Ys1X6wIhAMBHkyt3wE8I8G5Unw3AVNbJAzzsdn1WORkRF/frdX9O","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjZDZGACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmp1wg/9FvxJEmJ++xxNr9IitDb7od5GRtge0av8E3rofiUIxF0aFpPk\r\nUheu2vphKPgmVGG5VvupPI0SH9xcQbn8Mk4owYEr6gf4wN3Kr7JlUR69tJ8c\r\njzt8lNB5bv3QwMhh4W2YysVOrMrmLIatZGTk35YYGUexqe5SU2L9JDu310Oz\r\nf/k5sIilw1mR2Y6oln5cL5k+bhQ7AduGypA2oACdudCdog7++tFkvxEJC9JG\r\nlXyftQi+OS1jB1444UGun1eTcQ460kp01zIbnSnpE1dQpXRupslkq6+tDuM6\r\nI/wwfK93HpLRwXz7Y75hTyxDFC2cP6pT8RiV1HGSoLk4uSnrjl1hLBAdC9Wz\r\nhBc5RQwit7hKpnLmqOEKPCyvg4ng9LK0dG2Saoqgm29asqPctiFyufQuNm7j\r\n29QDD92mqmPdu56rsTri9CpFWHAHYoAAHmmP+Ifwd3c00uM7xACCQ+Z3IcfB\r\nhQeRSi90wJL8SGlVrC2Oh8TSoyjawnbr8xSxk2tJ7HD0Z8DICMtm/vlCw5Zf\r\n05SnjQa6f/+th4XbJb9RDmAfT4nllPNp5SdcqwJq1AQjczWvD/+UbDQvXD3v\r\n0xm1vVhZu2fCxJNAsi0pb23aYVXNDd5IU7suaf2I685vthnPSFBnhse6HraG\r\ndZekZR/PATm4JRgcbHiNqTf0PQW0Z0OmqgM=\r\n=6NYI\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"d6f6aba40317ad21b32295112cd1f5c62039f35f","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.2.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.169+d6f6aba40","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_3.2.1-canary.169_1667511877838_0.4805476149652774","host":"s3://npm-registry-packages"}},"3.2.1-canary.170":{"name":"@redwoodjs/auth-providers-web","version":"3.2.1-canary.170","license":"MIT","_id":"@redwoodjs/auth-providers-web@3.2.1-canary.170","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"8d11155d58cdb3937a70f7e1496ed21f660d2a39","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-3.2.1-canary.170.tgz","fileCount":49,"integrity":"sha512-8cRwRPyuqHQoxu/KBrX6+zPG4yy4I1hMs4/EYgpfRfd9qYTpq+fWJtsBeq4yyvxr1pctTms6F77R8m+lDho5Pw==","signatures":[{"sig":"MEUCIQCwaHy0gtUhTD3vZyQgKbXgZu2P2PNIceKzhmqikzocowIgNSvRNWps4FU1vWC24AWSuyJSlj5z76jqcbkVfW/IWGg=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjZDoFACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmorIxAAjK9/ag/0lOt+6Vv3K7vf9Nj35l5i4L2mwlEt9Twh8NVFLMB6\r\n9S2VJ6cI2CQLn30QRPJZ+eeKEEZAPRac8JA0gzWxPsKZJCp4ugBvfq5xyBO1\r\n+Wq4ITtxU0NtoSO3ERG9Wz84jG97GQVdX/EpH1Zjs3gwQ4kdOnVp+1Wyn0kg\r\nzmaELNqmsUjDrbefbr4olTuoRqC130B1ovr4uzxpcDldfqWAvLKJpl2gFYNw\r\nukbedEP56ZmZ0zei86b4M4NCrUU9n8f70GsLQGZJ/PCx28u24Ce4Df5j+PUX\r\n3D2bSi3jPs8toq1zdy/g+fVdJcVRSL36e2JTaZu5Jf368tUmJw0esQPw0xgt\r\nBSyAqoWdlRNd9QgEXAkp+7fGOYseYW3P8VGsZq+1M/FgIFD/conabvFeRMBe\r\ndOveKNzysvABHL6JVgipI4efsRLncaskIi6CpBMOWWekVKV9ihkpfng0mkKH\r\nDTs92Ian1cMLt8hW3doOolw0VMIxqPMpnBNerbyGIFi9YZqghM6fVKmnFvZK\r\nMXSdOBgVR8j+TSNSBPflAEMiYO3IoCKTw4GJ2JVomfdCstTqfshFPufVQZ++\r\nWbKquWyrdHJjUreVJSYy3QB5wdRiIG43DeCJSYcn2ZvUIdqTpm5htX8aCTU7\r\nSry+JVghkPD6deEdbwk1gl18kojF6JAfkos=\r\n=OgWl\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"8b90a78ee5614dc8f02054be7d38c3aa68e999b0","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.2.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.170+8b90a78ee","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_3.2.1-canary.170_1667512836893_0.5657867078440739","host":"s3://npm-registry-packages"}},"3.2.1-canary.171":{"name":"@redwoodjs/auth-providers-web","version":"3.2.1-canary.171","license":"MIT","_id":"@redwoodjs/auth-providers-web@3.2.1-canary.171","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"6406ca2c2fe08a30ed258382418688ca56a8fd74","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-3.2.1-canary.171.tgz","fileCount":49,"integrity":"sha512-JCaiJy55geTezxmXgouFbV7cUok0ZXl9fYjc74YsYkrbpttjHLIE/AcjpZqQjLOPd8+MPYg9Lg1adPaap4vGUw==","signatures":[{"sig":"MEYCIQCEumA/kg2FYzwbTGE/W/FtMC+37eb26cbpnh88binNfgIhAP1s164FLm4jy6pPsKIOgvCqULDHT+edvl5/QSfrYU6n","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjZDqTACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmq7lxAAjUhoOUNE1xUNDu5Fg87prGz5rzlwd04J+AHk1HkCWnLMMyQk\r\nu1Bhknsp48tAG6Uf88pKe+GTX8F2gDun3335fDxXc99dE3zM75UE2L1wfnMc\r\nK0/qPOWqIv3FdBWyXT16D2PaBfIm8V9mJVryeszLqlnhI4u15YCGOFmnG99R\r\nNZis0Z0VG0sxKz+ddNdK5v3k9V+EnTYuZKRea8PB6ntm1A+9PyM9CHda5rG/\r\nHHSqgjgOxJsedhHvjtiqdlHQtALCr+APqFp3PDfPJpTfzRBHH8eauY0I1rJX\r\nVsOItfKGi9bwCIHOk+wC6hhsZ+GoHvinH/c83xFaeM7D6U8RPHU+cT3OkySz\r\ns2W4K+HBtbesjKXMcw4mnImZ4sEcHgAcVtYJb5aa3FW2Ye6TSZQmKuV/JWT/\r\nqaS61FF3tveQJt/N6tmfOlOEtXMlnDTs3XqDl+DqH8dxttMbI6lW5H2M6Iak\r\nqfI+7f+igzL3pDb7QaA02wGpBLnrJ+W9MYww007qQ9+xFJztNH97IoKfZnZO\r\npNsp+bODJ5RHkURP3Q3MWoGSOjGWMJXxVY7P9OXWWV874X1bcYv0aQBBJPA6\r\nYp6vLk7+c+O//UYUW5ShwwqTauRFTnZGrSlSY1OJNZsKu5rqUo93tg9W5Yvm\r\n928RMgqtJvbAy4PoSp+sEtX9kya+cmrdDUI=\r\n=dNYi\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"82780aeeb39475212db4430e0b08f92539f685bf","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.2.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.171+82780aeeb","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_3.2.1-canary.171_1667512979478_0.9925050248390079","host":"s3://npm-registry-packages"}},"4.0.0-canary.172":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.172","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.172","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"f72419e750fca1f21760e18c9c476863f14de10a","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.172.tgz","fileCount":49,"integrity":"sha512-Pmk45duphTaWbdD06CCa59Ip6DHG+VD8iX6OPl4NgrDdvgN/pw4T0d5Se7RGCGPwBK+sfupOFZ4MR4iCFlZQOg==","signatures":[{"sig":"MEQCIEobGbzJDrRltoAoowGVvA4kaoShJ3LzIX94I0pRofP+AiB6Rrp6DMJ9dcv73imPdI3xf2ZDqZUFJsCgcG4kB8RA+A==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjZD9DACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoI0A/+IqSFy/H17nzmSJKvefOVxMwKiOuglB6SDl5EdEkbyKvHNpgw\r\n4e3MARrP4rsRE7qJky+n3y3mIhVMTspz+110blXxM3pK0m1AR1QZhyJzKEaL\r\nWqejIQ2YYljzti0RsGKYv08Nf+nn3rRdvt20rX6ifUxYndu5dvjdMyGrJIjl\r\npAKT/LH7NwOFyciDQlJs9s07A9IX+VuuBLvtSLi4HNkb+dmxvk1wZUlarSAu\r\n6krkux6E+PPiY7qC10hJ/9SUE+R/ZpNof3jdzUmgd5SvUbZ313grSDF8Bxug\r\nosAvOmHv7fNwbI83L2NRHtXnINLh8RmMkIu0k+2omhb/12HGWKLhpgp5w3en\r\nRyDg7mkAEdkyBGLrFIVSMcdKC+ISL/59dS5AL5bkUCxQb1z9nfuvg2snhoZX\r\nR5CbO4/0h7xd+p0kMa4i01D0r0cwhNAfOXmTu4L0HoKPHg/uEWawmYFqSyfY\r\nwSuWagSzQ3QBAd7s5ykndfP5yRNw+BLajn96CE2pesK61moMmZau+GPqAArj\r\n/vnjBIMhQ5tTjMHGpHSH21mWm38aZggWliRlgj+ihavFc/npYqXuwM7sUDcl\r\nmSoreGDNcenRjJfZRvhJq6fPW6/iLA5BnyN4tghZN7jN3QTOWl5PraBMp1Oj\r\neGsu1V1Al4rfWxkfMos5wsSm7ztMgbVy354=\r\n=3q/t\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"45ffcefc23fe8518a7f762ef21e223cb399758bd","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.2.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.172+45ffcefc2","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.172_1667514179002_0.10105378127740394","host":"s3://npm-registry-packages"}},"4.0.0-canary.173":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.173","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.173","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"7c84b25a6c695979e0b934be9295c8c7c63a3902","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.173.tgz","fileCount":49,"integrity":"sha512-LYSFoBlc4TuKVinSyI6P7kdQRi1NetkqHCZFblF6lo9cZuC3K28iW/Kfwb6qlC0q9mUnWJiPvHRyengrKrwZNw==","signatures":[{"sig":"MEUCIQDgco64Svo6gqQ4Z3ebTMy159TLbBRGRFMkUN/uf/6sZQIgcSjjpmfFoXXQDQn+kXNasCBOV6hxfRrnjvN1peIJ1+0=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjZUtwACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoRrQ//RM92yJ4jVI/tbXtHWp+TniDMc3/fLcoCK8lfEMR1YNJWvsP5\r\nJRlHb1Qu3BhKRqrOtrCUIctBnCrnL+yGlSjJVvQ/hM0+kP1DRwN77rezAQLH\r\nlRe3E6bGHW7/N/6OTjS8erjOxEfsvMPnqGOJxAQNNZZVF/0iw+yGKx5btXG/\r\nU2SxMT88hFaLLXTeFhfDGmn6IHklS6/Po3LEY8pl4XeF4JGhkfoznIoC7jiC\r\nHXFHUCEJG7vk2c3TgT1+5stt8wKxDDZnSICzc6GXLqRFao3zISslN0EmZIDW\r\njlyvv+4dj6B+UE8BEsRhL21JcqKkMEBvr3IQkIOQOZOlHSU7uHa+wtvLhr8v\r\nrGAq4bIfmqZse7035PZzneILyDTQ5U7b/C6MgvJwHxje9Ydak3vOaJwGUL4z\r\nDWwza08BwN3uQ0gv1Iu6PCR09lFt0KC1Ys9+9K1yIqYYbOiUoJYxY1v5N2V+\r\njkQpvuUfhdk+WI/FSbm9hoBvUOIHh00m1FVWkIEmkCJhvDP5oir8OgqvwU6G\r\ntYDze2iAWllhBuRK+Bto+Iy/kFiJ27T+Gs0VOaDM6Fi8+s5mc0k34Po/iEyk\r\n9pZj4mDo3IU06xA9KpEM/v2nAFCr0YwHu2hxrzNXS0ztWIfFCTX0SqFHE0K8\r\ngZvNvZHdmTy6k8flqyFa/Z0eDZWkmDdBJYc=\r\n=xBi6\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"9fe7be3a9264020f02adfdd40657d612af785477","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.2.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.173+9fe7be3a9","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.173_1667582832186_0.5659427339034815","host":"s3://npm-registry-packages"}},"4.0.0-canary.174":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.174","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.174","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"3b342d8d2621e94cfb4e55f948e0f353af144bff","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.174.tgz","fileCount":49,"integrity":"sha512-+FjFn5vvv8/O2lR20RhsjU5XWyPl+sSrGV1OABVul8K/gbx0iQdeEzAukD3FUzqrjDIRvU7x9/cYQzPevTNApg==","signatures":[{"sig":"MEQCIEiLFVBsGpD8vIs8Gkcfa8R1oWWsdhc/T4zCp2Z3HCwjAiBvz9IeF93OJtZZdJDXf43PKIXHJHHRTOdFz8U4UpkTPg==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjZWfvACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmr7KA/7B9kUxfg61VEPbOviELO7YJSC+ox3eA4auEMUxf96stV7Ykeq\r\n/bORxNIe9XzLxVxU3eCqhDyZxEBlhaFIflgR0Ke6h/uOU7UWwvZVWkAEH+ae\r\ngAYIWa/r2HijVVMVsP9gcwknIcyUcGO/+kqUSdHUvU1fspCxivkyvyFN/DCr\r\ndIWGhNmS6tMdPPUT9dTm9fJ7mAQcuJxsLeXJ2OgBuTjeqDVplfDTEISVaAb6\r\nf367SaFmJ2Umhnb6SVeCJeOk3M5oVzDr3zsKzJdjKmR3jPKjexLIvhHRt7gt\r\nNlIDopnlFUq9bzP4JTTvW639qYKg3jMYX1U8cdpPUYHx73+Tb75T20yu8HcW\r\n3MjIt06CnD5WRyOmdCtZ1fsBcqNVcr9gSzDg5zGmgK3G03Xdc44sg73EOXfl\r\ngNMFx3jNncQBskEoOeJDtsxN5Q/iBt06ztIp7uUV+x+MzFfU7PanyCt8dvl2\r\nuSqHwGj5a8aSxFYDLrW9ls/O4QD/fS3Ca+qddN/Ulufjnud6adbaF7MBCRq/\r\nv2ZCwxwspVoYLvQHX03wkhgdjB7hHdY6POBVj6dfbGCTsIFOjiDK2BAwF46U\r\nKONqeajftjKBgwhYctIt9qI4au3c96wzFdZS1RYGSMripuXMwVSCQEcLQ+No\r\n+rcu1Tg8xdUODajpBlRxTR1U64gY6aEnVo4=\r\n=6Nad\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"c072358d6687fd73c7f22d529832e070bea875bc","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.2.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.174+c072358d6","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.174_1667590127454_0.257924124542376","host":"s3://npm-registry-packages"}},"4.0.0-canary.177":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.177","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.177","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"ff6b2856c1d97084937f71cc889bdf19d3e1ab96","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.177.tgz","fileCount":49,"integrity":"sha512-u5cEIVWUOFJjw3VedtrggW8/umdLyX8Kiz5FfNA25zeB9M8IUfQHrv8k0rMDEiVDwcPvNPPFyYznU2WiBv+i2g==","signatures":[{"sig":"MEUCIQCKzYF0iTHthHWRRumZBK+lrVFcCFM+0i0AvjrOzRy+LgIgBBHXNO5AOFeoEsmMOY+3SXh7lEkFFqtMnJPc0Eip/cI=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjZhSPACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrVPQ//aQnKUAt6KzpgnD/R0jnQpdfgcx1LxV9eqPH+mP63dL+pZONQ\r\nF1ffstonrZPpjZblLAj2CV1fo9ZAVn5rJWNaLbzIoK4N+onQsPQ8czm4NsLM\r\naD34IAtpM5hlkLj26f3wH3sPYzazDRR68KtTFmg4HWWV6Z4GwCh0W8I6wG8O\r\no0Q18aRUA3cl9AidNsJQmGzHvUTZ9kkqVnPfcHFOZy3zlqimDWP1Dm4iS3cU\r\n+yxKZnK5ATG0nnvuSLXYSsLSNJZFBu051u8v3DkbZ3htYCxry2WUTvbD3Y+o\r\nwsMkzJRAaEAXu9qgghtS4lPAjrti7XA0njS87ZC6IeB2uV3XpE11Sa8QzWFb\r\nCSRosTc6teYq7mBrymBEyYPW3HHZM7yw/vJwxCWMUVT1ox1pjJswyNvrsuuB\r\nkP6nwukm3Mt2xf49x0wdlVU6OREGsYZmgbhbhrez0l6ahYKu2I+UiLVKhMdY\r\nAIjWozVSrnpnVqfGgK3dkWZ/og28goKxHIUkHzgx5O9hb1Q5eIIn+qnSeizx\r\nS6I0+GQNXHtvI4SzLwKBEDl7v5PO33OOho9HOj4BqnF27yCyo4AaoGqA7+EP\r\nR7QkJqvRHAVl7LRChe03lEz9lCGLozTQYPWnQfW5C7beSgtxNCMnNzwjQKp3\r\nMJGl9gS0VXydi3t/M9U33g3r1iiz3ebvmR4=\r\n=2ZtE\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"d75569e86c018ce458d3c850da0f03297b498572","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.2.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.177+d75569e86","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.177_1667634319206_0.947208238000744","host":"s3://npm-registry-packages"}},"4.0.0-canary.178":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.178","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.178","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"8576aa5bb5b1c02888cb8c4dbd0c65ac79961288","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.178.tgz","fileCount":49,"integrity":"sha512-J50+UNweVWw8ps/35iif4vOgqgry9fuMQT7q+PoGDKYrnehHwKNpFHX5lDk9CZNLGf8tnkLgcsnlscqOwh3yXA==","signatures":[{"sig":"MEYCIQDXbcDsIxC/X4A9Qz5yQjPTLyFnjjU297bbnMFgddfoWQIhALrlXE1TtYa1UG3eve24pthHDemXzjNd9NoDXMKWczvd","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjZjtFACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmr6qA/+IQ+PEfdx8gU/vFLvx1EQ+eee57sq58RVZpst/ntmub4dMgSq\r\n3GuLoS0H/qK533BblKyRV4L6NurK6LF6MAnP/jfZBUtH4IPxceHKZ4cIbUc/\r\nDxuHz4/0N9wdmeWPQktqWA+mmyAli+/xQyTfJ+nITEKoz/NaWKk3dNkNLgWP\r\nNq3jmeXNXnl7VbT6HqS5SRl9d/Nlm8XEKdK+YpyjLQ3lN6tjL5gJbhXbAjRV\r\njFIs0HE9ijg4eKlz+hNNBP+rMEtNps5hal1KJsWrFPBRFpVKxPs1XfcfB4ij\r\nwbaNw2EvxG7m171DeCR7W4VwvbBgGbVsAB5yg34R3kz58M6RrjdVMKhDyLsi\r\nM+9gVT/ggpIRCBtHjuGWJCQOGGwRM34YyywMBXcSJP7n6+SHx6Bhd93YvO4x\r\nQGT/2S85M2gMxL97Lrb26eSEGA0xq7/ZKrP7VOA9vuM5UMJjgvZs9d9kg8B+\r\nxm5pB4hsUc7hnyK0bnKSTdFtRB3mgIYGeh78GFBATUhIyI0CV6TZg5pk9v0a\r\n6oQL6E55WQkgfnQWswQ0l86/vnAU2dURCh4qZUFewJlZdjLnTlTtqnMEWt6r\r\n0fmWKiGf8Y9SO5/FkmT+iDlnZFxDuhArg+uXBYQg7yQGMCfR3N5M6WAwm4FG\r\n+95+ktsXE8aco2fZ6aN/g38IQGTxStjW+Gc=\r\n=G2pE\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"16ce2b034292fb3bc864e474a8a95a1ce70fed60","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.2.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.178+16ce2b034","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.178_1667644229398_0.0010298483118758028","host":"s3://npm-registry-packages"}},"4.0.0-canary.179":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.179","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.179","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"055c493456347700ff4cd13e2845b1f7fa025f88","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.179.tgz","fileCount":49,"integrity":"sha512-NffrFmfgr+h0UfIaltkrk8McwIOLS6Abhwe/4+hy7DxMT816nWxYDSWAUwm0Ky7Wxe6KijVciBOW2BrJP0jLkA==","signatures":[{"sig":"MEUCIQCVOHbdhdPB2K67Ddnf+bBL9PJMf7POo9wEblaMzdlxPAIgO/o4gUVgG4iIzC30TdJeJJdjepnW9jsAGQhVDD7CceE=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjZrBXACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmopoRAApQ0J4u2nUmrGcE35qaEll8ftrXwjw6uMiamLGIAHf6G2IBsI\r\n9ZArR6m488bIsA592za9gGs4u5iGCzh/hzwJtZOnSo7mRd5xsUqmGK5X8QcD\r\nWTlU7vwch3JX3a7l6xiy5p2xgTiDJQ0EA4n3xuIXOH6n3xWVoI7LiO84niCL\r\n/j7vE/V/r7iVjkZKBTTotA6O58qEor+Ms2Fd45ncPRqOkatoegq9beOz+qFE\r\nuIlj/LetN1+6uql5/iVV7NfGT4CdNUD9nMQDZi1KVmV45L8GtQ1/0F66wuk1\r\nBkRLipKlwhM5cOEgt3pPkWdwZmWqV6yumJ4SHfrw5I4c+ayo/gQPt3/OO8w5\r\nv2psjTHRzEhINFm/rX5vVj0YBPCIHrF1sk13UMNZ0mj6nC/KwHg3obseQgFU\r\nVCA7J/kBb5vF+SpkwgIRiDztIOdvrlxucTn66AX6ctHtUzLJaCAkx9LR+EXo\r\nenDwgyXuZ+n4wsQGhdR7NWMTaz46oa2UVCGx/Y7+4o++WaUJv9iQULs2o72w\r\nosgSDax6A3L9O60/GTKI1IOpH0ahCpIfizTVcAKD90+dOqkc5FinCKUagGP/\r\n1opmjcyg4bEHx2BtUz/i8gSx3WvGV2iukIacfbZeUv/90/5/vO5RW3O2lx7r\r\nroaZnVqMU72bPEvzvPtLu1UDzTlBcnh26zg=\r\n=Tsz4\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"c7ce6d6ac4c608609cf70a1777078bccd15edab5","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.2.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.179+c7ce6d6ac","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.179_1667674198781_0.8313724316236601","host":"s3://npm-registry-packages"}},"4.0.0-canary.180":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.180","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.180","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"1dc7f17de9dfa0bad30a93f33f21e616202d9ae5","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.180.tgz","fileCount":49,"integrity":"sha512-c7Uw2lw0sgtqKv1C4/4/kawp+7SlYzAGsKOHFjbM9AYwBnNPl39X2pcx/pA7U2fOC342c6ESHJ7XjbZWSIJYhg==","signatures":[{"sig":"MEQCIQDfD3X8kQ6AQbnvPjLqHwLBpR/+PD/L3XMQFgEjEh04fwIfQs3cPGRyfMqSaj40SPwL8dqNVV5jeQmuo7sISemmfg==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjZvyYACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpF5w//f1aPBrpmb1ffyPUMjhvigXqOoBPi5CDmlinn7r7CSW16N8zF\r\nRBOtXI3826dcDLHZdBrRHrpT6YWf59/vOBcp5Uq2SCgxMxkPs56w+c3pc2yN\r\nbizCwNvoJUVlt9ChMYOCjxmJ+k/f/wkiu+xC58nIIE9rWOpZugkuC+0hFUpz\r\nhDhTxjZaNV5ZAFO34l/OSrHWriYFsOI33ADQRIqr3cYDeBAHj+wJynU8APYE\r\nk7GPa+/jpw93pIb+Fc8sFIcPy02jc/do2O8Spr0Uw6X2dw73ZJj7CP8Tg7KF\r\nRGT9wI3K0gHEiwhXHE+b6aIcLNxwx5cyMbfQgzi52sbvtHdF2iIYKHe4SgPE\r\nsGmhfoo7uCbKiSjr766UHHMazES+95LmCx+HC2KPdTkLGcWeHax5uSYl+TwB\r\nTPVP+zv7/ygZQbR3UQGge0gaMjFSfQk2sC38cPSVSwhXbt5ymNLQixU03bfA\r\nK6eb0dGzVnwA7eFcJIsPRTIod1WRfjf7GcrTthG7VCQYPV/VMj1A+r2iu3UZ\r\nor3SarN44gru50AIohpVMl7IM3F08V4tk/v/UfanX8EePTspqjdYxy71KwPX\r\nkuIyFRKb1BrnWeQujtIVfazrWNvcBrvd3SuIfX65sSYRZL5pPhR18dgdZYPb\r\nTyFT8cnTEN2D2oiXGK89wKJi3uGkqgizCoA=\r\n=ylyy\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"8c8443747b0a5c8d7b19e72863cf6aea88d6fd4b","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.2.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.180+8c8443747","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.180_1667693719965_0.3225611497702001","host":"s3://npm-registry-packages"}},"4.0.0-canary.182":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.182","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.182","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"ab3b061f206bfbea9394125351068da14a866843","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.182.tgz","fileCount":49,"integrity":"sha512-Q480Ki/p3n8BBEv9Do0BVgqCp+zexg2aTD+AFDwYTGGwwjwV1vVqEyf1cD5DLa8jHpJp52G3Hs29JhiO6sBc/w==","signatures":[{"sig":"MEQCIGzMr4DAYOoOhTmbMUa/5PHDlV21b4fGLLubLG5aT8RVAiBWQ3EFLVJD93397jHg4Kgx1qXWqatDecbE5IA6H44L+A==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjaUIOACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmp6IA//a7x1gsNuuQFH9NvXqXIR9E1RyZ9KXtXBiQ9SSRBqWAfdwLxF\r\ndrgYoHDqF2JcWuFoz4bRR/7e1JH/15raysuiIVNQCov38tpncqKtYTtMqSPj\r\nIGG3+olAYB2qDuNV4brtYyUdCIwVWSDcEOL7zHLf0I9sPs7jHnRINlnuCysu\r\nGcitIQxACjDm/40TkOIyjJdsNxqQ/uT4xY5/iqNcohjptKDYI6v9FYgqNnlj\r\nMsDEX5RTYrEUK2HEZkwcVE2CyTUGnurZ83WggaL+xSEP6A2+dYSFHGTh3i0e\r\nEuXHr1Q/7osJhfMVPfLmD088Aj/qeVvL0iyaqYSP+oTCCBqvizdhfAywIjP0\r\n8O/mzjvjc+rGGu9uQfMqZHW1opzyZHh3I0n+XJtBnPA3sZ+TXzKmLr909vFS\r\nXlUOV5SFDOc+EKRd03mlZVPiu3WVl/TT24+tSQHqwLZP/or2r+kukzar/7jQ\r\nj+4nIrj/9ympE8EpAWp2cfeyh90j6JMDPMf8Xw6nTqEybqyIdV09OBa0C2tL\r\n84InIJVO5QbquWcIzqWvV8fic1wjL821tWNTYraEZ6eg05W+GSosuIEA8GXW\r\niLJIefwJgKmevABcxNYsnYda0IQOg5sl4jdOjsQmqRHYBR0TPF0Fu3C5v1SR\r\nXBZKOD4XlaJrqfY4UZq0yhxxiWMXR/Ozd4A=\r\n=gjVK\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"176fa01e13b8d0f2cc39239b74ef19c4a324642d","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.2.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.182+176fa01e1","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.182_1667842574744_0.0737233205516219","host":"s3://npm-registry-packages"}},"4.0.0-canary.184":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.184","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.184","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"df073ebb52c4d9454eb8a1b187ef6589cc377c69","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.184.tgz","fileCount":49,"integrity":"sha512-OCQ4rftpOPZW03xupbJ/l99yFrjq9vxtLm2zC2eqDza/jeSoviMjmb1TM4GU9lll4n24TidxQS2VrD36+U7iWQ==","signatures":[{"sig":"MEYCIQClNsEsBtMzEs/FNiMq8PM5ovfLCNhebM7NBofpilCwUQIhAIwyAmV7MFck2xHueBrUqa4s6ZVCrPSrkhEKBZoUQhG1","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjag2HACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqU5A//Wjxex4QqcjCKmPtFD+ifmpaZmzaebObT7b5QetTD0cpG+Nnz\r\ni9sQDduiVgjbIZP4WV4VlnfVEFu/uK6UbFyTfYFdcV7AhC5Fw5brSP0iFkq2\r\nv6804/mH0dMUwRFI+pzN7JsBxHuXqV7E5tgKMnFSOKgJb0j+MoZzPcrc0We7\r\nbRwxVbHhwE3cgdbMpo4n2xFVgGhLJcHhvlI4IsSVdZYju7btGtjfrRkWgvv0\r\nXnyVM0fNmtSrGvDlnYthCJGwVRWs6bJKmF32kXLnwuVDMbGKRx3FaEzGjrKR\r\n5x2yrALwik46wcCWXqagkIUPsf2oB2Mg5wpzT9/iQXdfl59fE/gzZ34ZdB7w\r\nIoc+bf8YGjaioo+REd6NQ2J03uvGt4pl6rDlg5DaJS1c42a3JHzqT5+M8ase\r\nvvFk0G/r99FekJohdO/zUVg+bd8y/jeGYsCECerQMrOOxO8T7fbwxE3K8F/h\r\nrZdK6RaGJ9g8CKmVKYEbSj8zUZDQijJf7m4eCcwKykyfitHVgBx6Uz+7C7H0\r\nUESJLAflhylGT6X5UCD/zmLo9UHsKtq2gDb7vwp5f272D6cnDMWBzKtjnwGw\r\nt3WSafPvP5NlTRV9GIcUni3glwwm46PhE0+SqcDyig+0D2gZvvgj1GssaYlg\r\n40Ywz9VuZMEgFGsLR6e1jqLSeKPiFzi+w9s=\r\n=sCm4\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"1354090a940de2387ec8d87c4bd48c5c437078c7","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.2.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.184+1354090a9","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.184_1667894663782_0.29541726062703755","host":"s3://npm-registry-packages"}},"4.0.0-canary.185":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.185","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.185","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"074f46cd1a40990c6b77663e592a29122ca43284","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.185.tgz","fileCount":49,"integrity":"sha512-9BdVxa0xrb4NoihpGvBhn8oli0rjW2HY9ownsInydWGU5B879EoEQi+mqA7EKvKpFAiLlxrF/dKHG6a0eNUPQg==","signatures":[{"sig":"MEQCIAMxDDh/B2qSIMOO/Xt/wLURUnleVOMjnofJzfExKx8PAiA69cVmFNJxbQTRwe9syCd5z2n5w8nJDBtF26AD9IrU3Q==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjalygACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmr1dA/+OJ27HHUjvqwd/GhKIRwoys57FtNieVsBKsws6lWzPXa0FGBs\r\nOpQ8B5fbwhjTqOqIZKQHGZGz316G+v0ab+tt3ZhEhTa8Z7h1yTZhYlUFnkjm\r\nBLvAhGhioqqc0q8BEazcl3tvnLT4mVpFmv5mtVHm4dJx2aJ6fAoYBOvfFS0u\r\nXS/uOXBJz8r3SiNIq+rCGUqtCG/mKzRskMMWBPQgMVHYVb3Xqb2RcR/rz87G\r\nn3NdEjWWgNusGX4fAjQ2zSxMqw4EmY+/gekWZzHCbwHQnQhQqdlw0YKimtyo\r\n0dnGIHBVqRuQR/5TMhzU3WwrSxF94F1SanSvnPXtuvmarYswbtJXNA3i2xGC\r\nrZ5kX7xeopHzCAZ38owCvkzeWqXkCTMVeaNQr5CvfSQ5SVLEFE7d+JdNdtLb\r\n4q8Vcr2a9dUyuvLLG7akXoJmg93ikiKzscjxmsAovv6y0FP/SjmvyC6/4kx0\r\nKd7f5LhXnAmc5V5EycFUTZ7h1/WtOqJJzNXwJo8ZWtrqbvbj/wZvQSABabW3\r\n8dnFORm8ztiiK43lk9Wj3Ev0+BTngFyrnkRiiQyokgLBgy/f7L0YySOeuZaq\r\nTsVMuU7YysjrpqY3YFoY2ZCzaNGiijgnnjLMmwMTPe/3uuD4wkdAQY+SwA6O\r\nqiPqAlcd9G2l47pUSynTwj0IeVwqPZi25Zs=\r\n=qrd8\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"c2275948bd90152979ea3a0feb87021a67babcef","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.2.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.185+c2275948b","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.185_1667914912456_0.3600686753706568","host":"s3://npm-registry-packages"}},"4.0.0-canary.186":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.186","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.186","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"c469ada5dc075128eb54d488b4c699cfb9985682","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.186.tgz","fileCount":49,"integrity":"sha512-HVofdXdWrT4sBoz7euENzZX0oHg0ItdHKEPwbv1qlbh7UKAiiP5rjZsr05VXwBZc9/fDl1kIj62wp1yN82zhlw==","signatures":[{"sig":"MEUCIG37oTxZxNt6aBanWh1IVmUPAsEZ8PcUmsIFaSRm457tAiEA4YOHOS/ya9OK3U/HvOuTOpaktBne+FaJsoC7u4FRvMw=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjao2vACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqEGg/9EMBOiJTAwCKDLFD+VdPZdqanLohTidm7BH4Px9565gnvB/Td\r\n3bbytMwd/y0kpHUYLxcD/rZSAZFiXjAu9iuqibtsezXIBACOpY8cS0snpUhE\r\nkPyoA1rAQybtUu2n0847/U2jQ7u1x4TwiHpt8Y3+LSMeZ6MuzCRTjwAma2YW\r\nkG1Rn3Vr0HVceH4A1y2ahosbPoQrXuzBmx1FZIwVJ7pE4a+L9NOMrh/ugXES\r\n2GSlSQyhIvpl+CdBoZELKF4mHf4Rx8GrJHe7Py+8VwELzeson38wt4yYL1TY\r\n0PKMFxlF1YZLRnTXnCcS/tmmuwq5JsGC3SHZau/3W0nqGCAu9bcuQUGYqEVP\r\nZ0CA61pcbQcfX1C86lWeCzqFLI3lQFDj0IbfVC0Knq+Ny6WDnPPOv/j6of/o\r\njxV9iHRTE6vlv+jBC4pRQ724KVbUVGkPbocAZ9yEcPY5zJYJ1j7JX7XvHqco\r\nDUjtA+k0rwA/WMgKuFP1CU8NNdqtAD14zByzGpZIkvgwEyITsdBkD5nMuB6+\r\nD/HEE60uyc/RcThq0hbsdz0IXdnpbVlKqhe2/7CDHNOTFlJ2vST1FbWEsTy6\r\n9KO7y3tyrVz0Z5jKzxdET/wbpZZe7sW4wKNdP6uZBJZuGZkUhNbmjz4UdHcC\r\njE5zPL9gh2SmwL2Ec5/XIUPHosZrQ7OwEL0=\r\n=2X63\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"49a12590cf0dbfc55fef0b7f356c23a58f3b536e","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.2.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.186+49a12590c","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.186_1667927470819_0.7734375904668989","host":"s3://npm-registry-packages"}},"4.0.0-canary.187":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.187","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.187","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"09f9a147fd8a56d5d7cd7338ed538f87c7794b0d","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.187.tgz","fileCount":49,"integrity":"sha512-2yHF+MEBU5X+XEZLu9oc4gL9Gg8ugtVG31ZOyBD70VjHF/GdcrTyT6oj3gPgeAUepJn+8dK58473MNDuxoffhA==","signatures":[{"sig":"MEYCIQDLfDk2wpS3SM4YhuSFsrfsOhNgOyFIpqcAOY9txYdmtQIhAJrJWjE3POB3q9cLdZwsaqWXeoErgwRepEmPvSVx3cfZ","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjar4cACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmra3RAAmlMPdhpMDPlO02Q47xB6sgefu3QYEKGaObncpoBaakUpJQTr\r\niOPZ0xlagLBX3/W7FhzOm7db7xSNeOgymmiRKrrxhb9lJ5gNKyFTUU0I5pxK\r\naQNm1uhdeGCoioKRRhTMcO47Tps9yb8WiFlG/odTttzB9/YICX+1rYGi8Cis\r\nLkRHmzXML2txxMbKTHxLl+t34cbldy6QAVopdk4gnIJJtcapTDZ0iVhd4gFw\r\n4ZPdzcgUsueMXHjvAkicLjHb03VatM5sKdUXTnfHM+xjUnepvntzD/FVqTPX\r\nBC5TbYIznGMPMC/soC77M8lbJabXApZh+7qhuea6jUczixatITZFGVaQaE9w\r\nktlDz6PVndX36XT2MExpmyJsHzh/QDf4VHi9KLmxEPwWsVM7i+XiCuE1dwTe\r\nFu2qVHSKKe8S0IOqkr/b7RekyoJA+3NLOXFU/T6o+agF2FHtf9ZRt30fDKUC\r\nDmFAlmGVzuGkWsixog3hqBF697xnmLM+ExvhsYUIqJa+BcoY6iKOzxeLwtuw\r\nyFRB0g6Fu4x2wSkK604vTK+K4wndRE4+N2kDnhBFy6VQMyL2Kt2JSg5dSFBK\r\nAvTHEw12PAsemaCAAKH9qqVwA2xAWxBjAQe3i8i32lvUGiKplptlzmtopUlj\r\nIjEOOzJLc+ztXgHIk+cc3S4mnSlDrcwDrPQ=\r\n=f5jY\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"a0b262d0bd4dc9df3b79ff6675c5a33b10c2daac","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.2.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.187+a0b262d0b","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.187_1667939868441_0.5734247901873988","host":"s3://npm-registry-packages"}},"4.0.0-canary.188":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.188","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.188","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"e5a1e84231ad18c42dd98c5247c1508f5aac6df8","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.188.tgz","fileCount":49,"integrity":"sha512-o1Qv72OokwuZjeJ8LctrCNtaaHogd9OHhBp4DOD22YWF18uM7IAlUPiWi56o2tVb95patjEPEporkQoQDOy7Uw==","signatures":[{"sig":"MEYCIQCkG2aI5zM0wJrQ8Ypw7m2hYzEis/3A8AGaIceXxpylhAIhAK7yaVFRVck872eGS327NRB1RpoXtYoPS99KEByXdPMq","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjasspACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrGjw/+Ja/jQ+L8AvrexzXBMEm5EP11OW5ZN0w8N6azHX1jNK3MQW5Y\r\nNuPkyZq0ogozNv59c2mEUOqhxzzSPcAFfyn1sn2m+7KI+0B+fvhHOZEL2hEF\r\nPP3iYaZKHVZ2P9Q+606+Mu/x6z6duB82Rqp9L+imtshAlypLlExNKa0jf1AW\r\nUHKr/j41svfLthQl5xUwkzIeNql1BvPCLLcN6r6TUYaU2qC4kffCqR1z1sV+\r\nv4OQNYPu0sbN5kDwMCRjqKB7K7/BZHnVOkA9VQii4VnL7QjHvFS8AaQ2l624\r\nViIqKYR/KuoJoKYJORMfUQ0hgz2Ef1Al9qNkeF9hNOvy2dNz9r2nHtPfYcYh\r\nyWQV4Yw/YYXmYCS71ODo5HiXhX8ygGJz5woagzT6STr6sLR/W4afnFUlmf5H\r\neOIrej+RcGGP2NiFuStKyBJr3FjMQbRDgW0PIcAN7G2HYsx7xsFNBzqtq6Vq\r\n6O2RlQYn93jCBxoFI0Toa7zoiQblxzwChJh9Z6+ObUpJoyAZVz7erYTm1S7D\r\nWL61qQj0woGP2Y5h20ctXuXEk2IwWc5tT/KLfyP5G0WZKHKeGlM5sceRp51Q\r\nZSkHjxzOgkwVgacs4ex+m3n1rgcvGM5S7hulydJ2OXyAf4a2RkJPQ6WOjYOz\r\ntonfKVzdmkVOB5lRAAjSBlGYA8AKKSRSu88=\r\n=VMe2\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"ca4f2bdb5359beff51d859ad8d37f8a49ba7f393","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.0","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.188+ca4f2bdb5","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.188_1667943209608_0.8084039735508342","host":"s3://npm-registry-packages"}},"4.0.0-canary.189":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.189","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.189","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"41329e4cd93fa56ee62604cca579aadf84d6b20b","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.189.tgz","fileCount":49,"integrity":"sha512-/Wj+yJJUeAu7RsKID7idSYQszrM++bm6N1A/Fby+CXx6KjEx7l4pOHzr3rOcesFSP3y5LW54AY3uX7b/eaNnzQ==","signatures":[{"sig":"MEUCIQDDZStzJCO019qyxV6KIlBO5sHdiS4iizJK+GrqYc1zKgIgHUiUeOgJy2egEoT+0RASz1r6bI8HY3K+m5KpHSA7rNY=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjavfDACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoTkQ/+LEtox1Edq/SvXaI4lmgy7zf2pfOuAndPaC8m138ftWGo9ORA\r\npceg3zm9Or8ll+Mmt2ZB3p4VyIg3Tijp2LR1i1cjXJ5lafq1JKs1lmXyoaia\r\nghibH8F7mP8XEN4fgh49QfbhrKFFchaLdf/j+ugvxABA91Z4Qd7VX0L7YDk8\r\nMV3fFNX56/IZNoG1UGr7nIMQX1syY9/5mMXAtuSts9oxmSroaLce8zowN+CT\r\n7ZEWQiW3O/AOPBgoWyhbccbEdmIgR03llkYyssZvfa1s2tGO1XcM10Jjspj9\r\ny8KzmEbEyn72Nt5irpYL483+xbe/G3wKiPurSFGomvAP80fhS1nzvWIUBeXn\r\nNuI6GDTKCO4U1OsYOmULyssxqD+ChpjDPHxhYChPLHZ4zPnRmgT5fFRklJew\r\nppQs416HbGSkK005OeqEj8dJ0TE4zMabqC/vtuRX8X5ZjxbgcqbrNZgsUicB\r\nguwppBlQXXgX3bGim514UvL87i52lEtr+tsTlr8h7mnjk1QfyqwKpoWIZgBV\r\ndPWFAopZu9JaHi4AXEM8kFO6C879yYJiCmJHH4ZIc4FSdriqG43AArxHQXUE\r\nAnbSEfsHtb2+GKAgmRgSKVXm15UkSa/W1HVYVq4ivk7/urUrO7YGm38LkEVd\r\nx5nUoTdnFm2F5qMOaX0KQVXeM0zQj0fVL0A=\r\n=9DGd\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"cadb28725da05b630f99493343f20b4c3fe3bd1e","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.0","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.189+cadb28725","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.189_1667954627237_0.38925981226546114","host":"s3://npm-registry-packages"}},"4.0.0-canary.191":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.191","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.191","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"a066c340db210127a672c8a731545b4c7d39cf41","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.191.tgz","fileCount":49,"integrity":"sha512-kJizuwZP+2JKDxjVeyJNqXdnemxa0m+mHVJcs8kTZC6Av+zGpSxbSY6drARfY/VNkWdY9qXlOAK/XERoWKIjYA==","signatures":[{"sig":"MEQCIDjVRpJ32r6sxP5OTufIegGmWlgBdRMn14+b/znNR1DXAiAb4L1nAr7XZDUhhmmaksvN7aow9j5Tmq4jyqAMJEmDvw==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJja07LACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqzOg/+O0jqnoQ1NTlnvSxomfbCO22G0brIpybYwhrCajozyMNLSAxe\r\npGwZ0KSs0HsIDKeOIyawP52j7M830A3cgzUNvWXyYOm+IwhQlkP2M1jPv/gB\r\nPW7cghSdjgAGUT33m1nUVts5GW+vh8If19gbD8wbe3JNrDNiA+03qhv+iVq1\r\n1Btx/tzatAA5fzx9CuK2X96QfQAERKIUrH3TR4GYHslmLps4jI7xAdVwEyrf\r\ncnakQFjQAXqbOAnCTqm0M9LL+R+PPQgj9wjl6EHxg2F4nr2v7jbAz8JCJG7q\r\nlhauB/6PiHoMFWQ/tSGupmI/gVxrCroLmKgkKqLxqKvhbZO0B+1tn1IcTem0\r\nPHHTsxmRu2uF+pkWIDQj4MQM7UmWx+wX9tGq+VotkBOgMzvKXOzBbkslP/Dd\r\nzcTiXKmGmEqZbl8lghhkzSykHW0GIL64qtZiG22qiQ0f8FIk807JguvcCc4q\r\n/cPbU77hFIUL2kaVrssh/nJoMxr37MVoNhwuaibL/Y5mIiIANcPXbWma8a2M\r\ndJTGPLLz77sUFGVmGIo2xGGKp2DWX1cxkK1ybNwOEXDJRr2CxsAulIszfamZ\r\nCH4lq602agC2sk46LmbqqDJ9Td9oazX3T4TuVhJYmHueNLHe+zJvGiC4OK6y\r\n8dKGjD1zC8YE9InfUF1hl6Dv2BUYFPz4yK8=\r\n=rNiB\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"aef46be63aea29a3e033cd9869969bb780fd634e","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.0","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.191+aef46be63","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.191_1667976907572_0.5333577666364935","host":"s3://npm-registry-packages"}},"4.0.0-canary.192":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.192","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.192","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"d88a8cba0f6f7e566aaf03772d7be4758482bd27","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.192.tgz","fileCount":49,"integrity":"sha512-o4iz8DW3JgGYq+9VJM+NPjkXz+h7s115pqIvPb7bvUftj8wD54mQXMvUfSSclUnhbvbGigf8iOYdWYCe6IEkEA==","signatures":[{"sig":"MEYCIQCOF3IRC4lvoaXMOl4w1lOWFFDPILsba0/WWXJ0biodkgIhALmwMeNMI8Sbt1BaVBK72KP7zYOqCKthdD6a3Bs0Eu7T","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJja3GsACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrxeA/9HsGSzh+TIyhBX7U2TcGGGQ3ZBRN9uIZ1hnzuXxVbWBkkt8M/\r\nqZ5Kyo55HGceYp5lTAee3LQ7aqevPIPIcnyB3pHFWJIpvIJX/eebpW6jKGTq\r\nrF2xQ6c4Xr4i6Pd8iawX+qJ2iSIiBnBV9F5qk0pXWTlLZecFHho+FLh4veOn\r\n26tcHv4B00RGAX4iGJ0knEx8rigxUVLi4SbvTwswL3snkXe3NApMyXEg+moq\r\n2AWJTsMhcLy3zsXRFzqbTUwyTU4uXyrjZOTFcr4SK14V0ti0RETg0v09wuZA\r\niAthU5CTHvXm4oMQo4DPilM5Q8NLeHCNTPNKzDf8tLkOYtfP/VxddPP9C8tI\r\nenHMS7YBb3b45AtKmLseBG8817XQxtUBwBONOm5oVmGmrGtx2x67NEMe/b8I\r\ngaHyL+KIWX6b0J38ZN6v1vjv7GiEby+ke6knOucVXm8WvBtnH2lE2c0T+5cK\r\n67deRtWnumJa5Ep+ugIXWy+pIZT0au8VTUWQMPNOkS1WjlIgN/7eacQ4DcFk\r\nWt1oNhVRsieFmU0rk09gVp99TH4Zd+rzZ7OhcW0nohbUM57iEsZVZoWoYc24\r\nld19xYKtPYmTu2y4uzVqYUPos0eWm6R0FS1G4LfGGRn5GQR9g3eNRhMnF+dH\r\nQPQPlGFo3Ggv2h+y4mq2NgYEycCoVaxiFTo=\r\n=Ay+Y\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"8a923c7f9cc0b20d495c7631acf9a62f3edc5c8d","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.0","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.192+8a923c7f9","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.192_1667985836194_0.36828075410369987","host":"s3://npm-registry-packages"}},"4.0.0-canary.194":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.194","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.194","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"d2ce7808b164722fe6db7bb3ba1f4a700169527d","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.194.tgz","fileCount":49,"integrity":"sha512-xyt+K6ZZdkx7yPODv2lUVUCvUzwZ4qPiwcsPFUctmqArM3FhRc3CJBUhrkDUa84sa63Ww03D7FoXLbktZUmHcA==","signatures":[{"sig":"MEYCIQDaBmUV6Xr0hzWExeOp4kSy8ypBg3flHnBFGjBhd0jfrQIhAPk6kzilZOUXKrMi1YIKTOW046jyGYS3152H6HVL3g/J","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbDsCACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoQMRAAlnCYUi3gmcFZqlPlwl6u3c05xLg5aLbr+t4OwrtQfiZIBEiJ\r\nHmfA/JxKkSbKP7/sZ9p/X6PC7iQLW0rA9RajjX8KYL0l6LGivIPt6DcGDjrh\r\nNZ0i81FAp+nwZHCd/B58Q9c34PD9832PNUdldlBC1J33gv529w2Vu2U85frY\r\nWbD/jgjFHHtOe54mrE5uuFS0bOhppT1AMMNEQ+mHIefu3W4WE0tLNId5SRXG\r\n/hUKIhC7h3Zypqz2ohVSWAAxzM3ZLwY1tvv0i2DSgZ9g3e/tA+LJKQsj7DfT\r\nf5ojplcywsydFXQ88uPpWlloNd4bHXzaiViJaHsy5U0NQ+ij0uF8dtbSaUaA\r\n18twkb3Fk6VJUpazs0zllsOdzaLz8WaMu4SC1SZI2nf4RuhSyyi2ZHlf7v40\r\nja0IxLQV+N+JXzv2ss+FFUyS2s2wF5blLFolWr8PuifxSmaDSxhSLa8WLpQT\r\nyngDLCkSJMetghFbqs2IeeGe710a90LxAKp+JZH3JT8IzX2ZavITg9z6+iZt\r\njFi7v9AkHvBMUnvDdL654AEjezMMBLgt6LPWDQaPotZbksEca+R+E1sWRSD1\r\nVTrbLZWtJz8M0Tpdm6fdZ0XniImmsI5LzevpYvIFkxqklMVQfl5yaYa6pZ/M\r\nmG8p33xe91kcJbl4uASGscV2hxHJyCmiCoY=\r\n=ALOX\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"cf9d43921cb7119c6d00a575d4d2447d82cd27cd","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.0","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.194+cf9d43921","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.194_1668037378260_0.2140034662873349","host":"s3://npm-registry-packages"}},"4.0.0-canary.195":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.195","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.195","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"626bec8081d971c1dd9ef17ca5e085a229d8b5bb","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.195.tgz","fileCount":49,"integrity":"sha512-fEvBbYmsyorcPND20hwUhVxOR7VyNA1IiadaQyxQYzLp7lMPRSBmqxQbxZFA+UJ+AwVW9x4hlIZ/cgWYz2h1jA==","signatures":[{"sig":"MEYCIQCkWid+pqn4TmoQlPlIZ5iiQy3PeueTDffHpHqXob67lAIhAMgpqlH4GvEyJQu1+RoofE1JPu82zs0A/Fsf2Vaas/QC","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbD32ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqmgA//bnuZKKEvYkutjZXSezHu90jtPHCunEC4oUVmzo73NUAhNitU\r\nYeAQAqruXzNJxuZbAbqSqLGunTS19bn491EXoHPJys8ty25ylFfwVqI0yncg\r\n/ACHLf2vVpM9p+OOwL4UnnL9aT1em2vSLtqtMStL4J6e0L9NwidyRdBThLsE\r\nZx1EsUsOgothGac4j8cHL26ppvtRYrxe8/syvY3vyyJgtE4k+cucAcLz9ydm\r\n7ZX9dhOWfHY5Pi6LGZsgg6nnJ0BYYbjUasC3rVmUxXhRnP4n/7Hg7LNoI/x0\r\ndlDbEFGaVjcXFUHInFVcJSKvWWAkwDaMPdX2SHPfZ3YXVdSKIQi2w5w5YxcK\r\nNutpzyxoMqfl+Krmj3h+i2xRASdyMk3btq7MmVF69DCGyI2ZynXu/2mE6PGm\r\nO8zjPBjLeLHwBLVGaj5ZxKVlCDx/kkEvEzhMICnrJv2N/NWD5wIPmLMJ6tVc\r\nplO9Sci98HmOH36IyoSM7e7yuBsknYQ2OcFrPJDieeTAF6dbSofFMoJQ1MOC\r\nPD0+gTmJsIaD1gBeU6HZOjNTKiQg30ygWLhw+0l5xZtGchTquckU2aKxgFC2\r\n/sqycwFN1YYRt1J4RtGLM9/6an4G8wIF2OUW2OHAJVhXS7CcWiPreBdIr6w2\r\ngBhFRfPThavzuTy8iQLISW4otpCRc0jks6k=\r\n=c8e6\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"20f872864dcd50da2da421169681919ec0b72bb2","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.0","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.195+20f872864","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.195_1668038133996_0.4122834377659452","host":"s3://npm-registry-packages"}},"4.0.0-canary.196":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.196","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.196","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"5dcded37581ddf91a1cb56fd412790aa282ad917","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.196.tgz","fileCount":49,"integrity":"sha512-98I+pMcWuQDoj01/c+iejx8jlZKhbeaMUJCZ8YEmYxsf6YMtbUes384LAjzbLnPTSIetMNxh3F6t1yfpp1HguA==","signatures":[{"sig":"MEUCIC2Xezoot89eX60qVKivR6fzq8BHUM1L2O0KZ+wjy5JkAiEApavKlZ8Gf0XbBbdqk9WqzwXwfoRcY0iZIHqEnOPvEfY=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbEH1ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrGWw//Ysg3WWXiyNky1LVcTkb0pgPmReEuFQdupFPf3ZRvCPFgdHYz\r\nxiqj5smsQRI0zxsVfubJz6fX40ze30F9VHd5vU0Q9TQV9hDDS8CR8r6RLABO\r\n3oHqeGJCcieEYiu7fijdIk4KyELbJ44X8PL+JP286kGvZBek9Gdb/uWQV12Q\r\ndKHIFJrwnlBMX16GNaX6kN6+gW0knK32vkBstUbkIMx9wRLTrNsN4V1b7w1N\r\nUsS9t+svzhz8K6lAFbe85rxsgcog3w90ivqJZNt8KYyKB2iy2jPIulMSrlB+\r\nFdm/VhgHGKaFvu5Om8cGAR8IIXrkad/1e4rdhMXdNjuiKph/RdmRhlAl1TSe\r\n6DUSRAnSQHBKHylNuQ4Wb8I6N/ZUAnKjaPkGchdNJ7GB1vFr6M8AMUDbemwh\r\nC7BDQk61pIswkTmoxHR5Ka7vSazt64c9GXtr62p9YWGcMb0NIm804BOBhvoR\r\ncX7wwNJF4H6COY2uF4lT/5ZovGRjNzafDhjevKtec9to3KSC1/IQt5AFryb7\r\nMLR+lrCSiU1kP0TBzHp+7rKysQAqpt4lhKvqR0bkWTMsmEArjcrGtSt6h6Mn\r\nZQGzk12UStUoWmSTz1uX5cy+R6lncuIpwMX+i1UigBJ/BtBbZ86QQYbyTnoC\r\nRH87jHxuPqAIURWUC7qne9i5XN362QPkzvk=\r\n=kS/W\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"333f54029835625848ea6dd2ef248065a44db32b","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.0","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.196+333f54029","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.196_1668039157536_0.3003641845366072","host":"s3://npm-registry-packages"}},"4.0.0-canary.197":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.197","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.197","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"030782cbd497a134fe861120759f4c74cd4b3573","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.197.tgz","fileCount":49,"integrity":"sha512-uheaJn5rgR5De9++Vwbpr4cGQyKsJEPJCINS1C3iwH/haRkq98uGzakI+ah6FujVIRon2CqljzkkfoNjFlJ+WA==","signatures":[{"sig":"MEQCIDaw0GMr2yq7UOfjUjShuHhnQDCtMVWqSKXr+DaOLsp7AiA+byXT4xy6jSCoY2KWE8kYSI+aCIsuUD/GwPqwfoudEg==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbEf4ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmom+A/8D1joT12lQZDdn5phoRd5BPznqMKUqM81tYlsUUWbYrNF+dX1\r\n/e3B+t3l/D8MvnvFHrIMgppllsT0NaP2KImbQm/I0jLYuviwbO4NyCtpaZFu\r\nNqYsMz8pwqyk5XSck2I/gLFRm/Jjkrurd0WB7gJ/t4RZXzUXOp2bvvPHPPas\r\n1PxW5R5hLuiaB1fy/dh2JpJLnlKzrQQIJSkPUsukKWMgXC7ULLLxw48g9mtI\r\nFCfJWxtJW3dY2ll33zwLJxgvW7sw3aAYHXBQtBzSn4f9PeX4R6c/4lV/WWR8\r\n0Mr3Yel0fhrc7L/On4VAKJ+cXPC6QPr7D7nmJIjb0gORLFiYecNgXrWRqYnj\r\nlF2A1OWKHTuMwrF2iKSR75OVuBH4SylckUO2/L6BuUHPhS8itlGYrel4fUk3\r\nac3/1K8WedYADElpyPtlPI/D/mvSOfum4IK+Mv/lisn+SBi/PsAOr/Ek59Oz\r\nk/hwwCSflzbFVnb3FE0ortzo9drnsci6sV68/+HeeqQ/U+6UM86eRPfEmJ7Q\r\nWAW36HJsS/MS0Hbsw/hM3IQvTOh087zegjwpkKHvPZs6O26sEZ/Z1URGERGf\r\nr3MarZg4NIAqAcEpTZMjiXTOAs0FxNH8K5ffRZYJOV/RbGUxMDkV42XWAuo2\r\nXh1qHznCYYzZZb3l7pFk7sTYtkl+0KpVKOY=\r\n=J6Gx\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"fbb7acd6bcf7a58d139b8ed33f962b950be1c3fc","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.0","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.197+fbb7acd6b","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.197_1668040696625_0.9566608045193286","host":"s3://npm-registry-packages"}},"4.0.0-canary.199":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.199","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.199","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"508a241e7d1da751a0c568a123347b567e26e502","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.199.tgz","fileCount":49,"integrity":"sha512-SGtqOrXgllcQmBuosqoq+0fjoFDEzhHDmYyTBrmoOgfuTJYNlLMssAr/e6/G8BqwNUjlvQlMxGUKWYLLTgHu7w==","signatures":[{"sig":"MEUCIA8j6tlOY/9h7ccoGlSGizPQeMWHRMQYyIXm9dvESe3tAiEAnFB6bk5FHMVVnLiXku242IbmV8SGqN+z3eTGlmYqUCs=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbFGkACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmofSg//Qhz7aH2qx1WHnJIYwsEEzqObTouwjP0lQJnWZyOAxARQ2A7d\r\nmxuFRffYRNwrVhznOCTb0IT8JTMNhWxz6rFP7PoJvtnCRuqVRKA03rVJ56Lv\r\njy8MDgSnI2HcB8UBYEwlOE+99hNEafh2rllQ0Gc4b32PDqh+5Ryh4rHS1n09\r\ngBs4uXwtoSAn3jD2xjHw0+2sfREeV9pee3eS4vNLXUubYYXLjUhGDeQaLOqn\r\nzihv0/56Hx6V9tX4lcn6l9u7K0EbJchYMw1APDO+qTIAIKSEmM0zmzFiEHNW\r\ndcl0u6cU8KvpSVSP9iI3cauiYCXKDmVBpRWj1CD3AHmrg9q77kY51twwQ7Fg\r\nlL30Nzb1Vrl8eePO7j6JFX8S0MNnLV4Ey0Jfv0NaLDD9hCGkiCKjCSVwqeOs\r\nmcdvQ3fHARVWqsR5e1rxN2e+cHzyUSRYeIV0bOvTBvUQ7aJigFN+J4CCE0/P\r\nD0mCflboYCfwe3mGQ+TiN6AQXcTcxEtjyVJ8sfD9IQMdPyyULAv1kxoRWc59\r\nLg7xN1FOiTwKMM8Ccg+4wOOkzHTT+kIyQTnAT/QrrYLwC27jWBKhIcv9Xkkb\r\n81iiHj29CpgbdYJz1d1GKZasmqpxRty2szt0VK0K0amq4/8ifvyDOVE+BbCD\r\n58aHjSWERsq0iXpVYjoMeSk52lQQr6XI5BE=\r\n=KgO1\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"1d4b2c4a0c72fd390ac9a17c7570b3ef6b6530c7","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.0","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.199+1d4b2c4a0","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.199_1668043172710_0.008614793594745596","host":"s3://npm-registry-packages"}},"4.0.0-canary.200":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.200","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.200","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"e40a0b2928f9e0f798d29455985494cd3ac1ccaf","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.200.tgz","fileCount":49,"integrity":"sha512-M0eoniBou0ept65Y1UNFjg6XZd7p1pamT77zDhs5J2c98xdQgNZ7OhIQx9kNpbnKjvSOFX2bmtOPykP4B2e8Vw==","signatures":[{"sig":"MEQCIDllkVkuFEUidI4MUTdq0f5baqr/l5T+JNZVQdB/1mPmAiBCcSNmzECSB3CT//ayYZwq38Vtlhn5nPY+2o7EvROpTQ==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbGmIACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpC9g/9FXwmlhvutyfrwvo4ESX8iY+mk7KUn0F6ieKovrFtwEObDmtm\r\npxDRQ03uRYqmhG2OUCd6bapX2NfnBn1TGr1mAuwV3+iQ5wIpMtZtREjk/kIU\r\n+SHJ0j5YiO4TZNfi1n8cnHgTyfl37obefR9TLmcN+ggeGsszPmXQXKK9ewLg\r\naIy1G+MAaMmemaHCtzlU/V1SDDdnat7RRq9l0gXd+GE+AbobTxPIyWGu0qG0\r\nypTEXplIDoDLfRu4LB8zalOigJIg8jK/J39F+gJJQa8ookTYJkJ7LGq//1KH\r\n6JaPyJ/J2+olQByCs6u25InNxiMgFoJnKiwxtKjEo4UlidrJXWITBPGfurSl\r\nm5Kph1KEZLXZ0TOSCN1HAprvkacwU/vTMp+e3yTEKvHuYFhMKYszfTw1j6bg\r\nJRxdTF6CU1e+gFXww7FXCHqnBWE3sAWnPaNyvcPkKIN/C533fpgVApEQIJW7\r\n0PEKLgZMs+CHFy74a8IHeNCPWEXl3LqEGkBYjYzi+JL4hwCvxK0CD0LjKSD6\r\nmmDbLYWXGGsOYc7mU9dATSiX66SSA++gD9bzElimDea8b1dOKLRrF4IZ4tbZ\r\nw2uTvCuI3GAm84+TJ36r19nl/VYmJbDDAkJoSBHuT7nArdSp358xTeGzru/C\r\nL6V+UVJ1EVVJEVPWeDn2+7rJBkhrnOCjz+M=\r\n=k+0X\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"7cd1204a56dfd42127fa63d04485e85826e71d07","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.0","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.200+7cd1204a5","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.200_1668049288146_0.10633723756650926","host":"s3://npm-registry-packages"}},"4.0.0-canary.201":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.201","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.201","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"a4b273415b68072eee5e544b92c2b2e1d16dc146","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.201.tgz","fileCount":49,"integrity":"sha512-PDbiMIvC3I6K2PbnUd7bvLwrrrg0LLIbNInPEjiywUObDYdrOU61scpsEYHG4GkOQPlYzdZRNrF0fU1XLaW6YA==","signatures":[{"sig":"MEUCIQDNwRfXoE1otv6c5yq01WHI2RMvED/pQPb2BN1wKeXKYgIgQXTsWP+KKh3rdBDEDAzRU9pe8WTbBztRRDcnhYDVfj4=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbJx6ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrRWg//fS/7geNv+kJoCARSCNr4sXGl9i9Cbv+uPsHtfJHACK4M4grj\r\npWbI467LdsHK40F0ypB46pzBBvrY7Lmt1FwreuaK3hfuna00hqzj6BVJTFe8\r\nbN9jKnOcyqVwdbNj+3fWCKujREkTOqiSUXRZoy/IBAbFQqxOjHQYU6XdOPlU\r\nfdwKZPTXPCxOa1baXmuXnSf0SSB9L+bv6+5L4k3SfLN5e8YLCFUoNT26fltn\r\nWZHJtaTrRUNEg8xeM7kW4x2tgb6J978JKviPUIcAbVtfpw9ON3ZRj6yN44wT\r\nbS5vtHZfMiLx0S+dx7kGq0iO6J7yym87CwB8yZHfBfB3FT4kZaNT5owA7VdH\r\ns6Fxdo+7TFpkKH/oXrEUefxbRPMezE2rqBtUQaMiUbpE7ucPeDeCMRbp6ppo\r\npsNlmSKOeJIOSoenAATj7MtGYabjxVmwVtqOe9kd1N8BDtOny7DGc0bbra1G\r\nIIladqf8IjwCEXu8A03jZH1JbGRRvqE+urNJzoBmDXPYSkCKzTDbJbMZPVz4\r\nrH6RHxaEx2GGK9dUesEN9wdHlW89cBqkXLFNozIZMGKrDQrpjQxLrP3Ywhgk\r\nGPVFJuouiBRzTTJITBTYCJ3FQ+j0JpqkRBh7HdagSi6alt16Mf5qDySwx57G\r\nGNZoU9ufSB9EvYveZ1Xwdfry+O8kQaYOeNw=\r\n=Pa7L\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"af37167632314e97917cf155e39d8bf255999c85","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.201+af3716763","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.201_1668062330512_0.199014853455725","host":"s3://npm-registry-packages"}},"4.0.0-canary.204":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.204","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.204","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"c65abd138095fe1ac3d822428341410b93cadcf4","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.204.tgz","fileCount":49,"integrity":"sha512-4H1HOb8GCzXDj4/k0tBz+Dz5GFVUXAjJp06KQoVO2QjTp3cXoGc8eZ7YMEDqCuTYq0Mey2fharSYCXt+d6xeMQ==","signatures":[{"sig":"MEYCIQDP3gRz3mANRe6iHira+NhGsYAyihiwnp+NnXZ6v/RXLwIhAPq+YRFyK8tLFJIs6I0XMHwtHzheQt/Oq4749Af7GKiI","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbYL8ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqEug/9EI6tSlSzC6+DYMkpWu+c//JU6Z645Jhh0aQZaGqcJwRihHpC\r\nV/m6j0fBnAXwJ+4DHb47qxbibWCaf7jICNB4RmPIoZJeDZaTEoyYNXhj4/hx\r\nQcJU7w1aKLM2gxqLCMRlZKbAjoYYcc8hWUBKSJH2R2CEJc85o/PRwRBNwyZ5\r\nKVFZbV8xEWTny+SAJE7Ie9HhVYt3dEnMBsMb+qc7MMeuQgjK7eXrJ0Cg0tUm\r\nSrd1LW4swylWOUjNs1qgDPWnQfUAiP4lTi5S3LE1Zm1Nz3uqu1dOIQbxBdLk\r\nzeT3H4O+iitg4VpBmSJfoTNQMkGTFxMfiqdLhm95vwwEyXhWy2rqlc9kaJyk\r\n+m7Bqlx1JSeQ35Enov3+6JM9lBm4J5W4HcJ6aUG9xNOPtUqqTQpY2cqDIRTO\r\nYsS+xMps+rv+Z39aRSRYljlNFTxAQKt+YzMOiGvX+pl8HroZNGtCYjqnr3D5\r\nJyk626yYOo7F1OXnrfyak8wY8ni0Gn1EqD275BHHVzf3H2Ikg3/jUdjdJZS+\r\nBOJ3TEBQGVikOtx/u8ypje+dtCCPD4MEFM8whT7nYk5k05ji4dmx71ynk/5N\r\nC2Y7JwXjqjWeFLwQx+rzTK8szAgYdHt0spe/B4fH1biXDs19ruG5xM0+ijl2\r\n019Fj5wBY38Zj6PsehEOdCAVEiNw3iMBBSw=\r\n=6Gl2\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"e45963904b2640b4756d08ba483d240a62d0e93e","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.204+e45963904","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.204_1668121339814_0.8800920169597577","host":"s3://npm-registry-packages"}},"4.0.0-canary.205":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.205","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.205","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"ba6813cbdba7123c80d8439b7068a5f49f45b088","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.205.tgz","fileCount":49,"integrity":"sha512-WVX7zH/dPWmMAlIm6kVkMZu8FYwk4woFtfaHyO5BOKpSup/dV5JkaCol2vts/mD17ZqJNux/jsF66y4XeGgqfA==","signatures":[{"sig":"MEYCIQCELCOJSGy8hwWPKClM2ukOySCgZQ8dhzLus30aXDzSBwIhAJ6PJRO0nbV8Ge0AmMzAvQE02SXDPJLqWF1s/blkcQ0e","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbZp3ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmq0VA//ffSHEoBUgPs3kSwV3Uhd2FKUsdSUyZX/dPN+f6b4SKntjc5j\r\nyo+7wjFCXowvfMcpEKCQcHPYS5Ng1CvDbOTeQOs+T73C5zv3TBtUcYcEtePA\r\nNi9iNqf9SRcKr26YvBTx5N5+F5qHph5g5gMYUFElI5CkBR0o+hBoNR9n26WR\r\n4eJUDlH1O5k/GWt+Mh3Lw+Hmm9B5Kw61eqdDqGvu1ytexZVE+B2t1BKwMcjz\r\nbQgq4vG1VmwWc6/rZHmHBw6rG8Pj1UrMYEVN/Yi7b27CWIQBfeBiCCyGYPK2\r\nBwnL1j/E1NVPttjik9EF/Yyks2rX85ZC3k6oIz1Y2UagLSPh70EBxfa93ZHc\r\nyItF9b4Md0Pqj+S5Pz2YhB/foLQy1BDKlwUQBrxEGhPlp+YaKTIRtfPQCy5i\r\nfrAmgV69EVUDUuClJiVYFv16P3kHhG3KBqCRLPcIGPSiJFO+3NccKxJxP/B2\r\nAXTowGJB/N/uAgETbyvVNGK5ODMmHaMduGmW+0F5Z2gkYH6rwL80KPVH6TwK\r\nEt9r+cRSRlPM2TGhsqe2BQIFz/CHWXEuLslJYihwIH3GPRPLzV/ul+XwPuuT\r\nTe5dPkdUGTHDI8whaNy+KURfxzi5u174uh8dM27v5uybMnFJrOmlQEeLLVKO\r\npNe+42xHjMNfXY2I/GToE1FIlYIrCQv1x8Q=\r\n=5/Jw\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"62c49f8ddd99f6cb36ec0a969bf776b36dbf6f24","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.205+62c49f8dd","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.205_1668127351135_0.7902628836880781","host":"s3://npm-registry-packages"}},"4.0.0-canary.206":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.206","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.206","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"5187f359cfcc7425a0d6bcb401c633210c15f57f","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.206.tgz","fileCount":49,"integrity":"sha512-9n6hIyqwbpRFoNF0O2xtEjcYStmJ/qSSkvtNHQLONShPEXRhKTHJJRicBv2FKd9LS/p+l/7b2Ss+9Nox8FkPmQ==","signatures":[{"sig":"MEUCIFbkFoM7ZTP3S4Tnn0bajbkt+vhBaP66V6zjBBwFC6jHAiEAuwQpgnDvdGkITh2fg4okymFBHxGGkP9myZ6rCyRDo+w=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbajoACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmq14BAAkPrLZjW+w4kEQGJZMF/QqtfkKFADC6kxkfRKWAQ4q3Ld+EH5\r\n0YAGDtb4jrQ13FPHWsfkTR9nuzl895DVRPEe+CkpR93Hh9/mGTEBFLKtBNag\r\n1DmmhdU80ouS45R7xUjRqaILm2Vkfda2TmP2zvkU1XpKAKAtbLvkbSz0WOtW\r\n/e1T00e/fzK3R5QDdM1zuBvqAXqT8Tj+dCEHJSXNaWCXFfsDZb9xr+9tCgbi\r\nbwXV3FUETrIxc9FN+88FYF8XLJb85KLzS9AhbtJtFaRgj/l3l8GSZLeZ9/SN\r\n8FDyrWBSVNTXRADW36y1044olQldmmev2u1cIhIZ36RFWA6q5c8g2wM3QHKB\r\ni6MfOS5cwQ6x1OBtWlCMy8KyCcJhbejDsPhF53FRANvav/lNgDilEBxil53R\r\nviQrQ4+mfBeoZqhsUtl7SzWscsbmkH4tYx1VhSOlHedYd4kgv3fJjqOdeIQG\r\ntznrarv5sOB1l1TBIjkl0Vkkizg/1zWccXaO1ibW7FtgLFHvizJ5aIAaxQkH\r\nkV3HEnBj4Q2WDcN2C4YrGDUyjVuPe/Qr6+wFIJALt5cpQd3x9KhG07LO4SNl\r\nBjmmOUAiQ52uKbgpRLHItOQzVWQMyOOc/rA+gQAJxXfabfE2pUZ9VziUHV7r\r\nw7VygJwSx0BMOO9CHNrUquAEJyaxVyTICHU=\r\n=+hv7\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"1066348dee0293d3d2ba3b89ebc819a8757a321b","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.206+1066348de","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.206_1668131048497_0.26713394942313307","host":"s3://npm-registry-packages"}},"4.0.0-canary.207":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.207","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.207","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"38f0b667e9a8ac658ac433f115367443011c4cae","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.207.tgz","fileCount":49,"integrity":"sha512-7iyw47AGJciEHdO/77jzWOBRikr2YvLWN4DyeCOIXWMImU9dxs2+WKxorG6ME/KCipH6qW28HvqG3gIECwbDuw==","signatures":[{"sig":"MEQCIB8MVahB6kIghpf+tmM6DfdhkWRHfa2UYY8BarY8agiTAiAqLhlr9LhzuEv6uAHfu+4RRTSdGU2D942j+6vsTVUCIA==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248168,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbalQACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrSZA//R/Axbrm3HyeLzu+eK/hmzIZx7iHXyT7BJwkupYJEHBECbMn2\r\nKzMvt4LEelSCw0PN88b/Otna1ozNvWPU6wvQ1YakQBL9s/55sesGMaW+40qv\r\nKHcqLOE7MoKdxST8vavwcv34lgkIfnftgaqkahsHVzvv1OWMjfRQlLEMTPsj\r\n11wGDL6NFg84UcEPI906dGCe3rFxJD0b/xQguUlPKhAivYLXzltaKvEW//vh\r\nxnHdu7K/d518SG9cF4mm0/geYvxRE2TyeEW07Ia3JcH9fFMzcX6bYI6DmOXz\r\nIRPMY908F8tCNDkWKErOT1iZVqjx9fuubec0ltbhC41RjZWS9rMrxDz+yFmQ\r\nNqW/R07zwL3y3MdH7HuiGqSBYEDbszeXrtaOGyVmwWFa1Xv2uAbpzpRFu6vu\r\nsGx6MyV7TyJ32wPkbJZPcidJX0Qesd91v6EAO0bsONO2aBOtFl9W/CiuoaZa\r\n+msZfFAS+u+wBTvA4tGatD52hdpOAOLSVNK0ZZPylyVcM9piXQeQT1R1z9ov\r\n/J0rsG5PaeHAV5tQjHUfcPGUg9o3YxJ8eQTX5f1O6+c7d7/A36WnPRqIE6MJ\r\n5purmi3a01rqGFlOfqwztkDjVeofotpSA6UzyQuAZrsahM1nbXvK185KNS0w\r\nzEniaB0e6mXFfvh+Lx6YIPeRaQ/Dr3IFFpo=\r\n=AnAl\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"0bb0f8ce075ea1e0f6a7851d80df2bc7d303e756","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.6","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.207+0bb0f8ce0","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.207_1668131152330_0.392453706636815","host":"s3://npm-registry-packages"}},"4.0.0-canary.208":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.208","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.208","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"2ebf402ff2b3db004137d6dc9827e3e53a10a667","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.208.tgz","fileCount":49,"integrity":"sha512-SKTA2E1sjuPiNL6s+vzq2yfS2C87K1r+05EOA/hhoOHUoZkeurMjX9ok9o4sdfqrqwe5ODIUMG7EUrcSSTmwJg==","signatures":[{"sig":"MEYCIQCH6a/nEKvfUbzcUtw8szRxNqt2fex8Kzs3bOgxQgRBNgIhAIdsiAehfaBsG0VytEZLDMGiULgSrkEFoxd4oSJ1/uXQ","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248310,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbbVOACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrvFQ/5AHhOj4r0mUh+u1k6Lck7nHqXbxIAVSr0vStsJZVzvXGfOB54\r\ni1Q0nnb8Euz1j0vPFA6kNIGAy6iofMgkekxOOPLgY5jcgjPfzXAYC2kKm3GS\r\nZsRHaneXxCx6hg9c5uixKELpSpojHQUKSw4C6trhklyveohx/4CIwukV+LRg\r\n4NY1s/9KVPjfjWSDgwxYUZENPV6xln9Clqb15amaU0V27wqMpkXROaSrREvh\r\nDSTks5q4GtZoJqIfda1ao/vfxwvWGtu0r7fRa3WbOgjTqsnVtHmXXZXV4rE9\r\n5enJdyw7m4KbfUaJdfkPL8UzI7QKKWYQxA1Xbf19+TkuKGvEEm3ZwTZ4CzYH\r\nnkq+4bQqizAKSdPhGXIcaGgao8SbzWGusUfr9ZRyY7Nb/t+D1aUZoW/Jo6HW\r\nXhnT+jxI+jSOgqyMSshT9+nsOfnEp1x6LOmwv2wzSzGFKky9LCO6c5x7D92y\r\n4FVJbPSX8UEDZ71za1uBO+TSd9CxcMqNWo4yqLLI92rZWYKnKTN11wVZGKdg\r\n8mo7U7RNjrrqIrT/yEvhOb+kLx+xHgqA6B1aDfv3SH8ZBUdV/SKr/KsS6zji\r\nFlITyMz9owBPlc+cYV0gaT78WwDdJQft9qspCSA01P5M2Ws9yjlCE/n6a0GV\r\nXsN53XmpkxMOBZMTsFG53J5wI6JFGDVPfYw=\r\n=R+1W\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"34125a54af769a0f50f70ff8b76ecbcca654aeb3","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.6","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.208+34125a54a","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.208_1668134222326_0.5358986026832389","host":"s3://npm-registry-packages"}},"4.0.0-canary.209":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.209","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.209","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"ebff273548341bf86dd9ce64a7cf3acf5925b3f1","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.209.tgz","fileCount":49,"integrity":"sha512-G1/CCk4nr69T8n/3B/baz1EprEy3aaOgwHgvKLHXuzBgJ0sOzh42YtFdLxE427e3UvA5geaCr+ZCnfvI+iXC7g==","signatures":[{"sig":"MEUCIQD9PSvLo2a3M97HbN/e7UjKmCCLncbsNKzoSLyybn9ywAIgUNXuB6nHAmY4h2bLnznEYYUEPdi3iftOKZoI2uXiK40=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248310,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbrPpACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpjaxAAn6Wxyk3s8dmB8fUYXd2cMjHRB7UGH9feCduNYsnXj1I2/Vf4\r\nmhCPEDNMeSilBnrM8XT862mMRREVNTC9UVF6Gfy3oed+u4LDe0aArViZBEGE\r\n3O6VYnSnUAiKEur6nXezpuB5hVZVOS/T3HBm950EiHWGYM5qfAmN/chCbi16\r\n33W+CNKOpoJIUkkKDsf5ayaJE4A9V+602F4pE7EgMAhLZtH0qMB0/sh+lBNd\r\nmWMXDfTwLRYU4nTP8fz5I5qyDFyfwa9osXOgKk4P9V4kh2rxbMpvfNiodEpf\r\ng9sFjrUJjjsq8dlT15ZBeQ8UCCW6VSCcUMJrOVzAdbtDHQpliK9M6KKHnTh2\r\nkmXz2mEuk7QB0L+lzXZjkWh5qEesLwXQRRPp6a970Bi+PTkrkqE+tjr6M17I\r\nJaiedo912AbiJ2uRyJPe1wPN/Uz02aNnkJJXF9Nii2gEcPofEYgkUVu69TXS\r\nzrWQOUVPvLH67vSNPvOc2Pc3ukLhN0ZTuYzNyDgmaGekJOp1kuvuK1q94ahT\r\nceP+RMh7V2Z447XmVbTCBX2BoeezCYGakPhR5UbS3g1LA29+gjxqJ41gtXeZ\r\neuQ3mlnJwnsr+5kVNSngC5S/5p2avQFj+1vGxAbP/lYT8QVyvtvGgZAnx7Gf\r\n//jGR7uNnOI2Q1QlfVQRnmb+Jr2uje6CtIY=\r\n=yHoL\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"5ec79849675546e71a0c3bbf1ad1a958afed6dbc","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.6","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.209+5ec798496","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.209_1668199401483_0.37455301252528517","host":"s3://npm-registry-packages"}},"4.0.0-canary.210":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.210","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.210","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"10429c709e66a619d3e5197a4b80e34203a5f58c","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.210.tgz","fileCount":49,"integrity":"sha512-uAdswKlPL0bfk6vUxKx0iBNYO/xe1mVxEAGtvvwxPhj5Jw5oBlqttQKR1FLGMCO8KtQ+n1YUs2F+lYWXahFmOg==","signatures":[{"sig":"MEUCIDhdAbqLYNDc7Yx3fsBE06buWN7IV1Uoo1J3E+R/8kV1AiEA56hj0Lb3TWIJ0oMcXbYvfuqUwKIfqX8OwYEmLVgk1hs=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248310,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbsvPACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmqxvw//VQDggUfXn/2FUCWwFeJJXUib3r/ry5iunK8/DfpLv0Soa/Nl\r\ntUsluAzdnexJAtP6t/ab6fpfH49RSlHB7YIaoEnDRXqutXd4ZSM93B1u9vKg\r\n+IvqyyZRHVOMU/I53Vm3scoMd0vnM9TK0jM8JOc7uDdIbr4TARBvskQiyjvS\r\nICaYe1HnQxmZ2iEai+C4m0hFxwlP1HkPA1a8Jjxf4LOR++/8M6bipk73QOGU\r\niGJJOtKCIxKR5RVhKsoLEE8Cn/0D/71wMpTqMbFpZxml9+TnlffBDHxEA5r6\r\nqGNApga9JOcHqCAuI4I19NPnnmRC9mC0W1WiL12Cdf7XQYCGYoSCL+u525EH\r\nwRolaG//10aJct4Adhw4DnnxBOj985G5kBFkYwK2T91xD5/7vKcUYoHbGSGP\r\nYCiW7JIt0+ng/5pLYOZx92JlRHMMJdFROMcMTOCr7zLL6FHf7o3mmNVvsgHC\r\nmKrI/N2TfKxNCg0lnfAo98NnFAHP9CU7qQyUqvbhguV5DA+B67GcfOnsoyka\r\njTgHmLlnbexGk2mzE0e6pEt8ruwvitWJ8eD0zNw5wrWnaHCeMEvDytf3nKQF\r\ntMRrRJCM7h/d1ucek4n5DFYvLycc3kz/qQX1TRt4TVNsylTa4kq1YnIuC3Hk\r\nsGWTqUsSQgejnK9SNCw78kQCJh46dTA1s+w=\r\n=UBLy\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"45325f866eee43967f909c7f1d2738d6b06e6f64","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.6","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.210+45325f866","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.210_1668205518941_0.858998780576697","host":"s3://npm-registry-packages"}},"4.0.0-canary.211":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.211","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.211","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"5526766cea96d66adcad91b6a22bf1d979e2a764","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.211.tgz","fileCount":49,"integrity":"sha512-kOXYyLXQvt/9IafTC14LgX8rlUKhVyRZUKeuJJNR3CtsH2oGyCoFheLG7TqwVr+vBH95IkzRZECZKnhlwPluRw==","signatures":[{"sig":"MEUCICc9y32FmZQi0eKu44WObVeUXgLXwmI1H2fIY2VICtBjAiEAi5xIjFRGYJ5C4eBQmSfvpBKHVqFkZEzkOcRjSQruMgk=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248310,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbuNZACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmq/8Q/+MoURotRwfujLX5iMVv7QSIzMACN1ulgadElFdyebRDWvDGDP\r\nmuucYkXCx2MqDH4WaYgRD90ZWw/8ag4w6Btz7wmM1luzPopB7/zIizcPuFNn\r\nM42BY8yxSPc6b++YcUKfuriVyr/XJUefXXIjEYNRdZTTNyQ/nbxp4qNtLvIP\r\nUh3PQkIM4mER2I0WL1GaDwh+vuKudrUHvf5pxBOpFpMQyEiSq1kw3ebktoZ4\r\n85/JVn70D7qQWeNQyH5fRao9hP/MFXght4Z4HAqFQBhojogX8Q6XWGFcB2n5\r\nr03gGYMUyzTuvy3RILEen+gmK/0ZYus7efIYKshfr4S28LMYpnA5wOIZI0b6\r\nT5ntOARWAVMqhliyVOYj0nXGz9Z9+4Uxg9aen7MfSMPRPGv5gTdAyez3hPuR\r\ncseBKbeEJqz2PPNzi5d/0hgzrs327Vcg1bwNTtYJ84svX+0him7GcwV4BhdL\r\n2Ox/5CS/WfZrVsuIjwsWM+Aw41qkxEXgIQ1A55at6Kz8GluiJjHAsWlyZByp\r\nlt5T5iBbo8fpOyikShTCVv7E00UhykaQIUwLBNEmq+85j4wc0isun4/C+9N+\r\nWYfiOzVznTJybRhas9imms7zFvhHGJGdFWYVaYirde50i3ILNbxHZBdvrebe\r\nGch512ES54BaKh9wae8c1k0nkiv6ATaxGE8=\r\n=mfWZ\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"01ec6c1ad3f9d532339c1e375dccd75b6669fa03","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.211+01ec6c1ad","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.211_1668211545558_0.49260291967345005","host":"s3://npm-registry-packages"}},"4.0.0-canary.213":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.213","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.213","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"7b38851b2f5e6262764245cbcf172e306ded5f11","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.213.tgz","fileCount":49,"integrity":"sha512-STVnm72CAuXA49KMdskc7d+B50Y29d2mTAgpEIHeMNyCzZ80v4nVDAmXXVnqlsCBxYXy8wWhdGqsnqvwCakctw==","signatures":[{"sig":"MEUCIQDUymyO5ESrdPb3EmQAc/WZ05mkvsntlfxADFNa2edc8gIgGeTVivLdDjwwPSOHiny88+WGL9UjJU2L77X7r56Iv9w=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248310,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbuQeACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmocwA/9GUifY1vGcpGwst9ygSWjRb/ZY2u5yhq2nNnJGrU6Ufbth6Ua\r\nh3iKUR6IqgwB/kM62q7l7/lwNgyNOJOm1sJsXP4fBajTGIGcgz4iTh8JiDXy\r\nHeams3Pe+a1HvRM022SlcuXr8R4ShgKO2cIE3SIm55G1u8ERFkX1u4lQM1Od\r\nKWXJ4QT4RTmPD0IeNjedA0397ZkMAt6k1hS2mNWZkBNCxft5SCv5Uh9WVMYc\r\neXOhKloQ5zapMlX05asyW352xWRO+lqODY4DUML+OBwX9r9gd2VR3KWQXR2l\r\nXANMfDF7KoWRgeG2uQxwy9+VD+B9GKrGe97aAkPZNOhwHNpUIG0X7jDLPA6H\r\ntDKodbSADkw2lI71d4FJJwmfqFZLlAuVp1cvPkU1J+NTOWdvtd+GJRC/lPHE\r\nhOKVPLq23ZG168ZU86k6lrJ5q9VsHNNQ/82SSLJfFin/pt63Y76O/fTAAhfy\r\nS3d0V1ET1YsXgnTHSquMet2kavdjuaSI0cMtRL7P2hZWUzEz0nytq+EolWeG\r\nkOhCEtGjvmJeDHEcODRcAiidjVDj2Y6not8yPjbTHVflzGCjjK+oE+w83oGK\r\nw3GmmwwbFygC+z4sMuGmpH4NSQ6Hh9JgUYWJzu0jVLAAyMj4XeczR4cBvN0+\r\njlSXCnpZsp98TqUr+UZoa5L7i4TfsnuL+iA=\r\n=xqYe\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"098e921bcf45cfa9d02119e1f2b146e6b19b3eb0","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.213+098e921bc","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.213_1668211742740_0.09738480680086004","host":"s3://npm-registry-packages"}},"4.0.0-canary.215":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.215","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.215","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"090892ccba362cfc5d630b43c03bee29cfd87067","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.215.tgz","fileCount":49,"integrity":"sha512-MEY1hG5eUllvXvOST5HZftA8MrCAJK4WCZArprKZIqWg1vSQREVdbrrTdRS1X7szBWnRK7j+ZL7zdbevozDvCw==","signatures":[{"sig":"MEUCIQC3hA3hm8Y5SZYGNJfwf2DA6OeVs5YvppPp4Vwhv8CHNgIgXuA1OezbHhcGGaI6fEuc/G/OeDOtelVw2K72/aCXq+A=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248310,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbuRAACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqCLhAAiLKSM1CzrntHV5i14ebX903E9xrqMnKFfHSx1FrrPPhY7G0V\r\nuGlD10GgwL4TmcoFHH5QTip8jSXCWxYX8b1dGG0J/ce4e8sBYdkRNKdIrEYA\r\njgE7yAcf7GmwGWZOtlRudrTy/Vdqo/hZeOFIwZLsIZpVDIofWYBllgwbWGOc\r\n8q8K+h7PR5rMf/lLy3mdYL19F0fSOzXWNaBqqyWwbNvlNA3ik+eFmyOiiYIY\r\nArU70BpODVAdE3CD/VLWW5C4rSGU5GBkRXJTTLqiF56GhDan6Tiw3YzQgLEm\r\nwPq1cHisk+Oxwpvhy06ix50Uk5azGB23um2uJrqKJ0+wWxoDQx7Q/AwuWl1b\r\nz3kx+fIhsO1cWcQ1xsh6vtUdmhv0LM/5QFO8ICl6aoCrjbpyYpVMvhzcHgl3\r\nhrJqSQWj025P/bxvWKkUDiLc+EZb1U55Sa+6a0DdryjY6uihff1H0ymaQO01\r\nE31o/8mtjfNXT0YqCbYwSom+nfnC8jNvHaDPTe0f8FkzQVrrI1euw84/MbHd\r\nlG+84UNKplVBKkx1Yx/pocl0AdwDtRFrHmG1o0RDrDBFNtdhd9nYJwrmQnmE\r\nlSgt3SUstVbPl8PB15EIXTdt2og4R9g3i8Y044UctesL9+FuBtDu3bdwSNfK\r\nQJEE80FUy4dFzz1TOZASNgEsHoGwVssEkn0=\r\n=CoA3\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"dcf86a53c849e374147d34b1e77a1ffd2e397a2c","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.215+dcf86a53c","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.215_1668211776684_0.7131354380977193","host":"s3://npm-registry-packages"}},"4.0.0-canary.214":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.214","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.214","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"52ca6ad8f477ce380dfe4df6d6b68eac0ffcf88b","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.214.tgz","fileCount":49,"integrity":"sha512-gs+3rP5Kvlb2v7lDs5h3+GY+pLr0+gZvQZOTxdwdhMTMPQTunyOgelswaevC+Q5LVt3KQhmSC6sOZkFLxh2BMQ==","signatures":[{"sig":"MEYCIQCmpldgGYfInrOJgujZWHhzukdXLnl+HEnoaWTIvpi4LAIhAOfyjLvWMwE99BRCp5d2pXw6G5W7M0VWgdJHYBMtpf+R","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248310,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbuR9ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoDHA/+KTV1T3pVy0uxV+ku5RfiXk55hl8dvVuRXY/d8lN6a+KAbH8Y\r\n3kQTolx2zgOamuAxVJjqjjzjqe3WSDRuusdzr7d7KNrd4pPiO2G551kRVkbS\r\n1aFZFQOOLT3sD5mR31qCdlVfU0tRGvaR4kbBpuk79/a5UQ3i3IJVJ0E9m28K\r\nJJn2JR8zWQIKpDUOfC6tcwoJVtkniZ6eA2m363UUFsRjq/iTUTq4EMbZsEpw\r\nNQm4Mj28Q6zPWXRQS4kiMOCbmNyDGYX7ekS4EwwfGseIUfpTNWgZvxVsWPkB\r\nDide++lTLMDnyNzWu3/bVu0NFFO14TeagwGGyeSf/EFqiYDiBQrOu8fTjjZN\r\nW2NAFO5cBgh98fqH00sqeZrcCxyGVvTwhQlpSTQFSLFiW3J2tq9JNEHt7FLX\r\naTpSyuDWHiuolVptRw+AE/qFFSSZY5pGNunwHPW5W6mMZBEWqzf5ZDY2Axjb\r\nqp4ZKoyqmRPQoVzjaaG7hO6/liQpFFitJEuxoCSb5vvPWRhZ8pFoPNVxSh2c\r\nZkuPdd12QJtPG4cC4NrpA2jwoj5ZWX1s5NDZYOJ1pNfc00kqcdmy7nGneqEF\r\nZQR+tcu0NUhzL8N7Voyo/wEaRL+BSXHkJeU8StxgwiuAg9uMjYXN73MMF9pG\r\n5iuRdRcWibjQKDAYkptPVmDxBbNqRgDOUf0=\r\n=n1hA\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"129a7e3465f12305f797f44710bb16bb456e14f4","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.214+129a7e346","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.214_1668211837131_0.07023910047840198","host":"s3://npm-registry-packages"}},"4.0.0-canary.212":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.212","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.212","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"b5aad4f0f8c585f8fe8ba618fcb12d2bafd39b32","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.212.tgz","fileCount":49,"integrity":"sha512-WICbuB0Z5ukR7DCgQFdt7JaXaEd3TPgrfpFBgaBQKH4DsNki7ZpFMLzJJUd7Y8ICU5OXmc9JS5E8qZnQ9HBRnQ==","signatures":[{"sig":"MEUCIQCzX8r09+1ocbNUk2ZiexYfoatvN8u9iRh1ddrS7Ha4FAIgGCqJMJgf/YUEM/0DQT0vaMMej6lLrBEPgXv76o5UwJ8=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":248310,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbuSaACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmq7ZQ//bVUYz3LL8He2NZOP32gtx8BpprXT8KfZDwrSi0eXF2/exM2x\r\n07/ELoA0eCFnR39gBJly1krPgbQLM6XzsXx3IiVHN0XpvJW4F4PzsXty4H/b\r\nssPubePMrYFEJY7y9wAV0m3zNuc5Dmp6t8aEameVqDdIyVrigNGXCNdkjYxc\r\ngJOSVMgsJ4D2ho6HKSlfg0HDlWcjyGqg60D4rAKL1jCK++AEOKOz/PwSltcO\r\nKvULCGadJwf1y2HkyyPUsr0469UMczNuv4wLrTZXTzedJkx7uiU6vnJEGA0i\r\nmeOHmlzw3A36G2XA5kidFyiSmrBbb3lJcfet6M7cyvZJAMS7OiXXn/knvAKM\r\neEzOvCBsB3kJM92Lc9f2gCpg1FgizdyRKiFuNSeh9lyRmwGxs57fs8fI/fg5\r\ni+0aAcF3yDJVoj9svjq9Cp1QcHgXxuAs1Kx5Rt6lfY5T7BvWwWrUX0YvIquh\r\nu+G/CxLr8yXnz3u9k/v1f+XNRf2iENrt1RHXFfty+RcnReXq1sDfyEdCfEXr\r\nthd6iR3AjdgP0I+UPYayC8pxUH4goHQxaUH0Sn43aYguDQ9V/n+HPx1mi64j\r\n7v3O6/vKMQB7IyrS8ZAt/lxyjftk/7as3r0uMs+bTtshpZmqwCtxAGQCAWJw\r\njmcW0hMfZGsgLCMew8CJKr9qjQSECpzt7yU=\r\n=/ar8\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"457550a14c0928794315aac49eac2330590f0f09","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.212+457550a14","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.212_1668211866083_0.651752962183904","host":"s3://npm-registry-packages"}},"4.0.0-canary.217":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.217","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.217","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"9adb5ec71ad1c19ea426a58782a4cf1a17bec7f4","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.217.tgz","fileCount":49,"integrity":"sha512-ylLBfbEp6X63e/UQ1Mo77W37wyiUls4mALxI1Tpb2+sHV5PwuOiuetpnIxhMjQdk3qVxGmBhzOD9CMwX3JXGKg==","signatures":[{"sig":"MEUCIF0m9e8G/DEW3an5gOUDlFJxlUexV3PRoEDSluU79d4lAiEA+iw492/ooDPA7rHDN9RQMlqeWwHfBxE0x+wDBueOSGM=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":254738,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbwNcACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrZyA//YktqF8p+bINESW7g7T4caqHqlvGD+EmEE/Ayg2DEIVIvD4UJ\r\nk1UrAZ/BVWoSp3z/enk5iYCR9CHOjUx0BNn5x79yrgj7VZKn02wz5YiWnvVq\r\nitkrTL3rIciTIZxrtkZIDhAmadlLDWjifDTGieyNclux1k8qtfJIRKPFJgi+\r\nqUGgR+QBmX7rELXybmuqjzYEL4GxXmKGoOcE46gsyJ7pMHxeK7eYMnI8vcQ+\r\niiWN5v2AmHJVOPniPnsaQQuaSmpCf4t5rjov6hJ9/nHQfvUEEPmOHEkoO/VR\r\nL9SdFqF7296VrFy6TVrAlKBY8AK+Bx+C+3u64lUmDc7lNF2dlKjqAosodRrn\r\nJzovmUf5PQZytBbTG4vDHiamo6JQGcNcFl6M5j2SpR29bu/PF0Okiu9yebcr\r\nbgXIwdttGE4LCvHIfiTxS2pgaB1VunIAI8jIo+ZkTuY3X2iR332j/37CkX0U\r\nZ7PN9wywP2eJk1rpU5Nw42ZjTZeQZHLr56lway6qp7OseHmwbpzLCUvw4HL/\r\n7+ffQvI8ujCsdFP/4HZeT0C9E4alShUJNXDjWs/7GWjLh6UMmqBdxPERqOwf\r\nCrBXfXAwgu4RdbFGRG0wdiqL8wFdNIur1sC9wyHWfirzBk2BK2b+/5mQk7vq\r\nf+BjdseUNyJbEDXnjWOnb5F5ja/9uGPjAwQ=\r\n=EJbU\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"7c2443b30569b8617a88d52503a51ace463c4cc9","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.217+7c2443b30","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.217_1668219740406_0.08667084196246688","host":"s3://npm-registry-packages"}},"4.0.0-canary.219":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.219","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.219","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"24e1015aa5dcd839e57be57de78e58ecbc84be0d","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.219.tgz","fileCount":49,"integrity":"sha512-6fyIf40JhB8HZYe8+TtsmQrUBq1UTEZ0E8r8h7uF1bhUkk6RG8vP+oPk2p8PY0t7nH0la5XxuSRmJLavryA5YQ==","signatures":[{"sig":"MEUCIDyC14izgyJfmaWVxT1o9jbLNP2clKAFFCFhxKfL6Wt4AiEAgGxAPPl7PZ4fm+G7R/wG8GqjIbvfh7M1F1XTNKPBPRU=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":254738,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbwPvACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmo2RQ/9EVNJRDleOx4VtqDE+ZMJ40pXdoS8VCD9Quw79ddKp2LK4jgl\r\n5PzgY6onSTg6Zqo/UQEY6VMDcLTugVsHICmJkevfWT22MfT5u+uDT7GJIRkU\r\nym+IgcB6RTF4s7GGIniH8SZ1m8AQ1oS8Am7pAnYK+4gp2w9kvTHVcQQ260ef\r\nJJbsqV0boL4JnbUFyXw+/fXFQ3i13egWgXwPD0FjdlN/noe4uLS+1agBjyOb\r\nUGBoD+0mmFiefLs2bPrT11hSwJ/kYmik0qhMnX3XgNWyk5x267aA9lic4R3S\r\np8ZcOVyfQkB/JewBlIeTAGrPlOl03kcOpzLZnczRNohx8M3T239dZO5bnU3C\r\nTTBdndQMZytkouJ9rYkAh0e8gASLbwrVaL1h1VyV7TWU3glhYIsgScEzJAaE\r\nZDrtw4i6OVEsmAnrhFQ8BUsv6wNQVN/O4Gv90JaBQaxuZh1uA6Vmb42OXIwp\r\nQ3W9KcPSqUBGwxsN+AqPmlSN5apImzGGhZboNx+rGhyW5gJzw5OmBJyuX/lH\r\nxZ9vs9GNSq5nwTBzBXFOEIBmW4fu5AU8RoO6S6O2/pOV9HiQxODCyrgnuNUH\r\nSU/qTLigbXqD7HHLaXE7yNiimARdZXnHLjqBld0G3m+ezlmeJ8Xo+Z098JKv\r\nThZWkBY/EbrQWL8Ozmrqj3k0SCMUx+9CBjg=\r\n=zplc\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"46b9b34ce0090f9765b829516e0d970c9ce2b8b0","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.219+46b9b34ce","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.219_1668219887034_0.6563606983990182","host":"s3://npm-registry-packages"}},"4.0.0-canary.220":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.220","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.220","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"b9427295d7da68958c527e651a35c74f7af22371","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.220.tgz","fileCount":49,"integrity":"sha512-kj2ESwgabQykhGvnqhW1otkp8Y+cXpYCJvbXZM9HWrSC+3mukDcRDThh/LdULHRZrNYptZXifG5PVoGuUZ/yUg==","signatures":[{"sig":"MEYCIQDU7eUnGeWafSeYuMqMVqIM5JgIHu4jWBfIVB+XaXX1WgIhAM55H98HO/6UL9BzfpQKwfMZw7ZnxHZ4yJODU0p1Og8L","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":254738,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbwq7ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpJdw/+LH3h9U+AwKTc2vltjaYJIUla8b0LZN6FfYmij2xus+7b7zLz\r\neTdVWn6CzjsZNWe7sjFcRL+wUYClVNRgpMjdkHvTTUdf/+iIrLpovi1c8fKs\r\nH2YM9Bq5H28Inq8vCSadgtBHysgXeeYPA6V+ou+EZi1IoPjOWR4ifKdFuO1J\r\n38Kk/4gFtkQTqMTmMAg6cswodGOxLH04TGpPq+pcx3NcCCtsDxKos7PeOgu7\r\nTU4LwHaxkqq2aFutPzBqV19xTmmoWyy2zTqBRINspmZI1LeXyBhBd5jT24a2\r\nw9NpMT9TkU3eFdJT+Xib2Ce4ZoQpYjA7fauJxrwzx0aF7Mviy5UxvAcP3qYZ\r\nXxC8XoGkz2nes2H48l0pjr7Qvh3ZlTVCINEO9zkx1KCXVn9NlJhJ6tiYl1jR\r\ny6WJMpUjO34BJRW/Ms081YkSOBQRon67pEC+uKVmG5L6J/X4FNuaWQPB9U26\r\nf9RxR50ae6YiNcXiS8wrExy0j8r2Z6ikKwknZPXGG4ZTDS4Uk9nvSNulWRyp\r\n2apGwyE2Hjg9cZrFvPF3JgVZy/jX0KhXFTgrUFhQymXPPkUU+3aie6efko63\r\nek9ZYW5jixZBtVLK0vVGgk0YDTCCleVAFtITUdc2hAjR59mu7cfSMXI4qp7/\r\ntDgD1YuzK97aSaHBt7diWksWS5HTcWSKW/k=\r\n=Njc3\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"7aefd74c3bfe12d56ff56c8852ea280076d3ecf7","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.220+7aefd74c3","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.220_1668221627158_0.06224115467297242","host":"s3://npm-registry-packages"}},"4.0.0-canary.221":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.221","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.221","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"6364230ebc670dbd9cdc4e4c4c0e944e2fb2d14d","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.221.tgz","fileCount":49,"integrity":"sha512-j+4JbtjRPQ1U5IX/PYggplAbOID+0YiYoF82tH1kpAF0klgTPb1rrLCiYq16iRZ08n9Lpnigi3RSrG4RWtry1A==","signatures":[{"sig":"MEUCIQDRX6wPSo07mHhSCtlYLb+uOnYj2OTweOOn27/MsnNaTgIgEa+iZ4j1oZzm+cVl4w7RTzRVUfQhmJiqB4Iym9SONFA=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":254738,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjcAoiACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpZmw//YfkuLO5cJLTxegiNGt/wMCvtIyOjzNCDJBWzvEbikbPTgLrJ\r\ndA/aelWjaJfe45plwW166TIxfdhS7zTfeSoT+H7/M+QjLx/QWJScKNrS3Pnt\r\nRcXWDZmOf/WnE0mw7NhfkAZkzN1msbY2wrPXCBoaBnWdlXu00y4GJuvjEvGy\r\niR5j2xqwfI/ULcLNth1MA7K0K2JPJrSyN0qz29P3pZQ8IywGi249YO8qANst\r\nS4GdwK2XAc/tNJQwRYxA4Ky06lB6fQ37etJQG/3Y8rGKeQxXPbyVsIXwNuO4\r\na7ZNJ2LQNCFk+oLghEHPgEB7f5NbHmeA8dUJbGb9F+/tuVzwNRtCrB/x6glO\r\nmlz+eGPqZJFjnaKXTLd2tDMUeF9zTtNEBFS9R41252R60nF6D1rOAON9e6QB\r\np+axG1qlr/pWPd2GDKprhxkdYny7/qOxIkuZb5WHhiS5hc+VSAALxmG3Y1eO\r\nmOgSeVmvkjTs/UDEFokO+g67RvUbBBIL1dJcJ0J4zK56o++v7fuiXVov+xfM\r\nVMy59noDky3+QJMyThUG6cQmTUGA/BkcqupQpP6MLOYbaBnuPYrXebm+HDgW\r\nvU20U3KWwZk72rlxgNA5J4tfpvQaxVAB+Fb+jdPRk8Kj/tXPc8gFdXIGqhpD\r\n+ccz8uqMyNF3OQdQnE/IsTIIx4d9w/HSh7U=\r\n=kZtD\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"4e3005252577dfb74c83429136b8bff043fb3342","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.221+4e3005252","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.221_1668287010749_0.914272286299751","host":"s3://npm-registry-packages"}},"4.0.0-canary.222":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.222","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.222","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"d8e13a026a6e2b6a4eea3e85f59819a7947a4726","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.222.tgz","fileCount":49,"integrity":"sha512-wFUd0oNJacrr4AMRVWFT+HDIIQZLlANMji1NnpfrK0jRBIkmJ6ZID9f1sQmeOgPxV++zARSETkge4HzrqXiUTQ==","signatures":[{"sig":"MEUCIQDdfMsQehhJ3K9J2qiU82f3PdeHWESqS6QVLUP1prBtbgIgIG5wVdicmbYdMIlCNVcapLJb0HRg/r9iQuVXYLqImCg=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":254738,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjcAqHACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpBKg/9Fjvr5k5mozE4Cme0c3YPr/E/SlOVrv2SaFK2+B3b0/ueBmR5\r\neEnonze+T646v6dw485zjMGk4pB+ce64RuHl0C91lZAf/jwz4JkbW3J7OF7a\r\nZtc2YTUuJ0777pWtMfZzDQnqdpEsyymUu/UjbVlK2tULIdvGYZmS15O8kYAX\r\nHgahjdxsV4sO3eCQhpZU5HrYF3SMYULcU/84G2HOnh3SmyTMy736VEMEx+3n\r\nkGiy9hGZ79fptYPS15vRh2g3gryPrpVW5bnhJLn1GoSIF6xCbSurNZH8Kw5Y\r\nfl48JKm2BjQB1UIbP6wFhjOgTSf/iO6w1haURgxE/Ucw38lhG/GuS1pGNBQs\r\n1vYCm79zZlk/R4P1N/lPgtvR1PgZVRk5eSrn3hZw5fAhJO8rhDRrLm9ZwsLz\r\nZ4TsncCjq9crELV8gl7zFphKQtjtwYMvQoQuu3MCZv1kJQHdV2dwdXVli8JU\r\nlUBkjA6Iy2piSND7YcFoQfOdiFEssTFKp5/c7g+DGG4bzjGJzRbHDv90MoU4\r\nvXXX5OijVhtY39vujYSJJZhODXVMsgZYuMrb2si9TBoVo+k+xqSXOEQZx54r\r\nr7NAAVCimK9TAvcQuurq/nswwxHzSxlilA8vuNdCb5v64ArUCtaF9K6eIQUk\r\nmZ9d5uUaIi/2M22zqEQ/W8y6lUw3D0dPdZY=\r\n=OS3Z\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"a9c13f656ecd9ba22b9a9546b0c7fd46a2e43e55","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.222+a9c13f656","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.222_1668287111288_0.9255009685850717","host":"s3://npm-registry-packages"}},"4.0.0-canary.223":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.223","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.223","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"269b45dce28d3158600518ae8762a142569256e3","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.223.tgz","fileCount":49,"integrity":"sha512-THn7/frQNLKKQoarWb1DRNtgIgnb6rPa6yz/Y0oP1vS+Lwi6hOQtadaW/93tjWzxMAgHAP3oYzhiI0HJtGrFoQ==","signatures":[{"sig":"MEUCIQCWv+dgkhx2r3DtArbVXVq0HLbXBOBy0YYH6iBi+vYa9QIgfmY4Gf5pghN3v30m/6c/+R3t2i1esNF/xrdQe9/UcLU=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":254738,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjcDdXACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmp8wQ/+PtsNVpNvhWD0DHKsXAZkGxzqU9yX45K++HOnFnV+Azo0C3Lf\r\n6C7gA8VT2s6qTeukGvqxSB5ou9u2ku/opoW8kyJgbd5WOsfitEl0EkCz+bgj\r\nDobwZq4EwB8lLQw1YNaxagaOjF94lHuVbMwCIxqxW1vwpY6LGLRlIs5RbLD2\r\nQgarEYSyhF63vzzzoGrfyqHZeBYYsq3YdxI88bdF6disEzudd0xWmtqrh7fa\r\nqsNlw6mc668Mwcu0fKN8CUR0t605TUmAcImq5zlRr5YqdFGiWLu5/oyFqj3J\r\no3Odw3MyrqM90PLGBDOSM5F2VEiwXg60qtx0jPxlAm20hskZ/YjyLMbeKoW4\r\nkYPBlsDEZrJXUdQv41IOgPrfqus24hcA18ve1wM6gfuWytOziNjwjMAVMlrj\r\n9eXSE5LQCvdsCWfJbB52ZfgTHy0yLGo651bp0aDRiNx20CpY+zlf3butLi78\r\nNbYRSkFYrTLWL5uxJ4JdnjhMcJZ028nnU45KHrfGPLSQVQuEGIr+RYqWclev\r\nsl3yeQ1X6ABhGpncEhyOlgA12IEGPFK/0YFKcD5oowctCDRo3uS2V9w0/jEh\r\naFNHr5pKvEq5c7D7ChuQA734G17iKQOilKWLicQB0baxJ33dB2RD4kL5uFQY\r\nJNInOn1J71+vJUQBc31Cc5lWujZvTBmz0Pk=\r\n=EmZt\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"4737667f45335d1de687b51b0ae8ffafac184d3c","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.223+4737667f4","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.223_1668298583549_0.17886900163365005","host":"s3://npm-registry-packages"}},"4.0.0-canary.224":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.224","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.224","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"90fd02f2a400177e62f15f8f626a190c26b911f5","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.224.tgz","fileCount":49,"integrity":"sha512-tdyC9FNmbNbrFDJRStBC4Hrcq3g8Wla09+F4iMKpn8SVD10IcDvTquY+iuVTil31AQQdXO/r5ap7voW+NOCpDA==","signatures":[{"sig":"MEYCIQDVZMVlceiscYAsHXiODal8YBzjCuTbMM57PLowYmRqiwIhALyaaLyuaqZXO9TFIKMhDOswk0w0HKRssalEeIvV8GFb","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":254738,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjcFjOACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoTPQ/9GOI+7vtptcMAFx092FqEr4CqS4C1G4LRB+B7YnHaG7sBlQ7Z\r\nXUbVzILNj4cvKzX+7xIZbzMWBwWc59mirt5V4jG740vLAK1hDpkwgXy6DIDG\r\nzq2frmzc5vFTUoAwBHpPB1neFvq9lWhM+zyPH5p5EDtZ969xwVli6q3E2HDU\r\nYPKvaIJE6m4mgwVP3XoNJcjNlGdW79a7N7kf+/ld2CfHHMcNXb5/U4KjREaG\r\ni1Eiq6I4R3FmDulqzELyyNbggNprH4EVrBJO4bSoRDIyuP/8ss4nA9+M/np7\r\nGj8JLkeRDS+EaHwX8Fy3rFVsers8bRv9G2a7xGiwUNh0OJUkqjYQgC897jHK\r\nvRB7Fv9m26ghKrwmAMr3Lk1HFwbhoUNMuqHietG37Sq+g3OZ3b3F/Oh15lXp\r\nR0XrYxl3IzzI2HPqP04vhR9tQf1vPq9mTpJcnlBuvuiBxYSxe/DASVsMZJHE\r\n6ZSBvkxJ8+dN9ilPifwDse2Mk9tZTM6vpUH2h+c2XMVoBZ+PrsY6+zyOjgux\r\nA3MTTYmK0Czwuwz7cQAZ4xlAbSPogSwBGTQnlBhYdBxsX+DGioQxOP83bHyg\r\nVhnXs45MVpzezxVlqPOFQxHqT4bl6LUwA/Q23/rVTaNMd5WxhVQuAJ1r/nD5\r\nYQ2TtnFlllHYu9afgd2EzK7YvJaDQWGszKE=\r\n=XEFx\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"c6bec27b4e51e2d214b28ec9d3bd25971d94d50e","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.224+c6bec27b4","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.224_1668307150637_0.6802965188892618","host":"s3://npm-registry-packages"}},"4.0.0-canary.225":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.225","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.225","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"822f8096c719c3aeb503e66041f8cbb442bf9745","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.225.tgz","fileCount":49,"integrity":"sha512-wNYNcqO48+vrJrySxjCmcBEIvnT/pz6o/ZljzVV7/rtREJK7bZMROtj79rcZ/tY54Qdk6VjQX4vi82QSbMWaSQ==","signatures":[{"sig":"MEYCIQCDnNbzDEfZobHhVSlQM8ClruuoTLTfUfGDbpV8GotWzQIhAPLWbQIO0droSbEl09/ix0f5Z+xt4jUvh+DOjHqloe1G","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":254738,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjcIAZACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoBShAAiB3OG5cgq72wbxUzq8mW8FyDtTma2b5CpBo61uEm6Pr+qcwR\r\nI0zbJD/WC6Wjl5GqJ3QI1SkS6Z3DQGqkBy/RSivlW6FWphnq7iGUa2mhZnI7\r\n5ibPsVW4Mpi6o51ExibjMwBhZt0dazbgIRkpae/w32bjPCW8TP0gNT3WvG37\r\noMr0ur38ltWmljtTd/auWOXuIiP3utGzSUO5MJFB51j29J8KBCvp2X+XIXaL\r\nis195dEWknZa8OwbAdKVKTa6wv2MkYvVYeQ6DqptW+qT1GwJFTY+gG/z7a6M\r\nzzXDMsdWeApi6ESIi37hVsbj86mqaTF+0L5Q9FoLoum04U61z90QxrHgESZM\r\naMQPqMoSPQqiHpGPLrJCuC+W4eQ8ybjH4Do5Po9Zw2b0D5Mo6nNKC7RAfdGX\r\nRMm8yOkAjEY48Wv+9mMw6vqGMx95ADinu/uzWm9S/w4HLYbiqblJt7kB+LrB\r\nrLUNJbjBi8r2kesXSaxqzQpxgKkN8FczYx5QpvYoJxv7FU83Pb+YYLR5iYI+\r\nHq4534YWSB5IRZGJFw/5jf0fQ7a+3JRG0UOiDoJ1WNRTjKFotwYibhB90QsM\r\nlakW6qZl4Ny/f6GW5RN99QoEaRrA0oo3EzmCg/TznJbMjGwpiOkb3NWA1/+k\r\n6h9ZIx/NR4/1bsdPV/sLxg4QG1rmadYVwrs=\r\n=Vsv1\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"88d8abc4a18a4f70131a8dc04364a49686318695","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.225+88d8abc4a","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.225_1668317209282_0.05767759938713035","host":"s3://npm-registry-packages"}},"4.0.0-canary.226":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.226","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.226","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"729f559003c9a6705ce6e6cfa528cf83d6161d47","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.226.tgz","fileCount":49,"integrity":"sha512-qG8W0to9W1CbxZILRkuP28fuaKRiD2vXUx/iT4Mv+xybmDv95oPQ4HO5di03Q40H+FFEGn8CIYYumwebiNtaCA==","signatures":[{"sig":"MEQCIHvRvltYF8jtwC6zXG1LCFLwBUhiwJDz792EugM9EEPoAiBJEG9dOYDhBte6vSJ/FQFgXvH15htgxUzRVJTODultJw==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":254738,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjcKIOACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmr/7RAAik6OZIR3g2JdjEO83girAgcAar/2H/SobTibfbQziM9UwuCq\r\nPV920iJ9tXsUiGV6Vc25t9H6qixngxbgYg9guiJVy9o0eTxrSdANWuoawSof\r\n2xZo0WZZ+8gmjECQmvAatTBG/R+VNEA+gCNgslefQo+LTueVZI7msYglnK8y\r\n2U+nZb79PSIGJtdjNJTwVaJwFK3IPLdEulxdis0EUJ4+f9vBn0n82D8zXivJ\r\nOb8r4DzzXJnunG4OptsWeCoUR31/HWdVlpihDJDdlSV+PlLQidDz1tnvIGmu\r\n667WN+rO2iHf5IMvQyVLx9G8tW8QWexE7rcY2NEdV5Mvd3cD4xldXWr3fKoP\r\n0CIAGH3u+VB8bR+X+PLaqlr6Qg9MGhYJxrdAtI7KJUXfxAv5ZUBnKfzxOTrF\r\neQLH80i0dSJmM5rBHOwRn18mzhfZTUjns0ZZYnTZfiVaXrQ/kCa/b4uthlMi\r\neIOFzo6mCaVvz1Xl78LSD4heqWZ+waEnf/glePm+ma4mx2OFssxyu7A/19n8\r\nE6i8WBqmxtYRWqs1/dcSeWn9CizjWzQkeAuY23QG6JYh2r6mLVk+umuKhnXA\r\nbHy3lXeAqKr3qA6nSUAW1tBuVqo1106he5KVQZPbUNUZL9ye8jKSeT/ftBQC\r\nnUPhYcD9IqUnL4DJXw3rgRWiA+CCdiPPqsA=\r\n=a98R\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"36f33a73e47bb1c29cd76572b531be04cbb4a974","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.226+36f33a73e","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.226_1668325902587_0.9069117078073567","host":"s3://npm-registry-packages"}},"4.0.0-canary.227":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.227","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.227","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"b6a63364d9db94cf85db94e328377c4b86d79641","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.227.tgz","fileCount":49,"integrity":"sha512-sDbB5XSdlDpKR5vp5QeJ4lPqXpL6u0crqksjvj8DL483ysN3I/xP1qd8MOkU1BpzZwjpgK5VWNtwXOuH5Ci2hg==","signatures":[{"sig":"MEYCIQCOHv+to2nlqOO3RBZzmenGNjPCR5zlYVljuTHCMwlXiAIhAPWMsiPd69TFEcIU5L6x1VY9IKD80QKrQIAjiVznk072","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":254738,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjcLs2ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqV7Q/8CF7l0uYtrgSY3bNrF6GjIimL5Sgz82KZ2Xhbynkec6+Gu/98\r\nlet1c8wB7fx6Sf+YS1zOvLeahJ08x1gJPqRLmCuMor3rB1+IYxTlzjaytwjP\r\noQSDiz9vAqIadi7A8N4DjgoM6cqMyMudNSLnbsczc0jXoct1OG6CPDt3c1tM\r\nJJNQGy9PeMfUHY76fC22Si93oKrbpzqVie6wG0jDJpoiylQu5ibugIcCPiha\r\nP1qpk23mUI/nNy4tfxmq3TaA1VFY6GaBw3VC6tnu44A9DSjLk8WYzzQ3kya0\r\nK9rPcGICjR6EvAjdyWhySBdd5hJqEBscwUGo+E08+aMFc0tPUbN/LHU5ineI\r\ng2rZb/Ieh5RRu8vcKRU2fYUjUrj3SSxGmDzbRFlqA6QPbwAHQgN2tfNlyoK1\r\nvhZ5Eknc/TZVi8+qkvmlrXuqJJq5of77BPnExighTVHbHy14aNZmYZ339/DC\r\nacTafS3KGqlF/T/7dLAF3BKQtkU3oy0QqWG/zlHV/0xKrvMPxG+YUVmA1VD5\r\nJT62gSfbHGN1y//87UCWblxRKbLlFxCg6DWXtvd/WHh88lkBPuL/cfEtdKSV\r\nQVbTIgZb39QlD7B3NIw43ZR0OJDqL2ouVz3dkFvJeKrrYVPICgW7J3UzCrPK\r\n4lzT/pOQlB1ZAdn70Tqqy94tq9e/W8/x/0A=\r\n=jrd6\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"80b207b886595931000b1bf127fff5fbcfd4edd3","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.227+80b207b88","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.227_1668332342024_0.71330156059775","host":"s3://npm-registry-packages"}},"4.0.0-canary.229":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.229","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.229","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"a87e15cbe42c1abae1e48b664f30ac8c5ab35edb","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.229.tgz","fileCount":49,"integrity":"sha512-60bI2oFIRFvUJUfELFXiHTUgGk/hpTaBtIzng5Z8mXLYtvFAoALin7v9LRgBOUWmJJb3PdugHmkO4oFCIybn5g==","signatures":[{"sig":"MEUCIQDL1Gp1n1CKTZ9JXMjeD/cJO/Yl1Lg5JCwbnDmtvLYL7gIgAzFxvHN7rP1o5HT1YLDdH1nuXXCkEgvn04/pJ1lG5n4=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":254738,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjcQFlACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoBTQ//emZxZ/NSyGKdMY68SN8R0BzWlmQPEn/w/BtrgeZPjfOqR8zn\r\nvWW8m3s3qobYwEeNXaxtUOF5Ets4M5uP7cczZg7o5YvLU1porUbh2Hae4xIq\r\n17IYHQxJ1Qzz4NJEjgrJaQw7864wSJLJnY+bcWDT2qYY/h8/FnMYSDA8L9PO\r\nzZJYzyxbUadMcQkc3YadRYSmRTW8AVgGHJgszG6xwbkhtWHFFc4cdEwTwn1S\r\nUt1lFJMkR079ddKd0KiC7Byx09HXhRCiVwMuyGJrwheZtVBYZMavDiOUVIBw\r\nyUfXxImfnbs4qOnG9XDSZMfI9SWo+7FLi8FxbySLN5/yqmEdGGoplz/8o2dL\r\n1EKrYMIicGqO9b+Ed4yw8D9mAfzur1uMKLn21vSrjxWWNp4uFnKux0Hrhbs7\r\nwpSSHhHEDLANFKavzRxjzY9ktl409w5Nh0rHZ+DN35l/OFVWlSYmDW+gK+uz\r\n97mNk/lzeLO021EiVtP3XjFYka2PL6dxlG4E8M5AkFUmg2PUkQhJDHzdKSgf\r\n5B+zTa4iOoBObEqEGd84Fb3NjIc4duU9zx9+memnOWKsjjUmmeZtnBVhE+34\r\nZzCvQ0c2TY/3W8RkuJXwxB2lFWzJ437bpFikufJx6UQj1WH8OeTO26wUK3Mb\r\nPhKA2W0FT+IAOYrVp6uzfJd+jN/6dykV6JY=\r\n=cEie\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"61ec0fe65985b41e880020a656d7ef7aa88ebaf5","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.229+61ec0fe65","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.229_1668350309055_0.7628327589912238","host":"s3://npm-registry-packages"}},"4.0.0-canary.230":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.230","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.230","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"1c99276538a97ff5e54f5a6e8c61f66e2efa9ecf","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.230.tgz","fileCount":49,"integrity":"sha512-XD5XS4FimXtEJwIkFIyAQfOJV13JLBoTyxPhGT83rHbCehjKM4ZWqvDwoXDesUz5sz9jmXUksca9Ol1cWJBf9g==","signatures":[{"sig":"MEUCIQDh+nzgKUosUq/8n0Ylrl/GfCmLSfwG4f0MNnJDeMmTfAIgOUvmUCFdEqiqtyQ/oP4J4iPTg1zeUVaSeVAFkUDm+Og=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":254738,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjc0GkACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpoiA/8DAQofaeNzo2pDPZD1vgSE/VkbNwOS4rT6m+J46gck2bwi1eh\r\nl/HGuYTIriEG8RNDU+/ip2pgj1/h7IWVP00PvjcUFTDvxaFvxRv0zpiMl8gC\r\nLfVYWEEW+Q744l0fGMCEbFhf51b8sKO+3f9vKWPNZoHEO85fVB1T0l9DTQ2N\r\nCbDnukGOTo+ZrzgyVs0y5Fk3Gx4qY+rux7uh2zpOp795HYPiT/YtzrBQGUno\r\ngE7eD0kpCzqNEZ4BmLLSWaKmyDCDpg7+Iczp9Q7CgON2dwgZv0U0RhdA8QIA\r\nU5kv9FPaUGyZ4zFNp/9w3c2+qPqwQadyRQ+A2XbJ89I1B/EnKZVpLQxss5o5\r\nS0b7f1MzC2ZggH91XKYuAylaEtvlc7P/hWob4xPIEIXLgmstAyz2fADb4a8r\r\nxBRomw7xX454/nrHmxe0JO6rp2oqh6rZZ1X7/GEk6af35tc2IzKuOFpHz1kM\r\n/2iiubofsvbdlShe6Ircz/fzDENAfnegwEOZyLf4Ar8OgntuF2hAhtFypT16\r\nzWX25MxlOKqOI7NylPy+3oTF7JCJqmljZCaW75nD5kZMI6BhxK2JXPfjFH10\r\ncsC2OLS4H2UogssSMsFmxGmfQbl2aLLmhGtLp6pBm6Hq737rIXUxNWEWM+ms\r\nSNgYPQqGn9+0h/jqO1PN64xIgAOqewT4Cxo=\r\n=lQtU\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"fd8229c550864f11c8140b8f8cb43f8d609ebd52","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.230+fd8229c55","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.230_1668497828186_0.056356403704676206","host":"s3://npm-registry-packages"}},"4.0.0-canary.231":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.231","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.231","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"aacf70488515ecdf92103e4ea582867a25b1ef4c","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.231.tgz","fileCount":51,"integrity":"sha512-fAcF6ADLhB+Yg8O0vO42Tg8qnvr3TzaGkVdGpgZrfDc6ufSB6b5nbz/I7tTC0VfhucsS9BEAv+XTByL1YvjI4w==","signatures":[{"sig":"MEQCIDBTVZ4UdS+A1wOompTGxboKfxoopv03b4//dwfobt1VAiAXJRkLY5yrNBYyIYm3ACjxpx43QHTOIgCMb/CiooCYtg==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":254907,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjdS6XACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmpvpg/7Bwfo32wxOhCQTDp8iV9QaI9+7vNnpNIfFiVbMU2krEcCZfq1\r\n8o0F+jTejMIkXFmfze13LkwVT/+A/ot/s1rp6G2+saphlFSmq45hSDCTDoqk\r\n0kVlSEGwbIlPzgwdtNZY/yMPtz/slGoU8azPnCmSTk6fePfpO5gXcRjbAeOZ\r\nM845G3P74hjm12Ueh1rO+xHcjzndbPDYu7ft5a82Z3CRMiodlfJFOWd2kcVj\r\n8BeMMPWqKCGrgxvzFfDg6ZqGi1/10f7rlnXsMTao882P9IPVFcgACdUfutGp\r\niGj0tLW2ai46WfEaoirX2548V1NbBLAEsxJ85ctpR8X8r4zldolWZThz1ikM\r\nWggvGjNSDeMYSlga/CXeWXpilHWhLpvPxQWHU5KxSaA1XQtuvFzb1K2zzFzJ\r\n1vmMsQg8mw/2vnMFI2ICyZlXdyatvC6TJn+aezwUn3jQeaxMqw6fRhCpVRfY\r\nFabAjEeGa+W7B9/8HuOWcmh3pKoRvGirZ7t/2py5EDMNnDU0vjjaIUjbjtZw\r\nvsAN28rBlSTIXAgBh/UeXG9BHcb2rSiqAm9krWjUh1KqJPeqNW7WOlL559KG\r\nyNcs3v1YPAi/I3xvtVlUI2OtLt2YqNqruN1U4JjzqRIkwrbn6Q/Jp7YrNTzu\r\nv2EuQ6PgrAQfsSZLewmXPd6wX6OUmBAYTyo=\r\n=dkYt\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"97c36e1de6ed3579056aedaf6c0076fdff550c4a","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.231+97c36e1de","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.231_1668624022989_0.6152246264144026","host":"s3://npm-registry-packages"}},"4.0.0-canary.232":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.232","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.232","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"fe5c2f8c9a8c037f8510c447ec2779c0e0b26fe5","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.232.tgz","fileCount":51,"integrity":"sha512-McSt/G2qaqParM6ZBozzyLi4cOw+mY8svbKuvn+kp6HoFjpJda6OGnMyQJgDCTM8VC04Br1VZbLaFFgF9GCMzg==","signatures":[{"sig":"MEQCIHHGIQfYnDvs9GVway1bRSYOUufHxWbr18mk7jDoFQQbAiBJunal+64DD2tt5vN2FUZPybzB1//YWjARH4J7PopYZw==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":254907,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjdXU8ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqKWg//SgftB2icDLEHwUYpRsR10jcP2e1eI3mQ1H1P764ejLMlsRTl\r\nb1r973IylCoVwqy2gH/OKZoFulCgyC01TMy/Kpmh9/aq85e/OOW7fHLb8WV7\r\nM3OmbNRmT2rvVjh0ztEXkfPqM/RNfzmV2HaCzj8pEw36lNRqtR17JQYT2MOV\r\nTkgmwc7J9hZrVzl8LdsYp25ytO3s2zCJz/moecp3mllc09XNqdBwYBpY2b3G\r\nS6DENxnNFbuBavEqnX+N/7VwlCwAokA5w99EGQtEYeJYhHW6oLzKesZVaxEK\r\nFHPv7wPceiwohXBQKBeLkFVHglQpJ0pkU9VTR5FJtakj4yE1qphDK3BCr0Xi\r\nVo+fmCAyOJYRT5yIXbKwC24PrqTmsjYd0kvBlYwbEm30zerLkRIIHMSkBwnd\r\ncNfPzYXQ89K2qJZgif+Fa1j8sfWY36gOZe+yokQsWQMNH0LCuE2HEGP9fUwz\r\n2FepvPVMIW5A1HpJw+njSLEQZGYW2Tl4AAFeuNbetN7RXnRrSjLuC0rQ6fw7\r\n1lTb3Pqf3Cx7BO1RfcKZM98L6SjY8gZB4dLSKhUGdrtlfOw0HDjq9Rn7SdQO\r\nRYyFTh0+KLahocorYpwG6jvGaFOvMCI8W+NIh+a8BoMat2MsUE7ETSvBadXC\r\nwSmgsieRml3d3vYkJADl+xfQRPR07JRxeL8=\r\n=aN9T\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"da8710fe030f9c517524fd88f304e734298aa56b","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.232+da8710fe0","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.232_1668642108065_0.4506301601957834","host":"s3://npm-registry-packages"}},"4.0.0-canary.233":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.233","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.233","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"82486ec50302a04006c8c969f4216b96d16b5c5e","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.233.tgz","fileCount":51,"integrity":"sha512-NJS9U8K78/llrgIxrwcZwT2GIifV0AUfLGiipJ9xPUmSnC4qh8RXvaTZP/MyJ9X1taVgiT5Y66hSRgNVQz8lYw==","signatures":[{"sig":"MEQCIFUClbMIebKPwqdUmxjmG1LT7cEFoQI4KnbDhkg5UE70AiAD7aHhuUP6DVF1XIlT6fknq7toQIjRJC1BcriziEkVfw==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":254907,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjdohpACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmqprg//Tzh+opTJSZytQZJfTsYiqkZJvl8Qn66lrHIkDWJN9MZn7E9q\r\nm+nN3eNx0+1BFvsB9QAkXBLB/RfUU9Z3BZcNx9AvyYTIW+Pv638TDs0BZCht\r\nZsl0fvWpl4vcVa29DUWP0kBjv4vmhz793qJFeCe/GT8beBXzN4CpF0n0Keoy\r\nXNaI4GQuX8DF950+jtdDCODZZEeu8fntMAlGoM/m4gjkk7s0NIBYa/pyLaCG\r\nb1ZTFjSxnC9JPZcLqz8fJoOzyHVXE+g7ph3LBsuY1kJENxHGFghjInMllze2\r\no3YMS+A0RUfuNFU7LjO/yugW5KhVHsCigjyYXc7U8UfhcYYgROzeOhIf2nTX\r\nebxwNosCYZ4FpVSASjjNn2xGI45fpftl9RyTMjbEu+XfeKDaDfXdYgXrApSZ\r\nVSMgjnzmictx7A0E1q5qGvwYKRhe3fNkHotQKHbPQfiKuzQaJVFax3E9NS6x\r\nuBrEt8wosx6uFzKKrqU0bZxgY6CpkBcfdGH4NeORbYhqpbMD3Ru5hZB/U1Zp\r\nsufgC41vUBDq10MZ0foTnlmdN929RJFa/T8BDKUwI7WP9ZLpCI5SuEtj/eCF\r\nTKmlK/4Ns6XIyFr+jsl7cCaX3br4ap1HUQYBmQALJYy+hINIQjeJZxoS2erj\r\ngKNkU0R7/hXFOZb8fqgo4spKjg2E4u3Syog=\r\n=zG1C\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"5c46d7812ff415f1ad30838ba8ffc01ccb253bbf","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.233+5c46d7812","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.233_1668712553140_0.06078449042793577","host":"s3://npm-registry-packages"}},"4.0.0-canary.234":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.234","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.234","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"4a48d6a879b9bafc69a7c6f9e8f7b91592cce5b1","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.234.tgz","fileCount":51,"integrity":"sha512-Sx7ZvaFKOo1CgDQBn9eczE3UI7j3DhT3LAEyX+APTZqLM/sVbYna8yYFV23V5wqvx40PyXOolNeoBH6yhTabAA==","signatures":[{"sig":"MEQCIE6u6eSsS1Zt/N4iHXdNR//ZxC/JvEnfMlcRpVlT0TXnAiAviEZ7GnFNUr8OXf0DS1npioeYviGrgzlG9kRF1RI/zg==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":254907,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjeD7XACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpBpxAAhIyVdRrmiSEHUx9mlkvKAyDgzVfUVozCj5rV3I2gjp2Xr3KX\r\n40cZdLZipPJJoZlKICqXZsKBgQ6Ee8yobdLMh/SDw/X0AfLb7//e6FhSmVsJ\r\nI4AJ0dR9Bpe/sq41V8xAFEryQqlPNwO6mWvC02lJJgdZBUiOGbJ0NSXyABVP\r\ntLj4hTSb+dPTzho06lcCkbCIU4nyceLZDfS7MafqbcRnGGt4g5BQ0JRwj2xy\r\nHNsZY1D7eHrNbRLS8gTr2hH/warDkpmvF7xHzKht/qzBizIuZUO60tv3ON5a\r\n2PCNn5XNOFxGAZX8UhBC7KjogHuQeoO3Cd3mb00ztvJZ2vVzYVcIRqSi9E76\r\nNuiVvvrMrqHIaw/y+FQrJ0FW1gdZC4uqTRrYm8uM8jFcvn2xk6eeYD0Q/elJ\r\nJTUizBZNOVf7EWJGlFqJ72Nry7EmE4sj6wBSJWb8pa6zVcMToRzd6KE7ycxC\r\n/tdyG2h31evLQWnlXuWCqDc7YsT/5x0BG8Lkd/aJBmXe7LAbLqCn8hKrRun4\r\nOg1EzBq04Z2U8iXxJa/byCniEeurfKHBMeQCPgRgkvtQ4C+ONarS1pWa0TrP\r\na2r5n30YJQW6NBKE0Mzqo5zMAGyNQr0gdI2XfgcoIFzzUTAFZDckCu+P7xym\r\n7qED//fAYtjIUclcro0npVwe4Z/9hN36lFc=\r\n=JCZr\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"5b772cbf4b002297428127ad804631fd0c62386e","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.234+5b772cbf4","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.234_1668824790898_0.8059438310063258","host":"s3://npm-registry-packages"}},"4.0.0-canary.235":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.235","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.235","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"d419977c99ba7badf829f3c7b3b86c0b0d8eeed6","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.235.tgz","fileCount":51,"integrity":"sha512-I3O3QuS8s1TScFIWS5Ll0+XUdUIg26Uaxzk8eRaXUpqjfF0yOlk/i70JtrG/Iu0CoGaxr7fNzuVyzRXY2HkUzA==","signatures":[{"sig":"MEYCIQCeYegzCicF/U5AV51JZRknGwzoi4E66TbRLFGwemCXTgIhANOH8ShfElbGAIRoKtdkA+C8RjxscnwHbfFBChmwmMV4","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":254907,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjeXJTACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmodog//Rc9WKWFJvIqrHjueGpfcyJfy6ZlKEO7WZjcbwNMv3KJgleOb\r\nTTl/le4h8F6DyVfP8oQbqSLux5p/KNrdGZVQgOK1jdDSPM9XznqqTpWzcD4V\r\noz7vp+rfnFck8Z7ZvcKVzXSCDsnzkZNXw0ArfGrFNoBiQz5YY5xNiQUAdYVF\r\nsGWQxBss+wVxpqEduNw5FUjb2yKvzFj+/tSs0ShxoQSs++1EsZ7XsHs+2Q2r\r\nUm+NkdGGJ27X2a7VYPXgqRcEt2m2wfAYvDsKVmo0cl+4nwu0esLUQ7gmd+Z5\r\nFtFmBi8e+Xm45dZw0EoaL1HA012nGm/Z/f6z3orf2XODR//k2D/i1aYoSVjT\r\nSA2x5sEoS4bzMsR9Jcp4/oAA6ZW7ZOeDH7luCbqKOErX6d2/pIAjS6mK3V73\r\nExyoUk94bgn/3cDXGs0IAedMfUZxis0D6p4uU/rsClnrDoGFiaopTbKLh8we\r\nUHIb27OU3CDeG1dgvbwVlKT0Fh229kkDRsdV4LJDMT8KCHBIxuKwRJYfc0+B\r\nseThCcGr+DZiXq+yUyeSQewKKo48nfgZIOtjGtoz5bT1P2tZmFjAdZTKa9j5\r\nkoog7Kwu4F09/uGWxkSmK6DHI1v7bGgEExdYIY8XcP9IFmd9A9VzaETFvVIJ\r\nxMNcT6uO+3r5zIgkzqcAWKeWvUVVtWLnrAw=\r\n=KE4h\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"2bc3a544167538da5c12e66902f6a385f4a374d4","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.235+2bc3a5441","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.235_1668903507357_0.5705983193395996","host":"s3://npm-registry-packages"}},"4.0.0-canary.236":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.236","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.236","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"4e75eed1b37109b5042cdff1d1e19b4f4d787701","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.236.tgz","fileCount":51,"integrity":"sha512-9F1b82Qc6eMmebqYOvFfx+ok5WbsWnH2g6zIUCvzYJQ53j/3bhg6bOoT3ISTO8U3RPPgmjPnDO5LRddDPfIsxw==","signatures":[{"sig":"MEYCIQCv5pJ0K5ANtcoBU4nsmQJSUdpjg1qoan7C4Za0rdfHOQIhAI+Mf33KR0P3A6LJIPJkHfi0pM/xk+AKOzZY7QTFAfpz","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":254907,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJje7tHACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpLbw/9HbdkIXDzTSV2Fd2JlbWyhYwhjUwq3+FuQFLNnkYQbReaL2z5\r\nEOJG23c2ubYLr4FsUDkc4C7IXZPKfLdpACmVM0PMsgqjwNODQ42mXdIsKvAb\r\nt8xXZ4ipXlJlVTjWte/bXbWKmhgTF2L1oVvDuaF1m5t1w1rhg4b0FkUgtPmY\r\nFy4AvfjcfSoFriXiSJHVS0mbR+ZgXCmJF56WMpaRofqKz2CfFJyYdVDwdyfK\r\ny/lcOB1bpkYOa8pkaOIbgibCfydNQRfMW2O9TlSIU1t1n76QMNYlxdPqbedP\r\nLmYioMLvHCIo4gSEWF48QckXS1xnYZhaFX891LHs8yFK5mOhObVpAZjR73a/\r\nF9CILDAU8Hlj8z6k7dNLOcdKopQdgRVk8xPj5yX29tBYb2eqVnyIer4NI0Nh\r\n6enm/AkDzn7yDy/4ARgkAA+AjZyYXua3dhl/TR7JkkZZgTFsRFBYQ+UiMBaF\r\n8p9k3Vp7K+v0MZvC7ks0a57ufsMWqGuEDRv4gZ9acy5JDufq5Ya8chBElLCl\r\nEfqW8nbD6AmFZR2FHh+lhVRsxg48VpocNheEJVnhP6Pon2dt0fux/SuqpHzF\r\n09l8ExirxBarYNij8mkQ0wdypjEVFiEuFSgLZl8IgdYs1RG4tYjdqgbZ0wW0\r\nrxB6BR/+YjGRxK/pkFT6dMVeFbyr+WjQgS4=\r\n=P/wK\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"2e4e4e136ffa40d913c629dd392996233c6008c0","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.236+2e4e4e136","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.236_1669053255520_0.3865029883269979","host":"s3://npm-registry-packages"}},"4.0.0-canary.237":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.237","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.237","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"163e5a16cc4b46ea71d893da23fb27b83ccaeedf","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.237.tgz","fileCount":51,"integrity":"sha512-u8j1Yry3vx3FMRznaQ8V0QUuZDg5yRaY7MnrqLwlaBXlN2fetjd6TDIo4gNnoOUyLsp9DkfBi6p+7uVGYp+SDw==","signatures":[{"sig":"MEUCICULMhhDq6fnxlvoS+bRQ10CVKi1sGCmdZG0C09UqzgHAiEAyANmYvktg+8xG8HEcdkx5l5+AJfiE0IHHjfyCab8uPo=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":254907,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJje8chACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmqfaw//cLT2Jbh9AKIAY5sBQB3PU0/9qAmEXyB9sXKxIiPavcNTj+DR\r\nlBRk1Qx1AeDEn/sw8+u2pc2kkfshItDkV3RYRxjk//sMlX21lJuRYqe1dRZ4\r\n3Y3eVuNb+3lKCapgRBT5zecfGFYjY/S6ubwKJF6sIaC/dwZKPoJoRbAqXxtW\r\n5i+gXvRry74+V6hkVNFfmaYakMBGqiJMtmZhV6TXecWhic8l4D0dRsWkyz58\r\nPHENeMGIkI0OIcJ33P6Zokc99UbhoAGlt0t0f+90oJn2OAcy35WppGFJzRl2\r\niGQZepMBty0wlSwBZn502Ks/hsfUCOOnL4/FDFiowRnZ7HLygQSuf6gYSo5/\r\nKGAAV76N+aB4uXAbtd8Zxj2woBBf8BLZsIi7uGAPEw1/Lh2pUAAqzmonqeeH\r\nj4cc6+iLvSj5iw+Qi9bZ+ix7Xy58m0iMBQmGgoisZpMvNIB0pGN4y9aYtN8D\r\naXR3fKBJ64HOJ4tqELjYH/YF8S9sD7OXpW+Kn8noAwcLvG7HegYq+4z/mRKF\r\nXmKU14zwXjmlXdqqy8H5+eKFMJUDvW7r1R7cb2NwxO/1EQz6IQ8yna1Zmush\r\nxcuMaaK0J3WnQSYveeQymYALoKZrjDSqmQkS0v76NfIrQjSZx90Joc6trrWX\r\nsOxWTXsh2VGnoPOCK9jn+t9CAVJiZBesOOg=\r\n=PwbG\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"4e0960a81f1b73c7055e7ee8e9b1666829df44a8","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.237+4e0960a81","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.237_1669056289576_0.28545525862876064","host":"s3://npm-registry-packages"}},"4.0.0-canary.238":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.238","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.238","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"1b8358ac0cfbe9b491d9685284a295233708179f","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.238.tgz","fileCount":51,"integrity":"sha512-CTn6EIOQfN2qlEtR35HUdMrh2iz/7mrj1qJIbPAMytMCJ0+2a8sRJEgB9kF+6wRblgpelrC5GaYBVL0gznuamw==","signatures":[{"sig":"MEQCIEowbDxprYUBhP2hccC1O8OF6ocNCmqh0XkruX2goMXKAiBdhT24av2v3C1W5ic6RJU0/g+wzpk73OgZDlqi2mdJFw==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":254907,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJje8dcACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmosUQ//f0zBxoAP21gt2UjgHs2lMLoioZKdjErg09IdxL/NzS4heSq+\r\nqgC1jD00Wvn3c+dgA3F5snZbRp8P0P26N6SqWfSy+HRrpEjHw2qqFwB73Hfh\r\npmSpApKfCPfYQWaYmywXiF2MuEGp12viB03Tl5GMrnxQOZGMROCsLzpgULcQ\r\nsGz8b7Q0AJApBJwo/R5C6fW7T1f6MRb6MipZh2qIe0GwfFSM3oCEw3cS+czN\r\nit4HTgiCbni6cbX8V4ednyZdeGh8kriKCwO57llBs1BAa8IWejYqRZR+k616\r\nFYkhWrjNdADXCNnix3h187z/8lMn0r+5D/778yZbnQpfvdk0wOTWpsBjjiME\r\nJy1TUg6WQcoUFjGDszmX4PyNKcbMBKtHgrKyrr5/70C2GTqP1DujVTeZNim+\r\nKlc+OUogS6S9XFdunb0FNZrvr60z0/07y1kbYwb54zLSjY8wN5MRwnrbC+9z\r\noXyQwCKQVh8b5eR5wnRzDQIvn15GYsZRMFH2jK5CtUUPRMFJ8afPwhjasWl0\r\nvfTncyhNDrboiGTp6ZtPVxN5DguGndH8F04Z5FauAvQnQgN76HHl8b3q2Yr3\r\n51m/SYbGNSoFRuDE7SVC7qQ34L4Qf85kBO5Cm4kzTQ+/SXy+ZZPVeITFP7Xk\r\njuKev9aIAnPiWaO2/9iISBZ3Tb8xVHZERBU=\r\n=52nj\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"e607f1e030b13e2a085742aaf06f41afb1b445af","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.238+e607f1e03","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.238_1669056348209_0.8676845773863546","host":"s3://npm-registry-packages"}},"4.0.0-canary.239":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.239","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.239","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"4f02787f046c591d6f43cf0430e6d26807973b27","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.239.tgz","fileCount":51,"integrity":"sha512-WZ01njc76CFKYTFC64btlHPXEDEAZcIownv9oZ0uQO8zZG8jlIWom4wISCb3Bhpp9xru8HpINSczlpgN9eR8Xw==","signatures":[{"sig":"MEYCIQD3z70kiBpEghThrEUwQDWFjMgGJPwsXCoP7hz5/oEupQIhAMM6ccFjHSF+RgxGn9uhzF0zdAS5oToQTv/q+Y/jyWpN","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":254907,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJje8/5ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpyUA/6AplhaWQmxwplKIGowWjaVZlvDAxs3SFdEVcaaZlEE3hVeNvE\r\nYoxahPw4PdBO06tkyaRAwdLKJWNo3qvh7eCQgFSI5Haw+ZPjMKvX6etycos3\r\nM75w2lZKl0oqf5YOb4vH4cNoiA4smJZGJAgYwctVaugV4myaT9xakjxvAbRQ\r\noEuClXwj1nHsuSX7eUwy/tf4hXeR74FQE+mqA4SJpK6SqPn+01FQdMkj8Pq5\r\nCIVC6ql9FOE/y03NpN01CXxRW5k41fVcWk9L67gZK5x70ckyBE/L3TrzhslP\r\nj1QvDYyRr5JmD9eGkrjCNFNpUJxHFLn+6C/3//RbYbuuVAAnOIX9QNFMwas2\r\n8mzDpfByCncE2doC9fjjwnONat1xNaTXxDpMHK3163SRy0qOQp4zbwETLzDK\r\nF8RhSKShG2UFHQCpJHl0KSOcVzifBNljM1WLs4xx4VopVVWqcqYsoh+neNzO\r\nSd8TfBJGyl8MKLr8731O5bKVRB0gcLP0bZD41eNWPsRGvtSpqV8yXSzSfSbU\r\nN/cdgNGpmpLZ6JCUVMVlM1pKLSdLV5KdotwIBFOTOzbyYg1sqxen1/8RfG+D\r\nP64c+45hydlJWJ8eM1zrz7+UZHiXplCdJFyrPJCyco15owbAHU650QBCuVhy\r\nOk1DtIq2LP5OiHB4+Oiq/rwA4XDFAbed4M0=\r\n=kr5f\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"8f9cbd7e1f3a7db5463a1b809ce799a5f8dbcbb3","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.239+8f9cbd7e1","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.239_1669058553668_0.4283657851913356","host":"s3://npm-registry-packages"}},"4.0.0-canary.240":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.240","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.240","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"d7ea1a2e6f5101b1f9961dedf44e8c08b7d47ff2","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.240.tgz","fileCount":51,"integrity":"sha512-3lFIbVvKUZV8rkd1axdWas7b/zV2tq2NMHk+cQRLboesRbGUe8EamTwXo0cyvLB6jZYuNc8F/3nUs1Th6d/bzQ==","signatures":[{"sig":"MEUCIEqw12Ahlyv9BBOZDzozSa6kKuyFv4OFMxkdPlK3mu1sAiEAyBauNJxAyAEsYRXa7Tflk3NK6jiEqKVEu0Ta2+Lhs18=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":254907,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJje/pGACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmow2w//VG7ijo9g6X0ISND2enJSUsWetvqnRK8EivXOP66Y/VEAT+XO\r\nVU9jghmcCvHpkMhi69fqvcR0DsGcJB9XPCj1XvpmUykpWZYTlN+GW58RZY/g\r\nU+SsdwAHjqQirAAn+10MpAYNXpzMagyYEu2wi+1AATN1H2C2QOGjv/xREbcl\r\nA4XWT5h2zfqrk8IG2z/667o9o2S3CScvBf/OB5IkmmpfL3MYXvUFLeZSDDIx\r\nfUXHhs9rcnRsz/d+wP8NYoDBfie7Ue08CUgutxIIejfmL3Ze6jR5QdsNhCtq\r\nALPn7BAtu5mLo/glQjfQmqM1JUU3KWF8r7ZSvt1NaxxALNCEqb2Zl8fdvtMV\r\nTEB+0tj+aOoYRgmHh1WfumdrfeN+YmVHQcQ0g5YpWSWKq5ubDWXmMtfORB8P\r\n9X2kiy9gfN8kPB2hCNZz417qnt3+vx8Wurbi3TfItGuWiUkDdjylysIi1wRo\r\nzGjIt2+9OWFMovAa+A6Y4HXvkVBkv/Pg9lVcaYiqzzy5NIjYlA+rE7XwTk09\r\nDBS/zyOaLFJjXhO/uTW6S7FAMSzzUFDs4Yx/5uK9mmh4A3E3i8AUwazGVOTu\r\nV5tx55QsvkVhvDCQg74oY7QdYCe9BbaOaegPzqW36Afa6JE/uv3myCTQVSLK\r\np+5ZECqn9L8JloBgNOLKQvo5dAFgpe2q8Oc=\r\n=hieT\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"f4533a8c65db36a7a697b2c9c1192823fe4ed04d","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.240+f4533a8c6","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.240_1669069381795_0.70217107751398","host":"s3://npm-registry-packages"}},"4.0.0-canary.241":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.241","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.241","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"258c93756f22978c160e5872c77f4d4684603688","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.241.tgz","fileCount":51,"integrity":"sha512-56HycS5Krzn53y7rRmnJx8d/6JGwSfZoHhhhQRX3HsgUNn/MJlYHJ2U+fuztkpt69PHHzLcQgK2OY9rUL6MKhg==","signatures":[{"sig":"MEUCIQC940LTLVfGNKX3USZGb7q7ub8YS2n9G9JoqNRGK8f+GwIga0sAL4rkiAHXe2HnxA5AAHRc19wicf1SZPlmlBr2EN0=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":254907,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjfAiZACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmpo3w//dqtn9adM98n6xSeyAMH2ZdviVMLp4W8v3ZsfgdFEZvRtZ7DN\r\nwtfNImEAAx/cVp+JORID3pxIMIeUaZUjxuwiNED9TUwnHrhpD1tkmVpvugIA\r\nGmT3pzid1MlHHei1vRl6yPjnsT/NunIIyoGudTsBmqgtKsmiLuKkANfBiO54\r\n88m2vzlx0S12RfqO1bqQQOhFZxnK62rkoXAyCBSA0Xu7X7EExp3TFZ7llBrG\r\n1fJZJFglJ16EoGJ6SAoFcw/fK4AcjS16nHDZLyuAJpwBhu8jAI7WuwH3SxRX\r\n5pGNWFqsT+5pnLZteLVrtkz/XTU2UT8Q+RqBPlMEsFf+76s55gTFBONsjjE/\r\nhXA8vQqOIMu4qaS38zZU3qvG4bU/829j50CKTpNtyk9J6WeUKV8RDEFUIizo\r\nv5psPsAGsM1XuMbefxiiXCz8XnAFCd4FJ52h0csQRMo+uMEtogMy1V7ZnHpJ\r\nWKTDvcq9gGBINUMva3ke7Phpob4mZLKjHZuFXEba98LRv/chIkSPp4lkY6Wy\r\nwUUE6ngEXmhvgO0hF0DsOGyxe0hMAYbBaNcMKGx46ab4Mt2MYYlZmrPn8EyS\r\n4Dv1UdV/84KNf1yslzTQgOHaQFMj7Uj1UMiClD9Tf8g/3w4sbE2/rsNSU+LC\r\nigR5QbuVVcvAu5G1ZiSkpXQ1To8WewuoyIY=\r\n=QvfP\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"7e5d60af9f0fb2fa297503e94cda9f3c02dde944","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.241+7e5d60af9","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.241_1669073049359_0.19623815120758792","host":"s3://npm-registry-packages"}},"4.0.0-canary.242":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.242","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.242","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"8f02e9fc440a2542d5a5b9a2bb83e6be9ec6ab46","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.242.tgz","fileCount":51,"integrity":"sha512-AKd1ZfzEzVytvEOBdGKBYaKb4iSv7+72GlwpX38W5EnirFqserBF150lmy9vjWgtzmCrtfP+auq1W0qS8BlaKA==","signatures":[{"sig":"MEQCIFYPv1Lbwuujh0hJzbV3nKoT5W5ytI769Px4p991qm+1AiBW1eXKCV5oUHmPJ8KDmf9TZjOLtPpHSTCmECvd0IGS6g==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":254907,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjfEyDACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmp1BA/7BHfhbG1uAXfoWcqcaphn62KA4C7VqWeFYw2HTHF4eayu9C5b\r\nlHqdSRyvQ3kUMly6klncIVCxqxbjZVBLlSoSinMh67IdkwjfAuCBXgjXYg3/\r\ndKaEczZCQKbuHya2emawkYSEonQHO8Z901mfunYH9my4pa+SX15Q5TAs2weE\r\nXFCK9AuWXQpH4TTL3Kg99SNZlhETY8C+TqBrxvwTjdQ66iLkLy24OedHtz9u\r\nEsdX2LZ5GymNrNdd1gc93NuMINFTrcnCrnZGZr8YIJqOfHhsGtcWuHmf6yzk\r\nwm9L1JksbYIxW5KKqyMlTd15muAa5a2LoMxn4jOw043hPUvzHJxf05NEylV0\r\nPNKEjkJJYZfDWxdmwdYtwU37ZoEcd1YcZawoV4pksbUdcFxQj+L96grW3JDQ\r\nwlcGBEppDwdEqwHR4W3leFFLY+irJgo9GY8xBVGztH9WfqDulGCaa4xUIkDJ\r\navog0s0TcE37ZkyQcoTirA/h6NcmnAq0Ha1JDBrMms5n26EUQFetL/xzowfu\r\nscD0CFirmXoEWxwg0AV3ZOHbcoPy1PLmPM4F9xz5c+UiCkB7l7NFK0i2oXWu\r\nuhQgGu4jBOjf5/setTRZrv/G3j4bphC0M3rFwRidcIl8ZSDKi2NETnXGza8j\r\no9g6fD8EnsyUNHB23LYtvb0EgXSUPalE8u4=\r\n=ja5R\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"1c440126df57ffd3654f5db75513b19a762f2cb0","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.242+1c440126d","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.242_1669090435606_0.4107126568781392","host":"s3://npm-registry-packages"}},"4.0.0-canary.243":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.243","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.243","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"2e33ced0c2a1904191211e6e9833872921f67d53","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.243.tgz","fileCount":51,"integrity":"sha512-1tlJACpnXhTJvWmYqxwwCSg02AK84xhfOuurQMYRhyRr9t/4h//nQBU9nlC/B/oAiME+jiD5YeO58W0j04096g==","signatures":[{"sig":"MEUCIQCyTGuQmwRaBvO3WvBLqnMDOHXCwiwVRyP/8ZpFPfMPCwIgboE3cEBT2sj/RJzJ1JfWv5oozXvb4Pgwc1hX0MYZLm8=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":254907,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjfIBFACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmrj0Q/6Ay21LMyGMTxZ409cJpoVYI8mVqr+cWnLwk3glW1wA5q7A5p/\r\nMZtul/AKDN0cv8GlWC4IoBQ1vGaz4Pqc3EuctlwcOoPOVDPHzhQykZXfyXOA\r\n7qgsOFG3sOwIA0ZbOIT6Xst6lIkQkoxSraeJPepOxsHLr0T2X7fMzbmRI2qr\r\n00K+F+OsnbItT4QfzJw47uX1SnKzG0C5afVREyTBwzNvobhk2GyYr+d54f+l\r\n0I3rmyVhWuVHCxvJ1u+wS0tp30QZT8MUAcX+djbEYts9+C/adzZmOYvRvJlp\r\ncLa+PdepsViXYkaPu4hf63GeLO/Kx2q8D8skCxJTGmm2Ehg1Rw9y9fC3BZu3\r\nt0paBvDqEe/dmDorSbwihWYFAg7zoGsBLLQlQ2XQPbNNbfvZT6JWgtuT2MlQ\r\nFtxnnp+Wo4WKOvqMq9zhhZzzKwcUpeWiOd2e4Iq2HLJ7RXgPexWuOKU3TQAh\r\nX9mo0qZv2nMmlFVJshv4A/HYRP2Dj6T3Bkm+zg1vl02bQGQpw3QvBEGQ70Qh\r\nfqVhnFXRPH8O6l/tFzgHEhfsVsupyIT+BdVsNXxRpVp6uV4/XsE9xJ4/4Jtm\r\nZDLx5SxEM2aMxujvYWzfZj0bVZEMLlwN7GsJIqPqotF96HLDvrH6Cw2Pdj7H\r\nN6qTs3nhNsyYVOwxEPxnuScRNz8+53Rwz9g=\r\n=oN7X\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"a7b811141b201b544530354f815200e19027863c","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.243+a7b811141","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.243_1669103685534_0.01928878425145597","host":"s3://npm-registry-packages"}},"4.0.0-canary.244":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.244","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.244","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"7a708814e8752d8480f5a531f00ab843b32584e1","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.244.tgz","fileCount":51,"integrity":"sha512-rJxTSl0slYZHiKQsE4A9vLFUJh2VpxH7xEckGYpY0m5FOQhxAf81cfu90RA5UN+EFNQkmCHTIN32Ez+kID618A==","signatures":[{"sig":"MEYCIQDV1V1vf70V9GgcszDgur11SJDzSI2mevzpledFCLfg+wIhAIT5JwRkzhwK299Vfz2zn9ciHKXO8aLcvSanbM9lt4jr","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":254907,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjfsqlACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmr6mQ//QBg8DxOVsXkpJ4IN5sm1FpsubDvF6AV+WiaICWX8trR/SRTr\r\nXN3H92z8aQwY/eA5v/8kVhIJFaoymzSEv5HgkBJJbXOr1+R4sqGcGFC2Ft2u\r\nNhqpl6nBy6dmme/esArE78oBvdfjycRFo2b1+qfB1uDB4RPoKDqxbElc5fo8\r\nh9kcvc80K0b+UJjDYQ/4e4IMmdc5q5wLLpJM2AWR9JIM68Ztiz0l68Fd2lP0\r\nN1K7gY2q3GnK0OXWnqaA2w0g4+SdChYemGB/XN8+RZjLreT8UQFGxie7wxtc\r\nFt8ErdDx0Xc7rV0JLttcjZCQXEuRIiEBEy5Dt5s6yoLtQCsNwPTYIfbCG9aY\r\nBGe6hWzHPVcDXqPJ/g0iLye7+3pfgYeZiVyUb330XdB6ZNplusMRtcMJ+mNm\r\nh7nLxUvjTsaWvO6wLN4sim4ZUaCizVxY8X8hWDBwxA2mlLFvTHbOnwI1qRBH\r\ns5fgvUXgzqcGxkAvrCcCGoslBqASQoyrGXYjuM24yvsbajN+TCBd9K35elVf\r\n9oCi3g2v6lKgg+1FdatPTxpy9EA9wkGG+ailfilNlD2KM+vHhnj9xjm2naXa\r\nAwdp8KZTkzEcP1RqsTmgSI9MhxtUb5AycaKA7vJucCfqCAVJHI2E0SSgcUPJ\r\nSWkLmbOEktnSkMtqb8dCoSMeCq2j2o8VorA=\r\n=thrc\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"9f92a63b8c32b872b2b45fe247cbfb2ff2fcac33","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.244+9f92a63b8","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.244_1669253797046_0.16679555699003878","host":"s3://npm-registry-packages"}},"4.0.0-canary.245":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.245","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.245","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"546bc41800f6fa40ce1e2a295bea95242fe96c7f","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.245.tgz","fileCount":51,"integrity":"sha512-NQJSNUpIb6/syYPXJ95mjiaTzsLt66FRs8ZD0nggYv57H+I7J4e3cbUL1TIuh18ZkOQtsk7h92Jd/LripXxU3g==","signatures":[{"sig":"MEQCIHUxZYf0OxNbgX7H0NS8Wo56TJMGz2YVdmC+lySTeZPBAiBnhYI27u1f7dj/0R9tBN3sxA7tOaLLBlis+/P7/fN4tg==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":254907,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjfssOACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqSZw//UZjVUZkaoiT9SUxZK2mJHAMV2orglIRJGLc7qB05PJtudmN7\r\njzl63Fz8RBmfFQSKSWzExaVDb9pKlT4oyocVs0sadD9nW7T1guBsn90+XXRE\r\nXIrm9uZh6k3bpUd7zE/cypeRGMWUTL7bpx3O84jjBzwGbxHGHddo6LNz321y\r\ndc+SLlbfvHjAQNokqDbmoTGWScb99XfuJeDk+kD76XPvvzYsbSQY6ew43Iyd\r\nbZ00vJawM4O7kVoFWweSipxAA5ASzagbehFWm2gdpKdMKahpYQKLRiANSang\r\nSLozvNYrAFd9qhfs+nR352cHLtL++o7ktLLQiBBTSLi/oMqYfh7kFrfqTBpW\r\ne5wP4EbkbwmXEi8jM7k1DNbAGES8K2UEgx51mZqaeBR9ZZPF8pg7z1VwCwJm\r\nA1hujQi8X0m9Z80IWP9Q9+QbSY16qnIeajcSc8cJdq32CFpsuuZd4EQ0xyod\r\nThg0M7gXNjXHd+LoRpSbuJx/6OpjLVUvOf1rk4idg3zgp21WNBwaA1oQEHap\r\ntvjkPah/TQ+9FmKuD1mkrh7tJQc7QKJ95Tk0Bdj3hmni05IIpnz+IW9SH/fT\r\nK2meRhU/oFkoO+DBb1rl/bUj2MSFKXaARMuvijjK147oD2Xqds9QNCKzCVAW\r\n+qTJFDu8GynsVuGuy53a257beWD/GYQQn7g=\r\n=Raxm\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"0a57f38cc27b9c2acbc31da52485c66b0fd4f445","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.245+0a57f38cc","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.245_1669253901787_0.29145954279362973","host":"s3://npm-registry-packages"}},"4.0.0-canary.247":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.247","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.247","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"369610c1626f97b3275ae25621f5b2f76b3a872d","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.247.tgz","fileCount":51,"integrity":"sha512-fJXpbMoCsCtRQYh4vGZNZlOPCdscru22yjSkEj+RMO2y7MkDPwvh2D/PAs2m4+6Rp3cGy8svEqNatVnKJyu+zQ==","signatures":[{"sig":"MEQCICf0gUWT+YYoHOUpWvF5OlNlSImMau84+74obwpCOMFWAiArdbEXTfM1kczetuCQNgB5qB2BHdVbdMhKkHyuf/EDYw==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":254907,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjftZhACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrUSQ/8Cpc5+eV/sy+4AdhiUEfRKUP637o86Dlr6J/7KY/lI2yx6Hr+\r\nFWxQSNk8YHZqf7UsIHoxfLL8j/xvEtXpjbL4tNVJy5w1ny9vUDiy1nGAhUaa\r\n2dh4MSM5kpgFO5V5zuXulrlxBYX2T/M5a/cl584ntUnMBhPgy2l3ZBfH1d0j\r\nyVKPvP5dvXL7x5qjwuxKuBs5ufYh72EUyZVirHleWnK7e/WIi4sgnhziDIkq\r\nud5+y8HpP3uCiRl7bpNR+LaddIICIV+E72PQ14BPax6Cn9E23IQzt22iQBma\r\n6EjLFL3NujQ3tPsggvHmTOIntVjG/6wwD2jn3vEBGYijIDNj7YoRT+1JLPOd\r\nqP+8yx1cbbjI+U2D6yQR8dRYmZA1vOP7P7madZp8sDW+st5dJ9nxvnADBE3p\r\nRUQtpK0byl1zd1/VVqhUKI9dHhtuG8tKSeYUFYpBPCvqtw4FQBALqhqupf6p\r\nVvVtvsEzcj9lMqTHcVIJCCLLn6XSei+i1Bba7E6P8fnQAeR64X8vYoyQ0S2W\r\n9Htg8Cp5GDy/yVkWMjRY7NtU0qQgAJFJaAHxAh2hxn3GrB+aV5bmymOxrTun\r\nhmKDi/Y1Bpq3iy4G7GQ93MEGjJf/JSbkOelsjpZ0PE8CvUFIvKQfz2SWHpTX\r\nmvZ2HJeJotvvevuNLt0B1QO+sZHzsd0dD5U=\r\n=aRSG\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"72651134ddbfe0e2d56b1cc310156a9ddf49b4e1","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.247+72651134d","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.247_1669256801716_0.4439121103987531","host":"s3://npm-registry-packages"}},"4.0.0-canary.248":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.248","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.248","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"4ff80ac9bf2d88f3cc9d1ecb5b5fd6fc651c04a7","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.248.tgz","fileCount":51,"integrity":"sha512-CPxTqvB8VG8fYZaI7caxWVCZOfYpZ9istguor/kD7y/7huDtNBxG6amJyYdcDKT3JHyRF6bDYs56FYqyRzs8AA==","signatures":[{"sig":"MEUCIBDS6D9KhCU6HwsaI1uGWZ5jQpGM4zKKvWpbi1ZtnOBjAiEA1KlLzX5cZ/iFW9lgnKY7pLitoHu1IwPO/RovBg8XRSE=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":254907,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjfwY/ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrlihAAnPyNUW2P0311Nf6ukK7heyLL8IVcppsueFhkKMokRwAi2Ujb\r\nYM3Qg7NBhR1Pd7hg7TcuW/0lVUFnMn+qojrZ4j/m3Cwfko77vqdEWtIJju2c\r\negPRMThuctiUTzWOtAWwIKLSpL1+jE1pKkItIC1lqxXalZS5DF5+KVRa1evI\r\n16mkBXIgTMdhA4b3qWQgRikq5CARXYtvNo/WRrlnw4SahprtWANGcsdpbZ4M\r\nV7U1u59hJUNohbw+/23aRyzUuPbGm/GP0KITfZF+tk2eY+gQxXFgdvPuxqjn\r\nxTAjPWVDLlqORi2zRx0C3/VqK3LwquQ1XwJtqxvGVtlCLvbXSN7bm1MWxRn0\r\n1ZLtFo45stCJyQ05tBfuMXHFWp+ub+9Cqk8C3WeY8PYqLaDAlYxf6Jl1RUh3\r\ndPxzxjgdH8Zs7IG/xjEzZ2EbyoguoDm9yi5T+HAvdgtRFbvlJxoGIQOhmlVE\r\ndMFCrM22p2tww/YqpqbAVdEnIjWOlSzJCAZ7YTPW1WEu3gry4cYCHQ/xjpmC\r\nSZ4PPy77E0dXqsDKlpOWjEImB9GeSq6995+PeDi/ZFQtqPjM6982CGjezTvm\r\npjOhUZl3pQ+03IkmrKGTDItC5sg8PmHy26b6qmXRn2NXCAjVYNEc1guaOpsO\r\nujrt/IDljtalKY+QriXA6BblTMxwuLhc1v0=\r\n=KSMP\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"c77202d4a133168f6e665a65bfd09bcdd5ab34ab","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.248+c77202d4a","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.248_1669269055274_0.1646335397085743","host":"s3://npm-registry-packages"}},"4.0.0-canary.249":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.249","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.249","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"06429887d6b39a1cc28436bcd8dc9380b9df4f95","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.249.tgz","fileCount":51,"integrity":"sha512-uNB7zUYPbk8GjxbCCT2LFSXmsJBJNi9cmd/KyIVIY9suU1T6KmB1PuECc96VHACL0jrRKAz36iq9cCDwdSiy4A==","signatures":[{"sig":"MEUCIErKslwr+LvndDLKeubZifNr545ltWhoZb8X4fzc3d/pAiEAtamjfDm+ZEejDNuVksJKXrSPt8IxJzJEGrpdxxu61gA=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":254907,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjfxt3ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpFBg//eNNBln23BdnQxEKRG/7IXi9kT/3SE5uIFAjGXlynbkIXPiRm\r\nsSrxWtxUO6/TPzjojU5HZbgXcRHavQO9z63nbHANr/LPetauXtNTt8Xai3Eu\r\ngU/Bpxp9sZsloZU6Z0dYwas93xncWdt0sf3Kj7HPx0wTTpIexx/4i8IFurTP\r\nRCCvaokZUtELxLa1I0QyE2b3Qrxn4LQOl9WL/Dg7YlHpvhh6v5fyllmkwec0\r\nJJzxULLNFBIlAN4dc2YvzYnutR8cW1oESTT2CoJlSSOGkgJEYqm5LneLCeCT\r\nTHeovYZujaJObkfFkXfqeg63n9XCAxVNZ+lU2P8lAwgW+j1hOxNL0F7sQrkK\r\nVi2pqifbVoUWXjhY11uO9abAImpG9v2MYYnQ4iI5bydVfRucVLy7cEQ1L8K2\r\n4e6RN7zsYdqc247hiFzyW28/BGWJxJEyzXCE155o0v3hulBcxurTOHkpU+M9\r\npu1yCDNftoEuzo3cavg6/amlSgcp4mGcKfMY/CTk3OQHS3QAaLrk7W12qsUG\r\n6WasJpjSWtBqgpM0yoqlQJzOJzuxyApGNRo1a27RPm9CNuhi21FAXBDcrANY\r\nJKfZ3ifSrRGH9VouXrzetG8qL1FddL5RNpaH6bpn2dvBvC1WW1tKIHmdZ3Im\r\nqz5GwV0s8WIzPz9SOJz3jRsYmtbKZRs5aGg=\r\n=61WY\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"0e072837d71db5eb3153d2d94638225067061bc8","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.249+0e072837d","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.249_1669274487596_0.43894412424583695","host":"s3://npm-registry-packages"}},"4.0.0-canary.250":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.250","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.250","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"582ffe2d0f4d8dc5afc17d867ec991aca90ee3ad","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.250.tgz","fileCount":51,"integrity":"sha512-ujewVIEczRwjl4MoZEg895D3bseegeWuSkGlqA2+knZTmhGxrYvUW5uDzIz8osiHDqit8l4+ptTJO4+l09JTWw==","signatures":[{"sig":"MEQCIAIM7Gh26zZglipMPPwOz3W7wZQTYF7R5F2es+iUMUEuAiAZ3ONaYmFBwRPHSDjGnKIL+bQwZV6nfxC1LttcLwILSw==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":254907,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjf0umACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmq94BAAj1h6CgfI1aDLNzWKzFq1GmEo+B7pOJ38GZITCXh9iKX2MiaH\r\nUU5kt73m+myYmSPamGSs5EBt+qzVvvjjEdB/rnZ4s6AjoosqjZ2RCEddWSF0\r\nxIhwHdzUH0FMTFDDRUBH+p6VhkoORnyPHkf/j0d5KFcSizrqNHFTaPiWuzr6\r\nD04ULi1hPhThn5fBlebwmfTVrV8qrWmJ2bIz27u1NmqYe+qidYsGqfC5MDOv\r\nXLrXt161YwvLtqEhDn7sP9KAsmjUh6YEub/zVzFh5Bw7TiP4hPYJDpSvngUb\r\n8z/OAbf+1BqHy05u1f0oztdjr3kYSP4MncMeeUWA7j0wCg3AxjRJpG2ZsLgU\r\n+6trpXVcL4bQ/DZtAwCJt4jEFvirP43n0iNzQAJf3WO3V27yYLOn+3z4p6aB\r\nfjYrHCiAVeawm7SoB2ucDLq89UCFnN8J6MsPARi3M/fg3GWeppudrkcZmyMU\r\nq289sR7jYr8aiZOjSXCJKLmAvSyzI9u96TR+KeRue6g7PzlLQkY0qX2giHb1\r\nj+YuLPeX9ezeKB3ctGfk2NOgVcQPsozsbyUDxFEBdF/ea53Vi/THeN4CuE7/\r\nP2OWhh2/Clt866vpS0Tmi3V52Ok6F2VRrkyiNFqqZrhtVHPqTMUMgALYprF/\r\nD++GacIF8oUNJSntfALdjfFQ5JCGq2DX/yI=\r\n=As6G\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"366ff2e65d97bee609f9f24404e56384839dd127","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.250+366ff2e65","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.250_1669286822265_0.25316109801323394","host":"s3://npm-registry-packages"}},"4.0.0-canary.251":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.251","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.251","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"47dc0d4f1994b3b690c8d75f8c2c563b747640a3","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.251.tgz","fileCount":51,"integrity":"sha512-cMkq2dGdO3YA3RzDongWRlg6aWGvYea2mqcA0d9lONJPqH9Un5ODiqJYstJdEyY3D46wZAoolWGmu0qNKnZQ9w==","signatures":[{"sig":"MEYCIQDh2YI4NiQpmGk814/nvXzuf5rM9rVRGCq4HN2UlUe80AIhAKRPf1KL9KqYxhblH2gYhOKtklmTgdgy26tlWwLo6kA5","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":254907,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjf4toACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmo3Tw/5AJUB97UD8gUMrrOvaeObOQedVpHkcJ3N1Bf0TKD/t4iuDkyD\r\nLDTAVgNx1HyGGUgqOhlo08PgWTaZEagNQauTJwfcJO0tltX0+M3s+/JHqtDr\r\nZKHjXY7nrcAEJikA/sNZrZxqTviAa6WsCczQECzBfoZJATMYfDMyMjDd3GPy\r\nOtzRfRLTeGHnqupvevInCKCY69xEJCYAQ37SevvEBLm6zghymCEG2t3FLPmv\r\no1jsBttW28ht//E9dhKTg/v+NJ9KZAdjaVe+CP9Aa1KXr4vPiQHPzfHQSaXs\r\nvgVEDGypePEiH+Pa5TQAyYW0I08NaEptqIb8gpEVVMLRQUv3UGosayBbIPE6\r\npkcUf6P//eYkLlobwDUEAELZImKogrjOwr9KApcpLjnrOLmEMrdrH0ycp/YY\r\nVcd2/81pWgVC3vvbvdrF2yw3WWuN3KDu44e3CoXMigZtARN2EUiY9aqLaX01\r\n7XmQvd6+DpDwqnluF7O2rdCCLUPj3/ia5hBXRZnLdS6Q1DplVZKy/OugPovy\r\nwXmyAkwEEYqBFwwGx7XocDIk+wZ2JiU1p29xjSj+nrpdXsCrQ+pReyuzX/Sy\r\n2sPkGSr0/+K/o1E9mccR2WkG0uW0JiYxVH90zuf3D83odJCIj0iwbWadq+pU\r\nhXIj6QVK3B4obXvTdDqRRArVdwKsOKFAr30=\r\n=y3f6\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"3d8807be033e0bf9106f3a62988686d4b10f98d2","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.251+3d8807be0","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.251_1669303144420_0.7514585866565642","host":"s3://npm-registry-packages"}},"4.0.0-canary.252":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.252","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.252","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"098dfaaca5463b9e8d927196082a6ec8c81dee80","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.252.tgz","fileCount":51,"integrity":"sha512-gSptmWstIgDseylR2yBovpI+Nq+1b/kX+77VE9IIhgqtT6vavCEVeeC5znaNlkl7XDf6XabCeF4fs0I2bZy/kg==","signatures":[{"sig":"MEQCIFQb3DvMv55vQdGdeoSFZGfVOJ+6rd+M60i7Tl87F021AiA8yImHYfsX8FdZBjyd1lq+SKJ4f9YwFn34ThB2AS+P0w==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":254907,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjf5O3ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmpctg/+KOBnGdAXjBaDq0Qkvo7MMv5HaRdOLzvZCN0DafBnGWnjbP9y\r\n4nVSJqyR62DsURGSwgUUQJZOLPSRasfMPHsTQRpWjdwD3IOC+ll61AT10vas\r\nHPX0yvV01dQe/SCc5fx5Se+w07jQuMT/fExAid8qSGnslHt9VyyBpNnyRYQg\r\n+IWS/oLsfY4x/HlVvGVk1G1fufqOa6axAJWYbju71DIxWblLO2JwSrxQ7Js+\r\n4yl3PZilcdgv3Ovv/Y+JghoGH879z5OQCx+Vwp8GTLj6iJil4VPdtWfSSiGh\r\nsn105fjsdVELXlDNyTjCMaAFwdpJIHVpgPZE53SmUkm78t9VN+2/iavYBahC\r\nTl5chO3ukA2ctfaCiA6S6BLCxBuViM9Br9wESPosjq1UDQif7ovc+35RUnls\r\nrh6jvuTM0pbQ6bjlfWW8NfaOygBeDhCAhkzJB/0nImX2BZuhOai160rrN39a\r\nddeUpWhJuyyXm8q5uCjfyySeoX7OnLHHdbm9T3RsJT8TBoxKuqEWKDfMoBqZ\r\niWmvQmh1pkUM8d3bzvJbM1bzxkO5HTsMDDatzoVWSlEnMD31v/KeAfpuX4zH\r\nr2Hl0FiIfFTqgs1FNe640TG8QAdikuC6Mlca8iMtlDp+ztyfHuWbQFovQ+p+\r\nO2g9hAj2ukLC97jxpJ2RpriZ6NN6HhOU15E=\r\n=uV3A\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"afea5cf7fa9e4377a7a865bba797f7ce4bd74371","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.252+afea5cf7f","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.252_1669305271347_0.10343848587547022","host":"s3://npm-registry-packages"}},"4.0.0-canary.253":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.253","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.253","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"35477720fa8c6cbc501c6fbd94524c45a579cf70","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.253.tgz","fileCount":51,"integrity":"sha512-FCNsN7ExecvQ5OU5che9WR1DyoMEQsusQhrxZ4D0zzyDVHlMH/Hn7114R7GTfJ7YsZjeBwIqPniR7hTgZCzDyQ==","signatures":[{"sig":"MEUCIBWQm0SuGmmyiVD9vI+24BdC0FU1My7w5WCtvQrB6lLbAiEApQw8He0bvJaGB0IQ1PPdYZHrutTTrxJvC0mWYBgLT/A=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":254907,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjf5ZPACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmopRw/5ABone60+bxNjljLclBvCB/91Si3BVBXfUOm/ZLnMn+EKoSeH\r\n6cyRt3lOLd6KTcvLlCzHAYbkGcg7/Kyrv2Eeu3Ei8Ph8X+DBmUa0oUkmt3JS\r\nRT05VxZ2frwjkpH7oIt6/xdRIOk+uhd0GD2wsthR1f5ARrTdKzXbZ3po/z/6\r\nfkCcSHbVCUgP7pinuSZ/0aPG51xt3nqdzMvELvHyIDkih+GOpEyIlS7UqKsH\r\n/KrHTHRasKEy+2Sbp7VFZL1fhgT/7yjKFBXQNcVKzlPkKNW/ugCed2Kxvvbc\r\nsvZaYBoAIaKMuktI/07M0Cnf9EXT8WwA1i03RMHIo91XKZUqPIta+R407epq\r\n3JEm+a7MBU9hGfBNj1/wHwtkq7xuS8mjNml+8TfksTyPE+IoipvgWJvoezgK\r\nVQGG3S3pqOe1k7q2+agyPaNrIWp7XOSEFWPLCD8JMgQE+SDflsUHWlezH8QD\r\nmFdl6udhZYeFlLtgO5S1yesVkVU8zXkU+ygrNsoU5++CJZ3JevoosWxJm1oD\r\nopFlUfro2sgQDuxZ7jNPEUy611qttraX7N6uWyze3NRR5zr1lKroD42M8xC1\r\nttKZzzvp/ffGXMN4ANP8ZeF5mBcD0epdRKemuGBpOTf0JneeLLVREfOv8jbb\r\nZ+h1JDoCOB7ygcT8xjClUVPu+du2qulrM2w=\r\n=CO3Z\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"6543352b7162b7f18228aecf17495d2c96d24e09","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.253+6543352b7","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.253_1669305935541_0.22070990135668267","host":"s3://npm-registry-packages"}},"4.0.0-canary.256":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.256","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.256","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"0244140073d51cb17a22e1979e68f9b84eaa803f","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.256.tgz","fileCount":51,"integrity":"sha512-czBb3ophDthTQ9DnojX47nT9lEuha47LFoQQhqt9OTfrVeBXe9eZNW/GP6Ol5EdY2OlwngHyO73IlSWC17/R+g==","signatures":[{"sig":"MEYCIQDaLSLebRDiubWh3b/QAcFzIbdCqZaS+1CtjUYhfRNv+wIhAM10z9q6/VmdnevZ7xW40pL3Fv/oaIDZ2fPBzd5Y37In","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":254907,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjf7CCACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrgGQ//T5eyDGiNFIxZ7QOUHSlkXGYcEl1Y1pxayaDv3cO1B8K9l+2R\r\nw7X2sO5+PDbED04CF640Rs2oSnf92wauUxx4DsgxsYL/ULWJDMTUgRZw4+Nk\r\ny0Bb+Zd9d2MexQCy8kjVJRCTQ76MHIbQ100f6lfPiqVotQVywOS7D1meWIm6\r\nlytTYqM02RVOxgND6E8walAeta2XdQtCqONpQVZKwaaWOcCUU7Gb43oZvLW1\r\nJLRTnRxnH/q4BTFniRdhM1K7FJWEHP2AOB0NwUg1mFRIAsQrHqZAOuzqhNa5\r\npiMQq5V5vE0sCs86BY2XCA7+GnYodEAcbORSDSdHGS12asqOuv9YrA/aI7xU\r\ngElj8nRx9Ij8BW4agxNtykxZtlST1wfwH13xNG5iOmYn8mo+Hg6AunV7ype6\r\nEWZ3qwz2rMxZ/KvL9tpaCQ3t6szhDH4JXT09O9j3aUgLroX1vRMHLhhuEDay\r\nSV7nKdgk/TdWVm+eze1mar+0iQn3gwYxuxvhw261DzTDNDv+0ZTiWL66jUxO\r\nwj5oJJ/sYxEsVIC7nwTIRfdJeCIbo9fk2zrPjbYHGEf9suX9h/Pwy8nmq6qQ\r\nu7nuZNJWQZ03yH/Rd4wGPvERIq2mjlHPsarSRc5YeZXUtuGMEU1ux5I8guQj\r\nUe/3ROkNFvvzaI3X/EHD7BLtouOtJJ3UvDs=\r\n=KFuK\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"42d9754e5c4686422f9bf85676084cc5cee8752a","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.256+42d9754e5","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.256_1669312642498_0.2590350404662116","host":"s3://npm-registry-packages"}},"4.0.0-canary.257":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.257","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.257","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"bd53e3d51c4373b4f6747b1f7e617a34281aad96","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.257.tgz","fileCount":51,"integrity":"sha512-pbm4cp5/J2ggn/msUoqvdfk0ud/L9quZ6J2yauW0wLSYemvr6OlyIZ7xMOzinnZ3bhy71CJJODGcwb0lXbO59w==","signatures":[{"sig":"MEUCIBKJh4BRm8YySMXAfDw7MNCgM6FC83+8yiOqFqp4fbB9AiEAmiUT3glDN7q3xn9apgt814uxisM8uIzLhOKGYm1mMhI=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":254907,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjf97OACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrNNg/9GhXZ6FZDXCbkxJkjfOyCuvpM8PBeXmzybljJQf5WO6RGZAVQ\r\nPuvTvJPNNKCJ3GVmGCj4EGcO9YmzOYHHSR6R9ri5xlfeo6ZX6z/q61LNanCR\r\nNZ30E/nfOhge3hfAl27ahhNCAyG0rQOohywDc6/yjTKjcT6oFLVz5lRtcigu\r\nGrDMjVSuW5gfUsrIZOl0vEt1UbdJzq3LXOh4qFHpBCpELJpsBTuZ7AtSfo4I\r\nFHrshxVBimNbTbI5Mr/0/tkxSMUcWQH0u6BKud7izpWIjppm7rNwEpac4iQG\r\noSbxaFAetNtWRFdUVEOoRB3TYrGptpN76iZRxuIKStN09O5dXJkl6Tzac34R\r\nvizj2x6s97Eiuox4D1S3NWm7Nbz9twqOCbE4QsRvmESaAJcbEQGGgBB7pTnh\r\noj6d4lrpbw31V4oJ6gPDtpvt+PYm72zzpKimg3yZd17/FP9/9n+bKrRjdJGd\r\nxILTX+LWOTvW3evsfg6/wQiyMsGHFJEoiWzWKO9lvHEHwQzHkFtGFcEFskbK\r\nWE9WRzkaPOa34gEsApeL6+/ymzTe7hj8MB7FAYkSWd0QOBp0N8msb5c9ussd\r\nX9o/bjUWYoYzAZRzfioTOwF4YBMJbE9OblY1iUy5YbR/jQV+BqAsZCKghxlu\r\nlAJcBF5eoDSUAM1UPjAuzMWsj8bwnMm7+Ao=\r\n=bIv8\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"d20729b709d800fa472c60915e95fe5b862977f6","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.257+d20729b70","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.257_1669324494275_0.7366931806714949","host":"s3://npm-registry-packages"}},"4.0.0-canary.258":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.258","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.258","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"376bb0381eecf3351d89b8ebd65f28b4d7f8a82e","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.258.tgz","fileCount":51,"integrity":"sha512-eXycuwG+6tjmVCUBZ+jh7T5ktYBKOSxqHPZDTC5ETa7pTW2dDpBJMBDNrD4lnvzHRFW6Yqf30BEJGkkWY7WfiQ==","signatures":[{"sig":"MEYCIQCNKzoLLH0E753HfsrNWLE5N1QJBOJ2vhVaf7axWvPjXgIhAIgdK3h8orW+BWMzhAju7sSaOn9NPXEnp0cBjoTSUqod","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":254907,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjgVZGACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrpVA/+Ky6SoiBtxzgtsbjaV451g84XosjDlnd0XYqBUSd31NhWCJOq\r\nsaplrExRhqDIqmHQP1Ee66Vs3WtzVJX5wtaSDY1DGI8iTUtrEn47ukrDM64R\r\nTKrnRXNl9vspv559kI/3eUn+xFCuFi8NnksGBnkoc0fQeIBCvxiS3PA7xAK2\r\nLjYjkHwUWDiLnkU93DmzkzV+SynwBvpJiV3lrpXra1kXwL4BybeYMOtBeIs+\r\n7z/iTfpHv3cxad7E6OlvFkNRRS2hZKGZ+HCexcbavBnGnFLG3ebIkCUOMZUo\r\nsHpUzrwfYlP0GdQVYJgeVTrDA+O+XP7KDw3PDU/qk0fKY7ZWHTVATRTJzSaj\r\nnN0gyGiMXoplNCA7zf1fe3LD6Ebi/XxqbPMiU7clC8iyUQ2+rxysuWCOOiES\r\nckPsryVTCxmC5uFBtjD9qRngoVuUpcC8IxRV/nAqGFjaNdhOvNl3MnutPK7g\r\nks3HQ5yL3glhds8/6bo3kteMvudVlGH8h/oTfHoMWcRQxXSsMdyg7zeBa/Kl\r\no8tbpWMD4DOeCDmFXJzm6o5uzzCdkmJpI28LUt+XTUyLO2Kh43DR5n8CLJ17\r\nEC4yYunp+eQGPlZ4YajjvC329k8R+Osjm6pzdK6aGyvqyJl+L1VGjq8+AX8X\r\n5JJzpScGrzs2PjHJba9Qe+XPtnAqR1K0YfM=\r\n=IMgC\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"35737636a871f6e77db725907f335136cb1c6f06","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.258+35737636a","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.258_1669420613851_0.8491592848003378","host":"s3://npm-registry-packages"}},"4.0.0-canary.260":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.260","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.260","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"fd22a957873c535754c220be9d547d4ad8def31f","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.260.tgz","fileCount":51,"integrity":"sha512-fZYHyfPlqt+LJUoMpEnvHYY/RzEh2BCqEoFFN5rRxLy0SeTYAJMFxOFQrU2HMCfacFFfGGod6sLILv6/71TZ+A==","signatures":[{"sig":"MEUCICglPI6RKENxXMDQqz3yVujHX4FlwnBCgHLuGnHlNYyiAiEAm8B0Wud+WyNeXxikel5zHYTCkGn32hw92uo7Q2oe330=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":254907,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjhM/1ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmo3Sg//eTpXhLd/UZIWX/8zo/hk+8BgzP+eB+Ufsm5qLSRKjjcnxeZN\r\nqRxZFZDG0kZDAfSlxlv9IR2K4DiOF8fJ2eJPQEvu4sVXZ4hSMKXR93azB0rB\r\n7BVWQdXTyUjfkYvil3jIE13e15ERm2Iuy5gO1L3snVIFDn/IE4tp12i+VDos\r\n98RiBICkrt22uxjYxs9b2fSHaZSrGHrTI88S3kLj57LWuc+NqnTrJZvIleTp\r\nxtUJ8jQWNVYCOnKzSs04e4ZA5WcOH44i2uVXIIHWYlC/z4j75LdWFXeUKTbe\r\nWx8pGlewK6s2y2mzExuvm0EKcBCSQwX3449B6yonHTiOpHp/lbcKiXTlsujY\r\nTtnKUKC6qKqHdp4Yy4gYh3oxtgIz6zV6OJ/noXV8t646cTpyyZvAaQxTEifU\r\ngxA1CpLRBg2w1FSec3brNmggDejiOe43vDpKDoefPAgXHf2Maf49IRjrtR/o\r\nIOld9CNUdbKGgcJEYCTg5f+rUJ7t6tRBdeeQisCTqIDLUrU1KibFdKk3DXqa\r\na/H2hQxAbBfIr6HL13cqLAjCmp6NqVW7sYk4y54yOD4+BxluwT2mcqYRmYrs\r\n0pT6cs3Dfw77+0j9AEiaGB4olDVRMY6JWJv9RNms6W4T8HXuGx5sDKGIlEzE\r\nxjsZB9raCDbigzFddyseybLmlMwmofvzqcU=\r\n=6MeY\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"0eb5ad7237016b855d4031020fe4f7917ba150cb","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.260+0eb5ad723","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.260_1669648373073_0.7564144495036267","host":"s3://npm-registry-packages"}},"4.0.0-canary.261":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.261","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.261","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"8165e0e60a9819457760f0d6f83951aaf14db3b3","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.261.tgz","fileCount":51,"integrity":"sha512-/KD8EZLBOj23B1XLEr7hQE2D0zN5GQMuED38I8F0/Quozjp6n6+UYDT8g8/yNn6S2aVGcf2eKLj6mbiuwPeqEA==","signatures":[{"sig":"MEUCIQDpNKfV5ujXaGjmOcxXFLYg/hFLHvJkU2lHDiuxl/3HMgIgY2TbWRKa/zmxD3UARF2UT6zRY1jWFGsOYGqYd1es9nk=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":254907,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjhOrdACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqCQw/7B5cgsgamV7HHyIt9fy8/9n8mkg9kyOPkvEFz/DMJbeZanMuY\r\neyjwcq1y2Lmv5cds5P44wp5UnCYAWtfYwCzeu/Fjczb2NdKIaLpKwW0d973+\r\n2ZCKsIWuFESJG9Ppp/JPbUbV5PSk6Ev27Z6U56MBbdQgne55D3W8tobUMbcw\r\nPlQjeohCYbZwoHf+GxCzV4Ds1ibQua5zW+Yc9zb7dpG3tzd5TmB2OdPs2HF+\r\nD6nXyf/64cpNpGZ4cZNAPhDVV8THkFSAF+Flod1uDBWhX+ZyKVkyFt8r4NpR\r\ncq1wjeR1xzT/+lJ0tJWNzyfMYPIdyfqHVR1tMLD5yiGSXJEMhPb5r0z4FBzO\r\nKX5NbzUgcdKAlyrT78RGtbP0HxdugytigAgeRpD1tjHqFQTxZ1TNU6HjI0I8\r\naxNhk7QmLpOj8Fjsso6L5gTWEnkr/8K2db84tKjPTs241witHFyDYmubpBEh\r\nGJS7yMigTL4gwkHa3fDtCnGgKxmHhvu4GOjPOy7U761Ntl36KsDVWXqcqci1\r\ndWfWgMYXk8WoVd4MUzScfH6BnmHyfYxCl0IXK0jpRLTzV0nnHWvJXf9iOBUG\r\nw4aVjE9mq8c0XNGaYLsqjj0kMAIfRVVVQRhkU4O0PPHY23Cu6OywWzc2eQCp\r\nG0ugtvM535BYUZxsQjNhVE9Bgfkp1D+EFrE=\r\n=hFtG\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"4d5cbdf745d7cff4ee6adc9fb70ea8811983b879","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.261+4d5cbdf74","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.261_1669655260955_0.5011759788362422","host":"s3://npm-registry-packages"}},"4.0.0-canary.262":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.262","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.262","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"d0e9e9279cbbbd5f247b4ecf390604b501bf4c8c","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.262.tgz","fileCount":51,"integrity":"sha512-smjh61R6e2ctAIJ+iOmNX2EuLtzPbIcJ3t3OWTfm3r+VtJnzOMzp+3qSUgnaRsY4iGzC5r/JszxIJGZP/7Uh4Q==","signatures":[{"sig":"MEUCICAvAQ2HNwadLkm95FYS/gXh7JeWiCS/tfzFi1ViKUWEAiEA9cmZJErpQ9BloxF0FCtB84XiL47idYAL6tzyvpLZQPU=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":254907,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjhQPnACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmp79w/+LebPQbj/H1ZKxk/r9Fw1fj71tueLOmwvEjeHe/jZzWzIuPZ3\r\nod1yDGGI9HN16nA+D+g1hnF4maxPnFWi3EEXqr+xbjmhm/LQLfC8bqn38VDl\r\n3fksTjH/HE0vF22g95/0QgASsNurO7hZBLKHccWbX35OCEOEy/toFsoAJB+D\r\npgfHZasJuRUoIm/ziRXwSeZ/S1KHiNHXcRz8LslpukJ7RGuNce8tXYrO1w5M\r\n8/IPoF/6bPJSChjrPFN8JIUpgIeyaq2yypa3S5nRlBkYGfzmue9piLyehT7v\r\nO1RHrPcWB6CEz8v1ItJklVMdVn0e45gPHRBOh1xnpMJ7pU6ztUPLgsgebDY1\r\nJuEcIMU+foWb+5vCDAoglyAnePy94U4LFYli7mxxyy3UR/2bQm9nRA7JPopR\r\nxH8owDVZWg+RMPE4v72bLY5Nq9KJf49a78s7Mi9DqXv7VihVbqCy51CAdMU0\r\nmXOquOXgOFqhvFZrWxH+4BheBqcUfDkImj/JUqWScDL6JUeF8wOvr9K3G0V/\r\nQ34xKpKE3WPHlyb5lNcR6V2cSwuNPGHp7fS4YTYpKArG18JQTCM9eEQBnj5n\r\nPeaUHf4ebJolwEflWpkaep4c+Hst48F9iTySurZ6BMog2HApbPCRGLmoEG7Y\r\nubs4aUdCT6b2CQt9b7c2ok3HGXh04Z6LKOE=\r\n=YEE0\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"37ddc9d3a293daef2ac6ee4e62b692336908c50c","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.262+37ddc9d3a","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.262_1669661670828_0.15420580109920135","host":"s3://npm-registry-packages"}},"4.0.0-canary.264":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.264","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.264","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"d297d3d5af65ceb48290215033a03eaed3aeb08f","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.264.tgz","fileCount":51,"integrity":"sha512-7aobMmohkEtS324uki1czoKuvT+Xst1BS9Cv+sVf9iI55zv2Z3AiyEYvu2pVriJATHh0J4lbh4qbBescVdhE4g==","signatures":[{"sig":"MEUCIQCVDYJ4k1fW67z+VW2mOzEITgXMCGH5oSyJ1ahcJe/GpwIgepRaKOXR4mLg5eo940fXq4BZBP1epWarUmn1rVQG3CQ=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":254907,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjhRaaACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmpgxw/8Ci7FgNkj/ZP5MA2jtXkLaeSSHwWNklWancchlxwCdRNX0Zfo\r\nAUNrtX5Oo/icPvp01K6z6q7bpYA5fqd9+Zl8Oh/ZY3NxCwbdVoPUi9QJT16f\r\nZNORFO21X8hQNpi80TFcn14nfZ+XOj2qaEz4AF+C+j3jWOUSbb2JcNvUI0ga\r\nf1t+adtSjTUD+WzP42aDQefIQkCcN+vQK5vyhIu0o+uc008+rMlq0V+aG0wF\r\nJxicvdSMvPLllXHwGdmt/8AyRioGoqJV8XbTFGgrG3e0hWHTjws9DTaOmyn7\r\niOpdGtD6LAEY/trJr9Xor7fyESaiJsETvqGfToERvQDoiumzIx6ESxtRWTHq\r\nhfQ87OautisYcxJCX6XDe5rsuWNf8omVmVyXFXBS0scqaVjrvulPLn1EhSDL\r\natNt+bdXFV+e/R5lJRDb9zgmS7c1gwc59pwks8L5ooh/rsmxajq8dqu0vrcQ\r\nKlZb7fvLo+mmTOpFe24H4pQIxFpH9HprNpvMwPbVP5fSUGggLXm9k8JMPpZZ\r\ncXQpOj8SqTXuJRoQnb+yW8Om42ezk5XWJIsBWg8LNEuPQFpDaz4CM11Zj0vO\r\nEvKMDg/3ife5r3GcNPc+dMOZ8eg2I0VZfJ6v1PtF3lz+wtnBK3S/V+8tzlnO\r\nzypAOqIcM+b2VY8l1ZVvKflDMXYw9PjrwdA=\r\n=+2ML\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"286dfe0dc88763f9e5a1c78f22f4ff8dcd20886b","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.264+286dfe0dc","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.264_1669666458353_0.7337074529286771","host":"s3://npm-registry-packages"}},"4.0.0-canary.265":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.265","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.265","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"d561efcce6ce4239c6f543f4c825babd0c49bc5e","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.265.tgz","fileCount":51,"integrity":"sha512-rwPuXKoYYWGpYV6PHQIqZt9U6fr2thwBvGdxZS9dNuWt4vR8gZX9mvWk8Y/5uY8HBk1lkVPvI9yCI9LOsH1Hbg==","signatures":[{"sig":"MEUCIQCONxvgBMgakI0YtFqkCT4qZHN5u0bpSbUUK3tallP3XAIgaFpd1h5xkfkHjIbKufeyt6QOUUaJIbla5tbacAc6RjA=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":254907,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjhShQACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmr0+RAAoW810iVurPadLFz/ZvbOqGsB887xSaQh1dhN436J8Jimnm62\r\nyK6S5qu7tKWl+w//KbcrjNJb7x5mSPm0Ifu6LOjs0HGXnRzp0MYNUr0uMH8T\r\nBBeK+Yc99+qh/weh1UTFeldB4V/uEmTSzK3okfV6vlciP7wce1cCeOZ7tvVV\r\nLOL9BwS7PX753vjvc5sUvd1/lBE10yRkv1VthjlOt+FPt8ye1aN/MU7LY/Fj\r\nOJ9nXnCC4NA32eRimMO5/Aa3VNfr9LyJcpQxMXrgl3k+p/g994foKyLv4BrV\r\nNeOBIIJ+HQDmRmNUBb3yc6YEDngwgYIbdZ4/VR6bKQg9O7p3MDlR7vly9Bji\r\nFHr2aohAPVHS9B79SUcGA2J0T9jOjDQdUhKIQ6xiaJl3QRXiMgS+IctxuzhU\r\n2OQRCT/dX6zbhkqX2Ik8HmGcPRVk3eljPe/PPbONfUiCYFRyUaGu7dAl5uF1\r\nL31bNvXhffGmviAjU87+0z0x2aDtht+zGrvEPVMOZ64nyVexS6IE3kvCFFFr\r\nsQWHMpDEFGHKM73D1TsXMBBAKUeS3T2Aa7havghxdsgi703kO1+USp6FkvBR\r\nHePw1YCopmtybhwyN7GWYPCarggGjpJtdPd8v8M9YuBbwpFCLcQBYnNYOf/A\r\n6KAv1sO9xPGyQ32XLNM8ok12mgOvPonwI1g=\r\n=PFUh\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"c3634393c1f054ed4d7102de5cacceb13cbb953d","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.265+c3634393c","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.265_1669670992577_0.061653838362061064","host":"s3://npm-registry-packages"}},"4.0.0-canary.266":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.266","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.266","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"5afedcc6a6f865d15b6a434f7dbbdfdb42b133c6","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.266.tgz","fileCount":51,"integrity":"sha512-3MNq1uEWuUG8qxCnYKmm4URq6HR8XP2vGtxiOftPnU9TQuapauFJDvmc2flfEMOESAcvCp+WG4sy5WEKs0AgBA==","signatures":[{"sig":"MEQCIB/TR16P+rqKWUNODeDznejh1eyLsyLv35sW/+3pUpxkAiBG7HYSaOJ2zqmi2nCMrDpIMOAmCkWQXUd/p2IHsKi71g==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":254907,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjhTIiACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmqp+w/+J3cS04PuNuv8jOZ6DEmjhRnotAtx+cEo0JnLJYr8X24FgyFe\r\nAWOcSoSj4x0iR0ruFgDLIddsFKWUwRnEpg5VJlnpm8KVVI0vHGKzJtANF/r/\r\n59AqHKS7OGVXB8Po7zWFTgiWotzTe9Pr6yFft/1bU3EazQVjoXQKQOx/Tucn\r\n0ry3bKec2NkDnPEpUlpu12zUjh8pJcsU6Exj/Zbp6/zZP5ViF2Nla8VjZyaX\r\nLi4A9Rwjagl/V1NgAvs9ETonR+fvNHxPwLH/y57vtt1qoU8W/k7UAO9AgLGg\r\nkIhYPKJ0+jsBy53PnVBc2MnHpy2Dm0d4aCKnqEUO/63hptcTHtrbq+vk/Fx5\r\ni1dF1QGr8aLHOFrjrvEgQTeG0QTnE42AoyefCJ9UbFXH8r2HtIkWqOcPG49Y\r\n6nXXwWb0TLhTR1N1ZLPVW0/3KhVZ04ZGeVWMOLSEQj8lujhxUqwq/Scf7V7L\r\nPm2SBX2neTvQn2zHFiW3Ld6Q8S7elJOKrH29gSqfenD5enYll3I+jt94rHJd\r\nrywn6QrIi/n3MkR5S6gusYvNAd/LD6U7W5aAuxe4W+otMs4fTbqXLskoej9M\r\nn5OYKfK6XeOEUuuKwzD14D3oFBP5BDK8VtD1+9cLpd3PwoyrR1dvybKKUrDN\r\nik8T7GSvMR9zRy8qbet7eLoud0hwDQIyeMQ=\r\n=uGdo\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"56cd2495f92780c39c68b52d1a330874c12b3a5e","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.266+56cd2495f","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.266_1669673506594_0.2694035087792228","host":"s3://npm-registry-packages"}},"4.0.0-canary.267":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.267","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.267","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"81125394984dd49886b59e1f5dfa657c16f6fbcf","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.267.tgz","fileCount":51,"integrity":"sha512-jNl69fMo3nV46BU+xXZirTsGeT0gZKdE8o3KNrW5SpDi6L2kyKI6nn/X0gJeT5DQBiDeH6CF4DFgPkaNLfoLwQ==","signatures":[{"sig":"MEYCIQDnPFLxCc4Ys8WZH4mFj34MyykUweD0Jb95EStV9GEuHAIhAM6+iqHR+sHW0uu00UdRwogg1BHXtE0GWw5SozWukh+B","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":254907,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjhTJyACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqLcA/9HdYP9D6bUO/S9TSYc59n0S8utMhxzL2uoJ2YwhONgIA+FeL5\r\nVKnOCPLhypF2VAWZxv75Cj0Nt8P1g4H4Ia2SNtCdRNuemQoDJtyXSl5qEFbY\r\nzz5F7Mdc6h7jGNKqCR0a+BJCIMOXNhN844hrCPLiDAHxjVYmbAqpk2X5ZYQD\r\nNktAfeCH7QvhKtLIHOYIDietcB85qNflSUuJX64l8wXecmmGgwmDBZvOnn5m\r\niLrmO9PLDaZrrbK+5A+H7goFvAyYZ9lScuxHSFyFmjITnuyYw2oCFUgQxrQy\r\na7ZKpGtzpvZ2jJpK3J64DBXPM12VYc+sscFtu0KhB9h0x0Lnfbf1kPS+4AJe\r\nEqgD/WjWZvbXG1TMxz0kzBcsghW7ktnTcTksdDbHsVFI6CECh+BEg2zkflb3\r\n+47Hf390vyAP79M0k5jcZHbPYO1WUVu9BgWvb9MGTEHr+ftzh2oWGvbGM6uF\r\n8rk8mQ5FQRT4VYQ78YGHXlGoMkxIkhK9KJXddyAFizQKtbsGO70hcb3n1Osg\r\nIK+2bN+Qv8C5GtT0A3DmXRfg1FdleKHzcSl4AuQr/OaRbDA1nuJO0xatkQZ9\r\nYHmn43Q1XywuhlfZJJlr8ycjsjx0srlGhrFnf4EeVzTkHw+qMqWGIzpXTRal\r\nIBNq488Gm8tmtJN6eBRsEH6F1NOoghLJ/rc=\r\n=RVlO\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"82eb282fc07d1d6a8d0c7136f17b680a0c6d5597","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.267+82eb282fc","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.267_1669673586197_0.0176234348603983","host":"s3://npm-registry-packages"}},"4.0.0-canary.268":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.268","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.268","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"3e5601f729cabcc012841d9992d5a414a2d4ca8a","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.268.tgz","fileCount":51,"integrity":"sha512-R15WnvryYh+jzt7InMiK8zE4ymexpp6DHMJQTDWrf1Ryo61fOyPbcj/QN5xrZ23p16WG2JxFcS6DOSoX/SQ6rQ==","signatures":[{"sig":"MEUCIFnE3EwIk9zCC2UxpE9tdoUSu1s/lrHqLpn4DD98KUK1AiEA82rGTbDPe1BClwy/3d8MXxOu0UFlk/WnR4vF6LiDSyg=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":254907,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjhTKPACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmofUA/+Ki1CezKYT+qw4g2orI5YRbySMw/MucwXqRssJGPwpM2QZ05U\r\n5D8K+QzazZu8AoFfHOCMJSSUCuWRuaq3dUqhUUgL5dNBVS1Ul689dOJLlGLZ\r\nkhzOeD0gfd7s8FGCGAotejV7OxDkuTf8+1ppEnDr6eCYejBV7jIMmNahntuh\r\nr65YuBJj9uHbD/ximKzwz17+8dFW93+ppKwwA461VgCoy/bbq6AZiPpewstM\r\nGTBbPNRVGVf9hY6pqhdFPAe4Ku4GyvU/RSwK06suH+nW8ED3SeZebgTTeSUe\r\nkkyzT6GcG0tdmhluTwPIvX4+5FRhyfbHU7R6QUD8Cul3JY98jWVxis3K4q6K\r\noziFjU+7lQauGuK91CXuGE9E//vwwEODBzT2/5QqPURSNRWQggGhmX3G8A4z\r\nLDrR1twNYAMLelag1zWvN7RFaxAp5PFeBjw0WM+CUa5lqcLO30rIYk8BatrM\r\nuipIDjXpFJeuAqcOh8MgtDfTx5e/tv3aUwyRfQtFoyDpM1z7imQvY9ZJ+pmX\r\n1JPS7uMXvELDTpPHInJZmgHbC/PREjBRSJom2UnZzG3o/jX/VwSIcG7PYr1y\r\nX/elZsK2RO6CeiIXwhScd6a3srd2D5TFjqzIEe3GVbBtQludM5/pf0wiovgy\r\nhBiwLkKvXESxhxNzgdZZSkgDoYMPxTn8p+4=\r\n=A1NT\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"83176fca7b13fa78063d1e05b3bad4dfb48c6d99","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.268+83176fca7","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.268_1669673615711_0.727561134589447","host":"s3://npm-registry-packages"}},"4.0.0-canary.269":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.269","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.269","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"752b4c0f08f326696dd9230c72a2e0c75671556f","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.269.tgz","fileCount":51,"integrity":"sha512-S6qNqVGg1bCxNJdAx2u/C8VMIrtpZqfIxMIaLXVU28lgq/hlimK6pWv6r2bxYosj1CxugssZ1qMoA0jr3ZpznA==","signatures":[{"sig":"MEUCIQC4YnOBPNbwsf4g2JcsR95w4W8H1MI2UHeZBMZZNT2GpwIgZPpgGRLHlXmbJSFPZhu8BR/tCu8vwdEzfMkRDVRTdtE=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":254907,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjhTKnACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmq6+w/+L8DpTAaII3doSOq8Ut0dyypeUIZCnrWxZCCzJTSTGgaWwO5e\r\nVUOz56r1DSHdZlYWaC5ywkk1CmTEwLRbCxj4foeoofIZbbDfCd+XnJ+e93uX\r\n1nX+SaXBq9m6THh7qFZqvOH1WdyR1xmT3S+TG7+36+KKM+lXNO3gjQjgNvjT\r\nmdWdvHfcPv0ivaKJ7g/ELDgHa3vablAZC42ObVXDiCMbBV2D/kikcm+fMVnU\r\nfPk/PmcCBPNERadXz+oTXCnEJPqW+MVrepbFgC+HpLVYse0Ubj+a8duQX25n\r\nDaab6umArhcTKJtOLfDM0xmZ9abP43CG+lQwnh+UUdkijtWEa/se4NHAdVPM\r\nKtvMdxOtRbmdyfR7zUsj5bCn+iLa9SqIqB3KfAPzrYvzCMTjuF01EPkzhVHh\r\nU+ZyRTlvZ5afNssCRXC3WcCCHlJUIiQuD6lFKSLD1kfh6H3VMM9qvWFOmzyl\r\n8CoPUwqvbcKVfKJaNc7fExHnHOjhhSKWA4oMHAR6b4fmOuBtZCg7qOj23ZlO\r\nnevWEVsTlxJmaLkymYUHlrG1NXMuWTCloArb8cnSfu6bu6+OZmwFIKVJO5bJ\r\nUICT45gZKpShliFRg9uKXjGjBpD4OSRIuK/xD7Iv2UFw7UgeHUAFtoo0blMf\r\no/39LEy4QSGgwXQJ8kpQlvz3ix2Tf8SF5oE=\r\n=5i1d\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"ad419b957f73558b0692d8ed0902f62343f9bb48","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.269+ad419b957","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.269_1669673639529_0.5196960464189504","host":"s3://npm-registry-packages"}},"4.0.0-canary.278":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.278","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.278","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"0d907c7de2c85808b9f1e9b174286677e657c57e","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.278.tgz","fileCount":42,"integrity":"sha512-STZ16h+Gr0XHM4gNDjq56pnhRSRSWLwX/NCufTcyfhWuQf7eGBzrGtC+IWQa3tiQuRFyhvBnyumplF7y1WtWkg==","signatures":[{"sig":"MEUCIQCoCykGWpMGhvULNbTdEcANaGfKo7I5FjvCYG/xebxEAwIgQHAtg6regSE9CGHyyWDREIubAdAqUHQkWThwfgADVyk=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":211679,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjh6ytACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmpk9RAAjTSP+wLZ/buHAiWmmuXSe/7vaSGWSeRNpCDLAyjjxl0XxVKv\r\neZK7Us7vcAQmxFSPTs18iQ9PxN9/IvYwUbb0M+xbbyXXEE/cLUoiZ5jDjGHd\r\nobUvNygihE4ASWeW+toxk/RhivylQjmpYnjraxyXQoB2mq89lTuMGTD35gfe\r\nI8cUpwD8LWA+PvJod+rsp/93HM7KmlR0tsOb9hXZerxxLEoh8Pxc0rORKE4t\r\nJ7/prYrnUWby5WhYc9qum5Pucx6MHvxgMnn7zifnw1SVQN/G+/1d3dF8caME\r\nNGT6ebc8+XRypuvHIwLrntwG2xDma6uz30249L0BDUMsomqmlstFXqbJ7Jpf\r\nwEi2JClb2o+ZptkwcqugW7jzKvOV3j4NsIzOcQgR9+mSb5niNebdilk2sHb0\r\n4xjJZMuer9mc+FEWVKtaSijTYJgsnNyp9dAinOHm5/dcUr8z317wItO3IYzv\r\nTg3ihUe027UKWGlyWSrMR5tY2Jomt40T7j2IL4+LG2cOqEphLH+MJE0m6p/Z\r\njqB3m4RmvcprtmbBNc1Ff0yE3lJiI/y+Stqur8Sf/rJe1dLS2aSjjAyl50sT\r\nWq9HJsigqZp21whfJcPl/u59TcLa8O2SU2GS6lB6bdtpklBd9kmBXBvQEmDB\r\n6kckNVfdTUhy7uooei34GEvToZkpleUIE/4=\r\n=3ecV\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"f25125a4cb3dfca64c69bfd297d4594d33b32a77","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.278+f25125a4c","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.278_1669835948837_0.9729980260470819","host":"s3://npm-registry-packages"}},"4.0.0-canary.279":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.279","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.279","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"da832c01715682d414f131f1f0953d7ce995e2c4","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.279.tgz","fileCount":42,"integrity":"sha512-wtRfH7RXMe991EIuMBZDQ+i6VtpcyN0yJGTzfmXcJH6OWMp3n60+eNHdPhGKUOnCfDSyyPfYRz6Xhl0mvBlKig==","signatures":[{"sig":"MEQCIBUsUxqIKbQhF3nX1RDcgeEjjugAUvcImusXfYDoQJfsAiBLjpQjiRyGmOmjM/z7GLLe19756wwPhVUNdzzgnA69MA==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":211679,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjh9HSACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmryqg/9Edlo5ddxGtSCE3hSWr/a1dShnm5hg7R1Yi0QvuYpGSlIC+zW\r\n4S13I3fQZnUAkINufmYwZ1f/mhRjKlAUySpaAAx8cBldHOBGQEhI9CYKQv8e\r\nxLIUPnWT7T84oxjYxG6j5RpDN9JizxaSLEmNXcX3HTsJGdpa6nlteiIaxd3E\r\n8adIiKAJf0nu2B5tNxpdw1uXQACR6kreqaah2V7AD1Sx7llyjyXCwaZsoSww\r\nrrb+Ik6OvRuk//XU2E0EBBqbxgnmPOA5bcJrW/MKggLgUCevfOC8i4fQNPzf\r\n9rEkrNpwDF60+90q5uxPEp9R9ovIrkr/dTZV6+hvn/UI3QSc0lyJg76UnQ55\r\ny+0BXTnNyIJ7aZh4RrSI/yFweXhpZTagO5/3kR4OWx5DKiG3QEzIPoPnPGOV\r\nz1O9T0Xy21Ro+1vDpTxuog89Zrub5u/Tj/QZzZu0onLcV8uV/vVIG1fxFAgO\r\nmaS8ZTVOKoqf+48FYRKTx/rvpuhOLZGUKCwYGjcY36cg3DvoEKoBfAPLmQ6e\r\n/W4sn/o8BxT0iBWvdcd1OBIQgFLJX1Brsdx38zOqMpOTOBfknJ03Vet+9w+j\r\nptbBPI2WdyHlY8ceZnttLce1W1aJAcoJhWcOT+2jdB7ge0T5zxqDNPu+LXf/\r\n5kdL3L3fkxRFqg7Xs6ytR2ZOPHZxFigMHCA=\r\n=tGIY\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"e0cfed48e0d35046a93ace47d8c2f2c5c01a5764","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.279+e0cfed48e","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.279_1669845458010_0.13224005462113442","host":"s3://npm-registry-packages"}},"4.0.0-canary.280":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.280","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.280","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"98284265c7bc625904ed67694be6cf7fc5317066","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.280.tgz","fileCount":42,"integrity":"sha512-EJOIDoAcYwVIi0XNDaMIAbr8hF46ICMu4VF9wDMU6tczPpoARZEKuPjt+Qm4HZL2N0T5Zb9Z7WdXcmi+rm5Dkg==","signatures":[{"sig":"MEQCIE6bzxMkzm66fnedNy65tmmF8EJQZB8yPRczXHQxS8AzAiA0GUN4pLqy1IrDJzJZpz5dliu3TnMiFu+zCcly2ABDdA==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":211679,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjh+otACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqR2A//Zt3W+CnuQ3lfALW4whntvsN/MzBLqahQmJDt66FJrMrAx5W2\r\ncnfVJS889alOv2XeJrT5KVjNVTIcutuxpzerPAISB4A/3PRGZvz0U2CewupT\r\noyIaLSr1oYBtVuWeKk5axQopKE5llIPhJcgUWzSG9ENYQZc6mGq3P/pZ+l9b\r\nKHSxHzwynWlqDw0wGzJVLzJUp+Yi0qEAn1ttcN63wbV+DxRNiZhzbn4ZCQJy\r\nVWv8dyLY0c0iP1BAC8+K8sMqWAgsqU5Y5akEmt+aZGU6bGuWfd3ryLjgsVgb\r\nhSMt+WJuiY3kb2W4WxvHEO9Bsn9woEgG+NpM1a4Dn717undGBNKc+M/Ttctz\r\nzs9AZ+BXhAyuUpTpGbMly6BQIhRAIlE9csftJArBFeVakDv3taxajAxMPAQ3\r\nB5t/WqOPkOdV91YUJsJWXbsPXUawfz7xooWR5Vj4gH74lJKhhqhaGHRIKeBX\r\nkAhiCbpqzCd39mWAJzjjjrR0UWpiAkbWMCDRJfZX7iSHNE647NsYCZA2GpTM\r\nJu3FrIWAuxYBMnCGfh/HJGyWv8y+F0uvHntd5OKfvZLOKa72F02Jb0IcE4Ju\r\nMxDnEpVGwTRCUnMpSPCSveF17OuffsPAp30YCPgCaz4ZsyRwgu3DV+qp5Cdo\r\ngd6Gh7/ACM2/nW6bZsA3fkgdcG6XNzUQFH8=\r\n=+Dlx\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"99c86332709f1b20c5dd7b9a5e5091a4dcdfd001","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.280+99c863327","@clerk/clerk-react":"3.5.1","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.280_1669851693232_0.9700688005317495","host":"s3://npm-registry-packages"}},"4.0.0-canary.299":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.299","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.299","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"ec20fe2e390e58fe6c92bcde8f2316128fd46a20","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.299.tgz","fileCount":22,"integrity":"sha512-jMCcmVwQld6IjXQoa/5f+vQh1LH4FH1Fx9l6V/m9D2eaVsFEwlNlXUQLxAscGff5q45/DABudFdevF/QvUKgsQ==","signatures":[{"sig":"MEUCIQCF/FLEoeprUoavh68NYW6rx4wcB0yeQw1294Hp6eTRUwIgGo5ykw3IvbnK7y+4QJQhJtsQlrxeShrxdUiv3UJMRDk=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157060,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjjuMoACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoC2Q//Z3K/TSL0dKUyxFUrUtl9UqkoTy2wao5wkTWe9mWk7pODqvbu\r\nmNDCtutw7lAMAjYFFOf9SvoN5DEmPACKbMFGs0LGY0YlsAaPKN8lh1JzI9QG\r\n2WrrTyTpJ7GXQRpQE5B8shdoLN+P6m5GdVxYW62+cM1Du3BsOXtiRMwOTv6P\r\ncwk9ijq1xXqU3fL6tvho9C8MHPPx4CVoNS7vyz6uBFYClgEY6kHf3qlbDxq+\r\n/PyQTRXj2lxYLrVsfvYoa0E6oYWqszAgzwzgJ0XaIpXYfL3YXV/NL1887cks\r\nT0HyXjLLdJ0JkmuHTfyJPkvdlVUqZWwexKemCacs5LvR7UV9G4SduEeCoXcM\r\nI6qpaZmwe1yOGKgfjoWtrBO4/teRDFoM9alra7FZNDO7w/yNpqXYhLLt3f73\r\nqFSQitBl9OIKFtlFhV2sdFCPotzKonGkKw7+Tuf+WI5mpmeVRaI2IknohBAq\r\niYcVDDiF87uP4X/3HtH3z3Ul2w3RJNsPx8tC7G0T0dxezV6w7qi2IRYAANOn\r\nWRutFCAlmPnnUQoBF6zGVOJoT3jvfgHhru53muFCSaQ10bMwumIj7NLIDMLY\r\nDJ7nuCDDyU1oPaEap8gHT0ecgQAfULnLM7hMD+kXePpzSIuaffcR9Zt/vQKX\r\nmPXcYypE5SyVXhdKBzABRs4oRrdokAhdKUk=\r\n=WdKd\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"bcaef0236b840bbe90d17b03a5ef5e394c0bc538","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.50","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.299+bcaef0236","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.299_1670308648735_0.9915598993656158","host":"s3://npm-registry-packages"}},"4.0.0-canary.301":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.301","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.301","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"ec58e60221cff611e78d8d1544f1b912595932ab","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.301.tgz","fileCount":22,"integrity":"sha512-P3Jn1wpFSWwzu00IFV7kZZKhW6EwFHaKTzcZkLaw1kOzxgYFFQ5FrvpCZ1Sze+2nwbl1fyXvWi08j5rvff1Ccg==","signatures":[{"sig":"MEQCIChpEhHrE+R9IidhfOsPWMMZDPxP7YdqBJFKlX3D6S1dAiALoGDa0JRdPYg5UTkrkQ3Vx2rPWgraG+0Nc/ATnUD0yQ==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157060,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjjylBACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmqueg//cL0HKwHx+RX7cPaq1osMDfyArnSMRTlXOa+ZcuECBodB5PTU\r\nMUAcOXG8gmB44vuNzrwj1T4NKL/OI7mCqG0B3s+Kl6836xXqzUItVQgBHgf+\r\nvIuLZ9woJgD8ikEl0qJH76MfUbS6UNQ6TgpfbBeFvOy8pd2UFtPzusvFRGav\r\n2pDo6HBX6DQzWIL0j7hF+mk/pKodgdWUqob3M5dbTaRD3xX+IXhq3Mgpggwo\r\nwTdvzEG5L7C4rihpDsDL649Hp+6zHu7KFKjN5RHo50GTuwNVjqN8m5cZ9ehs\r\nAK7vsSbLJH6/mrv/xzYpEemBI9uqHc7ysvFVqsA+6N+jXI+1VeF7UKp+jAYD\r\n/ZJrqg2Rt+HvpDBS/P7ByM3fietFaDquDHms1PScZVf6CG5iIs26C0Z9QyQV\r\na/E1c6QuSfeUMRHiz+qgXhOvIWgY/jeCiYFZZ9riqxuPyhE6X0yrXCnzu8ag\r\nd7EmlgWiPBecKixAv44h2viYkrA5oQqsWfhzXf3eUi9o3zoaSI45rt6Mc48B\r\nJLaHTyHiiyEQTW9VRsViPARrYeQcdWIeTkSKzMDsRg0svsQzq5VaRYqL0hVq\r\nem2i3Jdzi5mUrX6YMg/Vq89+FTmCfhExGBxVlQHJnKx+My65/WkIvQFM8WLB\r\nukxz9Wmi55E8H3cYwUG0NGQ+SZ7KZmfP0rU=\r\n=kOmL\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"e817d97e7040dbd7e928f4974cbabb0bae2ecef6","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.50","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.301+e817d97e7","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.301_1670326593226_0.6060301736486378","host":"s3://npm-registry-packages"}},"4.0.0-canary.302":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.302","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.302","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"1786473e6dbe08a8feb86fc14a2c9e0bcfe6cf53","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.302.tgz","fileCount":22,"integrity":"sha512-P101EK028t1x6yOaRgFUrrQ+15SRjzo8gSqFa/TWzCrNcwUIAApBtScRI8nP8CwSYwz4LHJrOKf78KGzuf0NQg==","signatures":[{"sig":"MEQCIF4qVSQcPrRYMWGM1uViZ1yYdaHi83xq/SbE9ORH290pAiBqkOy/I5CQX5LMfM3Rf16VMmcBmnfXbe04DHU3jwVk8A==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157060,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjj2zFACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrZag/+PJqQF5KmdBrrxqUYvN9iHzc0JO0ZYbIoituWgnwysUPXd6Qx\r\n8Uymq70VU6m4S+ZC4fdHmLRB7R0N2egRpYv73SmnCQcxj3E6rx2lMBN2nq+U\r\nFLW6n7n92KS8KdWV0qfWlHvt+oEx9zkWLbRvECzF46oraYXfmWMz+jZREWGW\r\nckSwjtl1F0R5Mx9ztJLjQZjXPvO8E/yXNp5s7BtkEGVHyGso2/fjZ6bY5ZjQ\r\neNW97G0zRyQXY8XGINJIDl94EpNhdSyL3wrnr6nbVDf66YKBd+gKh1FUqky2\r\n5kcq8PwdfA8nj8gAp5b94JKGYAtWGZUiC41swDH0dhpRcaMX0D0GFm0Kjh/L\r\njnZ+qC2NdEgJ6k2kM9tan52Mo6K1wOLTJxWJDwXfwyFpy9/N0VHmx7K86zCi\r\nSu/xRJ2LbuRCkrXPtrgQ9lklPaF6SfCZU23CWQm0CkrdColILhkR8pJnS3gG\r\nX5eOc15nNjvezEjgy/1V+VWlO7apGcidPGrn++GDPO70L//jJfKl2yeuxnws\r\n+1jWUxHbiDCb0er4hd9qXhedDcjVBm/p3EgT4ctPj7HDybgPxJn2kC5MnM30\r\n4oUcUf6X6MOP9tk89O0FxM/RQdHHywahBus/pSxEHU/r0xq1ZCycTHc15jol\r\ngjPaw4BXthtAsQJ29Whi6st9tO/JxBdo6L4=\r\n=/gE0\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"02ef934d25127d542332a4c4d6b65f31ca052a1d","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.50","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.302+02ef934d2","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.302_1670343877133_0.6233530089495201","host":"s3://npm-registry-packages"}},"4.0.0-canary.304":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.304","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.304","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"2c55feb9e10009302796af8f1fa98c7c7828016c","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.304.tgz","fileCount":22,"integrity":"sha512-PcuffLiEFr8cgv3oAyNaP219sVjz36eN3T3xSmQva3lohUYkE2kJFLR+1Tmu7nbWxTIgfGXsG7mk2ltQLJu9UQ==","signatures":[{"sig":"MEQCIGvMLnUZl0QhH+zEKquEYZ2YlTy+OEqy/NdI4Y0cW2GoAiANJsI617qzdELH3mTThns21Oh+4TJASuO+ueo/bEt/wg==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157060,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjj4nFACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrV0xAAjjYL4ayDGm28xM37ZT3OhPMC5z5F/PWOpAg2cg/OvL+/caMY\r\nA0KteEfQt39uiYsLG15wx+NJ8AbgqU4Cvihybfh+9XL0Ve/GGUdKBhJ8jtlT\r\nOQCuKzbsg6HWxSpxm4yBtjQdetymlKaNpNGE+r5RKsRPhRFTrXxUPpi0raDp\r\njbeoVHFZlG/J27cPdmhjWvvVy0qW3+AhGkvxxejHjdgItYQlFoFOYNa+93VI\r\nW3gkJy6OOO7l1YyTs4H25MIm3r2vnnQ5EBRsQ+bVyMuoiWbLXzttvQilsdWw\r\nffphU0cKUzP/7GBAB6HmjpYJDByoCi+gEIP0BOsIv7seKU7rDDUsyEsR5Wmr\r\nSsLFdLieL0wyArNks17aEgmjEkD0YaDKIECHI4ZVDlPB0GjqfJw8GHJkmfYb\r\naomEBq3hrZSXEntrnt67ITPVh7QUR0ddU39daaftebFlowrJ6rwTnv7u0FYb\r\n1Or04rBjFLzHFCSWJbc8WczNJ5HCM6XOCQ7vHTQIxd4o01zbj3Nu5Dug5Rvi\r\nDz0fxPve8VdMcjyMqBPZqZpxyVra/7iGpVSDEupwBahNFEpt1y0TaWXODNEn\r\n2xUORpFV7d1+BqRNLbN5KTdxQp3huGfisQhQLbx/9F2utJuqyg3J/0gWBsQw\r\nFnY6ehyUhwVWuTnRLQ2euS4/KVWIYSkI8Xg=\r\n=B9Zp\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"a897cdf2c9bea1918e604be576e7288598bfc93f","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.50","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.304+a897cdf2c","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.304_1670351301038_0.5517668130356828","host":"s3://npm-registry-packages"}},"4.0.0-canary.306":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.306","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.306","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"6a0c759d5b25ad9958c8f9444a5662d6ee34d0b5","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.306.tgz","fileCount":22,"integrity":"sha512-VFxZKdmyfxt0CL0GfN6td+z3QtevV7fu3pvmMftPHylOKaJwxsK3BSU5I7s9jUMrN3oO54H2LtWnd+Cr3TAIcw==","signatures":[{"sig":"MEUCIEgqVdxfzZSlmGhCzhtYlOjyctmqV8fRkwST3SldsvaHAiEAoFNzPM1Av6cEnYdDrMjnimzr5LNZFU+Q31G9MB9Crm0=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157060,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkCsYACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoeEQ/9H944TJJkso7mIFvfiEixPkNnqyL21ODllxnYeuY+Wib42GbW\r\nIWbzC0CbW3PTFuq72Ia5BWlw/B5cglQbzXQ04gT4HzSTSzu+4ID7x4bmcVzD\r\nHScSNbWY8SDliFpzg6+BW6nVkixREm6LrJu2QkgE/FkZkdrJbofBu2d183Ds\r\nbvqz0JJAb/W85hJKtaOkq1Aisvfqd+lcJOUSKJkECQk+jKDeO/pDhv9/g5l5\r\nSRT6A7AYGbVGSsLZ3LMHjZ1riry0b0yuYsHg/VRc1w/UghfTx71tLBzIq4Hb\r\nexkHTci7tak0YBXjkjrD6LJn6l9fHcESpnlmMaA5o6GLCtJdxOprWjVaAMLu\r\nhlmXRiQZGxBwF7Xi5PpNv8JmwpFDGHS8aeGFBZZ2kZYeeIdlJhXaV4jmrF42\r\nMst9YpwOXFegOwfkg7hyK7/eiUC1JIIKVL3Olu8oN6ENdCaUQBIfAbA8Dv4T\r\nGMCyOKLwD0QyNdnErz6lHOm71SFVSBmyhcMCYiIOGtQ0eMP1wP+kk4THbBa5\r\nRLDulDChhJNAE0G6jnWAWLSYS1UURxGAoF1su2Mh6mDgAh4sxnZwcbcw0v2W\r\nlpS8dXMO7BachhKfMw1FZmttTtLMRWi95HQG63r8WXj2yannf+fk+Q7izQY9\r\nTp2WVUcDj4TZIlBiS+u1WAyHu/XAvL9Onho=\r\n=VNgL\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"8dce180c0eee6b5e2847da8951d684dfa3a234f9","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.50","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.306+8dce180c0","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.306_1670392600598_0.3068013072477074","host":"s3://npm-registry-packages"}},"4.0.0-canary.307":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.307","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.307","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"19dd35d5a89d23315cd56bc59b300f9e87c275d9","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.307.tgz","fileCount":22,"integrity":"sha512-edzqdKirb8djsP5o1Gb9HeMl2w+89AXISeSs8R/JFKw33115jGQZ2Y9zR18pF2J0UQFRjjlSUaj6eteEXK5O3A==","signatures":[{"sig":"MEUCIAJbYcfzdMSjw8pYf21bTgpOO7A5/oFF26YC8+z8eOPlAiEArlh4VRpbb1biOb9zw2veMDmZIeTRL2BnkPobS6fcXTw=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157060,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkDimACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoAtxAAkGhuf7vAfnZ5XMPFKmm3jeiqsVh1NuG6r/3Qz2WpQ8ldd8x/\r\n/EJrxK2SRggaPqLRBwavxJHseBF2220Zh9vHRvzBltccYJ5FbvrA1qc3l5il\r\nsR/JCtUNcLQA9oyWx3K74A+wxX4jBp80ZUJotL0U72fHnRJOEap6PziT3S9+\r\nVX0l3h+gyh59Z/S+zTQ6aTGmu9remL6TjWIX3E4hSek88hSw57IsnpP5ATxR\r\n1ChyYlKB0F/NYWvPFGRROD3oYme/f9g38G65Zp7VZri/PIxoUH1+cnRnut3H\r\nD/WBiOhIBc5CoxugkhbI60cbOiqoLO1RoY6YOBKOcSt40ohBLJXwrhPC/VnE\r\n3NjNCn+Ik7zF3lcw4630Znvwwq5QHR12SIYbmn6yHazTMdUGqrAIjU8FAPWf\r\nMgfE7zzglctxIAx43WTG9NsC3O1ympg5NDtLtrV2hkTKVMSC3jURb2/IMlQY\r\nstR4DSSUPx21H6Ncs/keaknlpDOmtPcce0Al6CJp7yQV6ZPBbndvH2TS16sT\r\nDEFFdEkVhmsm7obKRn5HVcuvL4UFHnXuSnGzHdmyA94I7hO3EkTjDzwBx/2t\r\nzJgCmeCKH6xniOOxXMwMLm+61AjxsoVTP47PoNa3fo2jB4X2ylBeUX0AOc+Z\r\nemejvY+UTj62JoO0yy0bNEPyf6cLXCABak4=\r\n=JCeM\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"aa2f6786324c3cfbaff5667c5f5d1ffa03b63e9a","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.50","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.307+aa2f67863","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.307_1670396070721_0.9454199861473338","host":"s3://npm-registry-packages"}},"4.0.0-canary.308":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.308","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.308","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"17a452e561a66de229800ec5a9495054b71a0191","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.308.tgz","fileCount":22,"integrity":"sha512-+RGQv3YU9YzoQ9Kc6Phl8PQTR0SjmrDKcTVPHCeoS0Nq43sPBD7QeSQdCw3bAEzPvoFYVm5SGyVNvxMRGhGgRg==","signatures":[{"sig":"MEUCIQCczidcN2M4dJDNi/lMq5q/LOhWIWzuvhFnnGt3/28Y/AIgXugCb6GgUwGAexqqjdUx6gKCUkeoQOC7jn1Sxvs4sC8=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157060,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkGULACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrAfg//fb+epBK3v3BUtUAKVfQGuzpPvw44YcKCbDVLYbxMDdHdQuKs\r\ncEacrMiJprz0yte9+D/VnueHknOV4IpWgqv+vdEmgNpMh3uJXrnuWqIxVVmG\r\nOkUWJaRooiMm2I2b8/fNfiRkV05xwBERkTzh3V4+75hBf9xFcKrnoqyWhw1f\r\n5Ins2nPZjsu6ANnQQJ8cZ9n5XevUjZ1NuA7Zd+yIjZ1DivjT846Z9OySXzwk\r\n/nSNxeQ7bs7C0Xit3ULfWhN8OBE6wKzYKFJQVxb3q05++mHX7LZPSxHvzUif\r\nOOXvXwsR7sYEaaZv8xTnsFPIK9VGI63qKMuCcyCInJVMw1lP4im5IUdvL0YD\r\nwz7S6Kue1I4F+m9k3riPSi94ovLYZJC7q97zX2dY8KiTdFKIKxnWp1W8ydHs\r\nt6QjflLUS3fw1i81K8e0tgHP4dRUcVy2xp/JAg3dhjit/hEGoYGQPvccvmqy\r\n//TpKgF0Gt8yOH88jIFPn577ACu00xHIlZ3BxTmobj9hLV9PDfSkttrR4PCm\r\npPZGryS4WJ8cPUyR7zfhWGmjVpEB9JqfVK13nl/uWcrZJk28wnibk7VXrYs6\r\nF9rHQEKHq3zLC0pN/7Xd87KkSBOvbLOuhGeqbikzRlVZhcwt97IxtB7LrWLt\r\nYgts3wgYn8eGtCugyW9+zQE+7pM3Pt7U9ys=\r\n=T2fb\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"b7aa70a1948a57e42c83511399c64eef82a0ff62","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.50","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.308+b7aa70a19","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.308_1670407435236_0.21963297354663402","host":"s3://npm-registry-packages"}},"4.0.0-canary.309":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.309","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.309","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"94b79744630a7609f87dd9729aa1ef0ef7af28af","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.309.tgz","fileCount":22,"integrity":"sha512-ECOdR5cYnkgCPHL+xJTBYpcLk6jM4eQ0JY/OKhGxJF2dOCv/jHY/FeGiGU/D8bp4reYL+uK03VFn5u8F0/2Jzg==","signatures":[{"sig":"MEYCIQDZ9eWxY4k1++gsSfHd96VdC6fs91s9CFSBZ2Om+uRNEgIhANZKUeHK6cBwJVN71tu2dGLIXSAe0/vRqXLcBQxr7jPn","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157060,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkJ8wACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqlFRAAi5jjOgWSUR84qsLpOjt/99lbWpBLqTMG6X/yIV7uCVnfZm2i\r\nVCF/ojqzSLkF4Z4fkCpqMrP8/IRyAa1PwfSQAfsSLc3zSXhLKRX+cnQ6dcki\r\nlj+2VFx7DZSiBHl2gXc8CwEXmBMyH2KcOZbDDnDRsNDAVnIO9U0aJK88PRJx\r\nDc0q+wI00rdbPUyOwS23NPLvUTAkeKL9FZCZkYZ/sKTLruOTUDa5l+UFAW/O\r\ns/gkVuXGYwuYNy8lVRPqL+/mUuSL8UypZk5zTr7RfPwkXAWDhKu59TCyNm3L\r\n+bMERtDbgNYwNbbHCwgqZ+dxh3bPReJufGC8nqmAIpt/Jzt/yPVTXkvJxe8S\r\ntsiDojD1NSbuhwvTOQIV/eO+R0NOOwHI0xnhN0rxvUjEerKvrNDIxihNWRFs\r\np3zBasnuRG2oH9ARKN9X9+TS6XCjzGqHb9HTL76OgmL7T3jdh884k2MBvSxW\r\nHFXutDi/mBZh0g1bfOyn46vCrA8mNJ1JuQ9EbGxSDPLsWSyrIbiWhggSShoR\r\nTNscpgRPzGgt0w5RnjBnpNFJv/C3oRPaUM2e0rwrOga1pHv7MVb1C1WpPmjj\r\nQb/Z6csYG5aWbanauZVXuC7XYyLnU2pCyYWJgV9b67ojdy25hCSt3dFIWEhq\r\nP1eG8okJfAwUXrPT6XD7Qjxx2Az01kiegtw=\r\n=TA93\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"ea5e9bc23ce5d4f8f5c1d68774adaba20b899aee","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.50","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.309+ea5e9bc23","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.309_1670422320570_0.021690950929839303","host":"s3://npm-registry-packages"}},"4.0.0-canary.310":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.310","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.310","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"e0de4a3546095e318720f0402db53fa9b9f8ffdc","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.310.tgz","fileCount":22,"integrity":"sha512-NikRNwJMEEJRfo7hhUM1s6OAo1xmHFjOhv7RUT5sHIjDvUOyUhXuhKQ2WE1l4TahAx+aYLq64EVpSCOz5U1eqA==","signatures":[{"sig":"MEYCIQCz3aDXfQRRqDJS2lIgiy3/NRg57wNUN2p3bhM6H3zKrgIhAPXDqsma0i9i9Q/NjtmnnA1YWv7f3xg7dWhHYKRbkUZ5","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157060,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkOs0ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqZGg/8DzEtSnI9rTtytV1BLLNGUzL4gpTrJMhGGBreiPUj6PYZ4thz\r\n7qvDXJL0MWFVApEzkVUwqKtgp30XJfxkOCgTImTqaVBNk4N3ol0W9T5HUFkw\r\niNd4BRy3Jl+Iy5LNAr2YW7NGUAnDVTzvb7Kjmuu9QEtvkVuGf2xxgA5vRCHE\r\nvCju+1oQfL+BQFQjfor7YMP1SOP/UrKQrgljsAtS6+26UZ3AXiXWrVvPBFJW\r\nF5efPIJAKBqZXytcBqgYu8VU9HJT5623q4szhXVxZTDfXAA2JzpL9+2IiSpb\r\nlMqR6Yy4Ehrxxia6O+1DUYY6lIFIr80STDX9NQ8a1YeGRjyB/WvIwQCp4xel\r\nXAtq8I5wEnlgZ6iGPbTXiP8Uvm7dlaYSM2Lnb+ppG/YqqllSmlJPPNBdQoN1\r\nW00vCPnKs/QHoP2Vmw7fiyIvWuIlkxDXx4iXjldlxIR8xwKxMXHzS7VxmE9D\r\nriGiI9ObzvR5hbfk8DCy7l6rm/MH04uCKaxrx2TZr0QXMYr44mR9M5wEd5tU\r\nIL6iuVarX4IBEE112DJL/CdIbU5DB+nOv0FDLXEGj2Cuqh6Fc6sf0i9Aeq9b\r\nHwucQxpbMHjKlXCceR2h0YjhQR8JmnaUFfbJJk65tpnnwkeEJX4t4/vXs486\r\nnJQIx85sO2v2xItnkWySEk0vYFamW2lvWmY=\r\n=JKCH\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"c273a476ac687d8cd1bd71d90c377893330a8f74","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.50","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.310+c273a476a","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.310_1670441779923_0.29415254270815194","host":"s3://npm-registry-packages"}},"4.0.0-canary.311":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.311","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.311","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"c61a8ebe03c8ed85dda8bf798c2814e0e4e35c1d","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.311.tgz","fileCount":22,"integrity":"sha512-YvOlJQiQ60rwcRZVB43riz/4iFHzMLrrRo9swHCYRYXWS6C64ev/BQd8PdrDCG5BA/GcDhMiCGEfv+7hJ4MRyg==","signatures":[{"sig":"MEUCIFQ6aNJspuD+6iTOKoxcco424HK9ET4pr+vKNJGJYe81AiEAseHIDxUlJA75VrfYsrhlCcOUBq/zy5K7fH2xqmELdUM=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157060,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkO9iACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqUkw//av6HvAKIDFmNBXrehjYfknRJyi56ShQSvoVXbBfautONfDlc\r\nGkAazmHHAVtQ/yh4Py44/A02k3KTDvVLDXlBYiK1lYK5VEySQqbIQs/I/Tid\r\nWAf+UckyPkMtwdUkNpm5aUW8nj5izSNxR4BypjcTNVQM6oIf8UqyIm7v/0t0\r\nTXN0I7+JyQlptU0FA6koe6XxYUd30JroEgVYrehwbVJd1DuZSDbbhCI9cA2Q\r\nOaQYUwMWSqsIaTdZQX+C/6s5O6b8asHNJRnEFvmZBLdiVVxh6EYEckP67wdJ\r\nJma6Oi62fGAqeQfCvML/cc1+vqNDJrONg42Ra90SMPaB8UyvBX9XH4NnWID+\r\nFrLKQpW0MGKqtl4CyhbbkF3nA+EBV+SYwUBIL04N97QASTJc9QT4AdUn84H3\r\nrjR25Aib6S7PnbBCKDZG0RKObXqNnjW1A+XaqG8uecuvqy0LvO+dxLduzklK\r\nM3MTxtW5X/hTmaF6EooQ4/LcvFwQI2DD+x+k7GVByzJ3lERTxYH/VxGz+mtj\r\nc4d59N52WsRJp+vj8VDaGKOif9iDosPff3dYAqKT2ST2urkU5F6UQPJCxMGo\r\nTui6DEjSy6wEVNkZz7OViuBGEfvgSpF3onbnjS7n8ZlptImE0LF2o2MuVjeF\r\nBNPmq7D0pvGx3ODNlFGV+cfoP5orHlAmWrk=\r\n=RaoR\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"b61d5c4b388ed33e9853e07b119f081dddf690ff","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.50","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.311+b61d5c4b3","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.311_1670442850400_0.7968028760030574","host":"s3://npm-registry-packages"}},"4.0.0-canary.312":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.312","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.312","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"d185b3401fd0a1285a9a41d60080ee3596c17ed5","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.312.tgz","fileCount":22,"integrity":"sha512-M+tyHqeGF+OiNZLGFHnjAGQ2kUQYYrBotKavgYPhrSFcypcM2ZJOAFoDFOramOGX17Q9RKv+NEVZAPjR9o7ejQ==","signatures":[{"sig":"MEUCIQCFmDC/1XBelE6LCmYBCnbUOZn0yVACbVOoIkZrhx5QPwIgEnTDytZiPkrjaulEW1l4mYEG/pqmJh2tPLkDJvwTQVw=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157060,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkPCNACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqDSQ/+Lw/xjJjkNYCUNs7tjWCR4ez1uP7Y7m2U5KtqrO0hTYbF15ym\r\nVpWO4812tccht+MgxZhEntU2ZkB3UkP1pyKDhWdZl377iqjOlzv8Dd1OGHoY\r\nbcMeW178Qd6ER6919swKi9KDxGuD3hLA5s4oBsMDF7J8q7fmrtZoMF1YZR8b\r\nxqvCRRftvLmv6kTWkz1tqOMpiQKdHdYayZKGmyKWJXRyGWX+LLYrUpGcs0+n\r\nKFK3fohyW1+ZPhjGGueWN4aNkt3yvgdBx2K3jytHhDXF533EdIR/8iz+Wb43\r\nsCas4FQ27tUCSeEi2wq/312JlxYWFoU5Ir/8wGS+GMC9mfzMuKwrno9Ky8jy\r\n8Ew9e27CjUdO6/vlpVBUhf+Lusmxw48hhz51NIsP142p8O31i60YusKORr0J\r\nonokUjf9NdBiX+Zf3Ro0UbttauBgrqpwUTzALMujlcsCq6yCA/KwO2hnxPQI\r\nIG/5w6+kO6kGUM2DQw2exm0N8CQniwKalfEftmeVUNBnt+VXCj+UXWE+sQC6\r\noyLFLsPC8hIwMQHaBx3Bg3s5XZXlG1p5MtTKIdkQJzfL+RS4S7rXoODzGY8+\r\nOPXD6kSIoU3yvHIVFFfNIKvihRIrNzSvDXtA7s1Y2g8mVTrTSdZY7ijrQas3\r\nIkb/xRLiPP/tRMqYp77H7Be/H4W6MaCoIQA=\r\n=w8VH\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"f6a6e640df9f6ae8321253fe8975c1887b1dc260","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.50","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.312+f6a6e640d","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.312_1670443149430_0.26069687888904225","host":"s3://npm-registry-packages"}},"4.0.0-canary.313":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.313","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.313","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"a1f8c48457c7a030d652c59528f11515a99e0a45","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.313.tgz","fileCount":22,"integrity":"sha512-eGvQuWEAyxcfFTJW1yiabEMjBo2sJ0bFZUTnM9zF47A25HVdugkY0eDZE4/OwqQR7IwFotdaZngMyjZTJYNEOQ==","signatures":[{"sig":"MEUCICHLUVSb+EUVeSuYH6vOmxCuK5hj3/gkkCw+GHZVZEp/AiEArNJ/EBKfZbrD53o+X/EV0YajgyvEMJe7rsyxBW2rH1o=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157060,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkYVwACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqPAg/+P3arF7r/bq4OM1PA3Slmu6bCRFC2GFJ3jX8QIGCVOuHtkwAZ\r\nH2bRCnPLEeRNxBMUASzzqC3r5an6sZ3ftQJg/mgfHDtuurHcQ8w7bT9fOph7\r\n4k1snPSoc8sWs08eztIpW6liTVgsz5EPIpMlDrDQQjF7gaSKUujGv7K5Voaq\r\nbf4ymi+dKNVsomjsazyFf1IuMrwF13pxOREa15q/d9iXyUqFaJyqw+0FWt7I\r\nCHTiLYkr6ZpV5R2MivtDZ61435mdE1VzgppxwHOe2Q4cMOZ1UuPqL10yaEqV\r\n7LPZt5PLqBVqO2NivfYcCu+GLqTnANFcsOxYiswyvi01m04UTopJhjauoVKb\r\nmEW59/y2wugz3fWMyks4XwuGuHT5H2DlL7giynMJK4gHkpjYrd/wzBL4Wh1Y\r\nQ1yqpWvxnyYoRvoeOvVvhLBuByE3ZrtnbBH1G7KXXvs4DD2Jkye/jM4ViVt7\r\nQYUw02ojnG67fVH5lbBu89HPihMOrIOX30jBhvsGDy/KJqtfgTNl8V0nxsNX\r\nqh1fq0MyPF+vqByNVD1w/uuviYgz1Q4GqPqXLz3nmvnz/XfvKaff98bVc9nF\r\nqtzoT6yANi36zeCt//DItU91uOuJjink5hCFsdBl4YKmCdGcS49WlCKO8QOz\r\nIDjzxyGznrRzAYqXf/+EUj4+/7ESxqYHiaU=\r\n=Ltn6\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"1fa8ffd96659c714684ceab1ec0b42e98d9c6dec","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.50","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.313+1fa8ffd96","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.313_1670481264447_0.4542790023097669","host":"s3://npm-registry-packages"}},"4.0.0-canary.315":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.315","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.315","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"30857d5e174b559e53e5940a43768be0af78ba64","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.315.tgz","fileCount":22,"integrity":"sha512-bD6wLOC/0NEuapnEKTt6/FbunfU/3E85e3fy5ATWQV/zBJBZz/IfIfhHcZjH4v+AdDV+kjAtpqBdT0MOgxLaPg==","signatures":[{"sig":"MEUCIQCoShSelhBxZ+cvuL7b/Q2Fr7uaAJeyiuQcd3I6IJgVjwIgVFMKYUoy5a3U7guo6IIL6oPW6ENsLd/FJXIqvQhURi0=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157063,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkYYoACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmodyw//WRwBbWpiByzgWEFP8LSj82ZB4ifyA5fQVvZ9kkAPi7GNIT6t\r\nPmZ3PIRcQbffl+P0N/nOEZLAIfNbBdxfvfv8+Q1JvN9RYtu2iupOZWyzy50p\r\nZclhwlPplY34E+uRE5G5iY5xRIDJcrxsblE1r2SHNkBwOuy9jD4gd9WYYGma\r\nAQXNOK8FHa4dTk3sCJ9tbqmAmADU3yp8gKLhS56XzSxAaS760ARaOenvWNtu\r\nNHcbLAznY5HpWwuQTasYRCcUqoJSZSHj9coCIQdwohijjXRYQPvxeMESO7M/\r\nraQrOReRNKaeO8B+VZEatcVPpuZHHBUfP8EzqvJhRXwzHphnHtGGTZ488s23\r\n9IGtlMN+aS5lucyj4zgtWtPzUbVkAbXmf2K2eRVuquUiMV6Ig5tOIYFaExFN\r\nyK8AlXIV4/cFnqggjaeuwsqwn+DCOlWMwOXRdi7jcMZwvHBPWmv9Gmay4Zez\r\nD5lghXMCgL12gfAMzi5Ru3txzalrUIzR2F3Bc3btu2f0f6lJEbVab8xeke4O\r\nE9vtjoh4MyopvRGHWSP5jEh/pboUX42WBlgjtDnEMdo3ERMzWTWq0cwl4PX5\r\nmkQD5z/muyoaVmoNHo9RFuZ861h3oohlPLwzg0+fDwnhxR20kV8KCbB1y+ce\r\nlP6w7h2TEgUqEm5rTASkeS/XHF4AqddIJM8=\r\n=yHi+\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"73a6075930789baa2d2affab1c7dc1eeaf711859","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.50","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.315+73a607593","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.315_1670481448708_0.5716273433633947","host":"s3://npm-registry-packages"}},"4.0.0-canary.314":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.314","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.314","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"9a07d9fcb3b168e0fcb0c7681a5a65adcdb234ca","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.314.tgz","fileCount":22,"integrity":"sha512-ohFqhxc93Kv7/W3i9rvHWINlBz8MIw6V+srIS253ij4xjeGPv11du8YvNakgaJKbRqbc04cWqhq4Y2FB6bTLnw==","signatures":[{"sig":"MEYCIQDZU/vLSQcgpu9ys/1sOj5QlRLyGIhQVTaN8ysplt217wIhAJVPCWyzNUBwj/zpFn9lOQ6PAaY/CZmpvxWBelplUFuT","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157060,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkYZVACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqONxAAhpk5+fAPj/Pf14rVlcQ6/pTQhGMdm2yraSR+NbB6B3bT1txD\r\nsWy7IG1al8TXu0+5GoRw9vE2eXGqueWSY3prG2M2XFjgbqCuhq5L3jdvmrsq\r\nkGQNCLfAZ/cwRqNcDoeg9fmLBCDBoNkXb07hIuYSqA6VDZy+43+7mMqEwh7g\r\nGEJKqKcgx8HtQ+9OqpG77wfjgLNZEXpK5y3h7QHI6Pc1ooNNTFrlJAmd3P0q\r\nwGz/HgrzeOTAvSZieTseQo2cARWbXPX9Bw7NJOjDzV4jFlrC/771EsOxILvp\r\nHkMJJNPu0ih0YMbG4tIi6esRcQWHRVHxnHlrVsS5oZhzWKS8MI1GTFWoEbw5\r\nvmDMLYT+AwlpxdTmgTwkMW8O083cKjrQT/fvI8nn4jDX9bjejFLSXd9KedOk\r\nX44fDsqno7pX/Yq+AfOzx7t54QufGS/gpM+N6YBFR+T/fMjpvFs9ydXf960f\r\nV0ujUxoRfPy55fD6gW1IIEpRlpDgZERoQQB1sd3mzOJMPADAvxlsNmCJM/2A\r\nwtB0nvh9O0R0CIhioIyOIFoOGWPY01/WhooLjutouKz+//FXkPJ+jwg+bY2k\r\nbc2z9HvccIGx+4IIunjKTOZR0ioXG4Z0mCYJlPF+cD99QmquM9FC4oZkQoIm\r\nuMgkWHEhZunibK1EY670w+yzT43J1uWNxuA=\r\n=wHmS\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"d5c219f2e8521aee03aa26e08225487d85f80106","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.50","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.314+d5c219f2e","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.314_1670481492740_0.8158172435634754","host":"s3://npm-registry-packages"}},"4.0.0-canary.316":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.316","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.316","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"10eaf2c115202e1441b52259d495b41d607e2b87","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.316.tgz","fileCount":22,"integrity":"sha512-XPSJldm9M0OrwTpelCw5zRXPIrUXe2iA0w+gxpcYDBfjkov9tHR61RI7atKaN49KEQcdlV4+m0TIySeqj6hXaA==","signatures":[{"sig":"MEUCIBfr3QPKi0ULjRhJueN0Ihv0Ba3mJilt3IknfvSPWlwEAiEArrn/54uOm3K55J7JPiQcF5h3qfsFPS5Ci7JzDH4JqeA=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157063,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkYZ2ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmqc1A//RqxiDQQ6QdDUIM62830lxrhMxaAS5exV1mX47oFC9vU0Yp/4\r\nz1tsrkHWqIWu73ACVHPy6Nfr/RjLWNGGP/ItSgWZdPy4CM/p6gfkXxCsLPHe\r\nztoh6bUmwVMYrOuSKroVDwySLlDGiLUjSxOiEc94+weEL/iRvkz4KxTtfu6/\r\nzGmFBoYK2vrt89mQoMxGrwGdxEekqw6A1U3JAPs0LX5gRAAtjp5RuoT8hBMZ\r\nskJH2z5kgGN9RTEvewqK55VvaEeRFyl7o+d2vQReERHHayShDWkIzCC/t5a7\r\n2HpFEGXbEJNLEA53blGpdbSZ4e5gv4sGKvhqCFb0DRSU5tYxyrlSWvzaMGKp\r\nf0Arm9hTl1leGLQ7bS+v6/m00/vQM1pg83Zjff/kXmxsshiAsFHwg7HvZa88\r\nvQ735l9tZwrYeg4Ng8tLNjqx4hNzUw6cJa3olI7iOM/rr3bpy93wNBMelQ5g\r\nUCXfjYBtom2YAGHh9dCvrh2PZTS6pL2KM2TNCZyWQ/STk8zXIeUHtzfFVDig\r\n8mjuuHH1QzV2fTP4aV6fC6lea8pq6p6K/p5QBqKr1VW5UR+tR5h5cn4ed2/L\r\n3mcbSLnqIoqXfULanGJR3ikm9rSC5hO34q6ZPF8uceUqNoFuURXdxq5tA11m\r\n4H5+BpjPLpoDahbHDRTmBzac2z8XSfA0eqQ=\r\n=sj1s\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"e5a7643ee1e57f1d025622e9a3c23ee669952943","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.50","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.316+e5a7643ee","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.316_1670481526079_0.4464417189748995","host":"s3://npm-registry-packages"}},"4.0.0-canary.318":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.318","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.318","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"46c095caba583afa846ec6043c4387c4ec24ad94","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.318.tgz","fileCount":22,"integrity":"sha512-ui5hEt3nhmwxmtttehMstX9x453R3ykbkN29GBlPNaPIkLH4wQdR9qK8pkBxMEV9pYDqMAk9MxYGSr3wWsQbcA==","signatures":[{"sig":"MEUCIQDEMaixbNE/2Ci20PsVohc1RGLK0X28ZzEqiZ1O5o+vBQIgbn2DsriSbjc2kORBicYILWtLeE2VZZva22cs/qmbisE=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157063,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkiEBACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqQpg/9FGUzQkxUbomVeLvzD4Z/npxp+3/ZJFemDdLL16tiQ3M2h696\r\nBU9d4bkAFup3djkBqjfJ8oGgJpHvfh8GdNfH9HREvsOj4LaqTkkYOn1Cra3M\r\nRUlEQ6r/mP9PdF6zLODmCEELiCv5I/Z2QmUpjDF7SutmRg1tBhjj/bWPQVqQ\r\nsyjmVdDZAc18/1vJ+HQlxHkqu5Huqcso6fT5aULWJaMvyxlxayaVNVLE95Cl\r\njkTg5VzE/69VEhmcNnAEnx7m88/DZ8O+/SHFScWICxugsONMlIcfbYbjQqof\r\nhLsL2I/H5gQ8NzO0OF9YnZFnCMMXx8NDYtYONVcGw8WHG+H9lGLfZYH4pqiQ\r\nKjhNk3VYyzos7c261TImJwV0cdy19IxWFmG7OrCQRzw11D1tHA5LMTaugB5g\r\nGGDd5gacr/wMfUj8fRslJUPbSstKteFJfEHp56IYgI3qH9/xPxawnJuyEKbS\r\nw6Cb6nwatGfHxQ1WuDjclN8x0xCRsVBY96Px9xoRsNKwYjL21vQ6lClqcrt3\r\nNZ6ts+TH6XWHFpfFZOTM2VIY5DfMudrShsFd4f7aSl7ipoVkdkDY6rG+a5+N\r\nbUvAqv/ROINNK6/5MT/XUcE/g5So9u+e/wgjxxqOruE5Tx/bUXM/MUT4tsMY\r\nwYIp/UOQ4PlW3L76rsf+pUCEdOEwydzlDeM=\r\n=xXci\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"fc84893ccc7eaa5f87b39cd12ad49819fbcf9a37","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.50","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.318+fc84893cc","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.318_1670521089440_0.8909794908780535","host":"s3://npm-registry-packages"}},"4.0.0-canary.319":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.319","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.319","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"413c8721090b8c2705c7dbe2a556426ac2a5deeb","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.319.tgz","fileCount":22,"integrity":"sha512-z4dB0ncyddpQVw0lBKGCEQ+vGfhK7DH2/ZRfc2F3u8t0/RSQXuZo5JavyeUC2CZYSn/b1w9rJLpUWi24cxDLPQ==","signatures":[{"sig":"MEUCIQD7vfDXftldnx2tj6tMU/igjQHRpF4qpKXJe/PD4HpQNAIgCG1V1aio4fRfxpu+ljwcz4ocbd/zHvETdigPvH9CZgY=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157063,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkixhACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqjRw/+Ipp3JWqG4zF2+UQI6Tsugw4jgv559SYDrhUCIMsLD9X3uGbF\r\n53d2ddFKZlb3f0wULRiJYqeFaBEuKbXHhW6TpHqmIGpTF0ee0fJUUjVmzynZ\r\nY/4EYyVq+iPUw2bygnXysM/JUomQyf15aZ6WM6sCr3f2s4iIYbenCdFtk4Rq\r\ncrfHMdzIfxass0I35j0t0MA7vXNbUOT7O3DosFhRp6Q1NYDxdvKeSqx9ZeA5\r\nQL4S/L02Cd3qKZXV+iy7cu9U50cILkHKMeLPSWXQIOxgPNWvKMqWDNnWPziD\r\n2z5YIDq1Xwq2C4LrtoXDqROoTkNVExkSUZKAIqItYB+QOkCqnkLN0iP/9oNM\r\np+35oEcCCdAYVURuOg3CW5nVsI+EzH9Yjw7NRl2Hg5aHDXboV5aB5h1Lnuw6\r\n/Bi9gffUb7HnW+IWrB7zj7cnnacdpnjjiu7no7O/NBiTO4h72g7DeWoSQ1va\r\nDA2aQvzwus+N5ow2VYAs8sru1zVV1SsAOiF9pZyLzVNLuAMOwdPXNNKTzPa5\r\nK+N9cMYc4wGI/iIeI0L70Jvc76RXFSO3K0YjG87unaql6ZZOv587YWwtyR3J\r\nWC3g3tdPeGUcSCNHm4cj8EchVcn8GbsSA+MgMANyNbrNmyvyTeNGJDUOTdlZ\r\nW2ux/PU1xZmr+0xxTzWI1QNKu2fgh8VCRz0=\r\n=bw1Q\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"867569f2865df108af54dc645468b79d881ace78","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.50","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.319+867569f28","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.319_1670524001561_0.6151363566193921","host":"s3://npm-registry-packages"}},"4.0.0-canary.320":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.320","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.320","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"7759755d31f55017d1c2a2ae2aa6c41881a32e0d","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.320.tgz","fileCount":22,"integrity":"sha512-9qTXEHUQeMjFFXZwdSJLYtipOdlagg2P5jDiVaaNX1EEFD5CnGZmtgHcKAXGmz5gfPlTbJdjta8qYtcUa+ZEKA==","signatures":[{"sig":"MEUCIQC3TuoHS9fACZ+e+Onhn2BILtOJ+gHcoDTIDfK/AuPsJgIgBTDd+eNAhAPxG+/y+vbGYPw5NPimc13vJ8pyBaXikRI=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157063,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkmYoACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqrfQ//V0I7czGAameP8hhK7pi9A1KD5GnpF2zh+yjeg0/zn/nX5y+T\r\nyojOfR/ReDI8KuXdc0zOLSUzDM77s9qqsdLS/vqRNULGMvVgHDYCkRTDXMR7\r\nvZbKtvy5RAv3h2KAWCiIeO5obdugzBmGu84DsFDyFNP3AhOP2EdvMruXXATC\r\nfG28yj9VfRZlMK//L6CzOFSVvK+nCYPjbOvLFYddJg4aw2Mf96LjV6BZlPlg\r\nrJPK2CfOYho44ooJs+T2ZbJ3Ln/EOsTNh2mkxFZt/qAPyIAM2WfIXfTQHkbQ\r\nJD5sPq7NoxtEveSiUUqy4zJ7zB3LOWNaI8NGxehwboooQGDzyY5x5pCUV9M7\r\nxtzWTjpDfRmiylipC0AMrMN1ufxQcrtnOEorH3K3wvNw6URNlmEM4C1KKNRQ\r\ngTit1cVMpaGLyZjUmRaV+IxohYuEL8fzHBP4a1ybo31L0cRGMC+2Eb8vStSO\r\nCQbGTv7n2Lxf02MxFLBKEHsyKGfg68J2JoSQagpPTGZOJ8mg+VBxwfjWFK68\r\nio/b0m2qWJpC89mp8puQZi5QFSpnr8HpPxk6kIBBtV0CZYLlF1sjI6k68pEp\r\noj25GmoBOt7FL13FScCsbv24rIZHFykaHoOI1tHQrgZZA3g1x43AVv0VGgYh\r\nCkReGORUOWKY41bX4jAyKGQ3cYC54bWmVsY=\r\n=6OfV\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"e26feec2abe33b3925c492970d1bceb2a2a22297","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.50","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.320+e26feec2a","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.320_1670538792691_0.14527986910429247","host":"s3://npm-registry-packages"}},"4.0.0-canary.322":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.322","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.322","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"ba9162b0a3a406bfcf8d4b4e488fa77bf715eaab","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.322.tgz","fileCount":22,"integrity":"sha512-nBbz9LQcnzW5qGCn4lM7UFkMutHZCaYkMKOvJtYil2ZfmYdXft1yYxS/4MQ2iCb3dyP+ffPylEVLwbC7cOnW5w==","signatures":[{"sig":"MEUCIQDpVVqR7eUtCl394eQm0wxufDUzJXOINZdy8n1Lijbt6wIgEcfxFrbsOWI3HpVl9ZlI1QG9bnwsF885UHhBIafsuOU=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157063,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkmb3ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmocoRAAolSEsyEJVXeULRjQa5HkQxnSa3O5oiIG1r4zMxqbOWbLzpdy\r\nqzNelmw6uJUFeYSCUHtHQcT/m+uBElXtCsBqLLY1L67f1XDzEr215D6LLKGk\r\nkurcP6zD3YkD4iO6ns3mVkZUROplOzlGwFxYcTvB9ggTg7dcuL7P5+LLjyQN\r\nuWZvWHgUUWvGIzNpzpRITtEkeGM09mcJCBPqsbIG1Q1Xj1tzt97o3U2pYqCS\r\nVESyqfQHYFEAhuiP2M2moEP7hP1tj8yMTOyDAHpqoruUKmXBDjGxktusZhdh\r\n+m1jhl/y1oGHpBnx4kPKwFXL2i1w5xrHkDeUQU0cn5Ns/jrwze2AuK0lWz1W\r\n+7uUIVOKiip7H1AQ9oeRq0xbNEOxXOBHFxowhwdgchm+/zTKFCPxFSqxLCm4\r\n8xxdkjglDdaNpMESjRKdvW8kFgRFXtVT0uD/2iiZszTbHD3W0wIAF7uOOvNe\r\nHutfhT+pP2/tql/TxPMEexWf7MgMF2njfSCt2HKypgm5zEfmBbyYdaoAb8Wq\r\naDZBwJ3K3lzBNFnxXJicd4b1sZujFLqDglq/QGbfNrGueyVzjYYxgKVTCDAx\r\nypEqe3OlEnyamkoowE9QjOza/yu6trrwxiSY1GDBKQhEFTWxOf1RwLGakkIy\r\nIDifMXE1fIDdNF4jWHl1qdHDgEY8Eqnkkmg=\r\n=nd3L\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"cc4d4a4e4a23e184389b8f29fe007ade2fadc465","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.50","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.322+cc4d4a4e4","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.322_1670538999574_0.5328891638221194","host":"s3://npm-registry-packages"}},"4.0.0-canary.321":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.321","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.321","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"84a16b88bac60b2635d550acff04a1974b3cbfd6","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.321.tgz","fileCount":22,"integrity":"sha512-TJ1IfnaRu2xOPnbV3LaqPMcLnv6xHboHlELy12bE9kNBn+n1lcLvvxZ6chLj+OMN2JB+LFIZ320Lf5G9E272uA==","signatures":[{"sig":"MEQCIBER4sxbocnEHZT6EgJSnvk5Js+YddeJozD4bMDCUYExAiB2qY1GTvFgCMw+fzvTWilw/hB43/hRYz1kQi5hiP7WjA==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157063,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkmfLACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmoqlw/8DKxo9l+JVWYWATCCIiRu2tB+3qtTCoScw4874CoBkvzuhkhs\r\nZ7/oqx5txRMHoiVwMnzU2d+ihVAjeMloDPGxkcwOj7bAJ1RG3QjY/d7OpNZh\r\nvRtyIWeXKL/YxgJgqhbU+H8urI1EfbxHcXs/gD4jGtROiDqxC1ORJwU/vOGJ\r\nbpEV1g0VMX428nri2DBs6ZueHZNSyGi5dFFTK6tanbercxs9RLK2LVPEIbZP\r\nBaiU2Ml0yIrJBtJCTtG12yb0DC+QoNH+DlCQZ/rj/FijuvXhBvhublioRuHc\r\nE52hJaERq5mVmhUmnaWlwnsv1um/E9LufhnrvUvnM/a06U3IZ/MNTJ/FF2LW\r\nwcR1dMKOYht28lnSlURFxcV154OLq8Pt3FEOacoW3LZpD97XuJId1iQOtMVz\r\nWKrsb9aTaIxUBjzslW0WUrEqf9cCCP2QTO2vx3u9Q2d1FMdB6f5KysB/UqZ4\r\nHQie/IrgRCphupgVCcY2waB6u9sAdJlL/8Z909Oo6at4TfEZBugMUwtJdoNj\r\nqKFIP7iWNK2pAL61QCuaSKAUCwulyPa+Dd9o/RjtFsrfRAHYl3WMku2B7hDK\r\nftkeBP27Ggt4cfVFEiBRbLvznAwNk9ka2iBXLy7OUAiZd9HC6yiJBXVcK41x\r\nGoZkU299AHiLrq0yF6Mq/XWqqJLMVtiuuKc=\r\n=IarA\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"b1f242ee395097beb24ed4074f7318defd12d340","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.50","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.321+b1f242ee3","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.321_1670539210921_0.9464194009634412","host":"s3://npm-registry-packages"}},"4.0.0-canary.323":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.323","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.323","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"ad06dab37360e1633614fcf147b4dddece5a2a19","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.323.tgz","fileCount":22,"integrity":"sha512-t939sPQPRlklrd4aX8ULDu5Q6RjHtc2oawECNNIUL0s48WEL5ALU4FdMfge5nl33OJYn6lNtgLRhwZfHLBBhJw==","signatures":[{"sig":"MEUCIARAu5RXPNCouiEG5GbVr64oD0qaMS0jEXVpvsCMo8ieAiEAi2fenwy5HGYjO0xCiQi7OBNBobRFXPQsz+cEDvgAw9M=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157063,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkrFmACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrDxA//ffaVms3RBKRe44+0xVOZRb+cRAnEgwrd10Jk+jmfqRmcy6n1\r\nNYsq10EjWGC0p1spuWfHNL3ksR8FqZoK4+62gMRB06iHDasXVZGNH+YlQA4S\r\nHbk6TUnwDiXlYxpWjUw/Zu12Yq/UOk654yV65w3i2VVshry4OiecVc+euaGb\r\nOKEKBZ9ncGx5+YV84zAQ5axVL9YBLnzQeD41ONP4fhkyNTfIReADbTJMJIrG\r\ngFoNO1J9uoUzqgLKVgs6umvnMWjoXDWejmx6uqqVigDeIr9Onv/kUNa63Tbo\r\nv1CWLupFqcVglI7bg51JXQnypeO5s9PgufQLnO/FeTFxOFj50UJwCNtQAav1\r\nH6AMHUoQsaFWrF7m56zghBM2/x/rQOzASOQm6NY841YyPQhJRdyEVvbgI/uz\r\nIYs4g5vs6VVEKL44EQz8GSyRBGPJF/l+JX334mgNJETB5POaNkUDALx8Ommu\r\npSnsTAw9vUlgvzhL7jQZzJZYEnUiiDsGXU+ysFocm0Ogl04Npgcx0/pmabj2\r\nhcYCMx7v2ASjjBU3gBIbctLRrqtt2p+UP0GJ5F+VA6lqo1G5MxSD2Hc1iDL5\r\n9lkBkp3AyOKrSMaRfG85cRWWBEZRwo76U/q/vTCCdaGQiOIFhst2yliVMmzV\r\nTcXyllQV+p9MO0QJxQvDiXTt70dZ1gwKD2Q=\r\n=GeH9\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"1e2c8b748c33baf6d289f54c8c1bc39e969ecdd6","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.50","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.323+1e2c8b748","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.323_1670558054080_0.8560257791338919","host":"s3://npm-registry-packages"}},"4.0.0-canary.324":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.324","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.324","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"33a84b9e39ff8ea9d1dd11e6d538c64a2c2162fc","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.324.tgz","fileCount":22,"integrity":"sha512-JqSmm6YG5XdbzbPEi7sanzpk5CvJL/hgWv6HqeTKL+fvnoOHGszICRnkSvN9uQqCfDDiKO7XQv9JekVHggp3/A==","signatures":[{"sig":"MEUCIEO4n9UdA/emx4MHKTalachf5357CVpiDOgRCeKgmoiOAiEAx/8ZtzqqJu9doReGlFhiVQHZ/Ao7IPgaSh2elnthsiQ=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157063,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkrOoACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmrslw//f5ECo2wfP19Bn4e3Gp3J6nOkW+ZGeoH81M+9esisc/mm13yg\r\nBuQ5YnJJgXdJZ1FLa5Z7qcEY93DG+sxDkFmL6u4oYuMYKRAnGbUbRoLb7CXq\r\njGJ0r26rLekL8DUIbfVrANYf27TAuSfWwzrmfFe8AZ8oDWnplJ0ndmk4mWtn\r\nP+SnUeV/XJ3+RIAPHQ8txjvfEtb6aAUV4Ofn7yFBT0W2TB+jjJjzQvPh7FA8\r\netp0dhSPFkbaNFv38D/L5DibZz/ITZOhotQZCB395L4X92iVVLSY2Z/KX77q\r\n8a8XxNjZcpx1I0bX+Wwh1VhEMoOOHvF16viwckqCs5WC0wj2ogVYuGec3nwp\r\nEzzohSui1PMLQ2s5zzeiWFoy/YFZxpDyqfqmykXKbUpxcHPdH4kOkaZnehrc\r\nRrQWxqZuWz2nywCIdEXOUdudMXmS8orQEaXLFwdh1oiG+JjrKDpWYySO6Gox\r\nu7+F1qXbZwWYhpZRPxGsDYoFkcRsJ9VZ1m0sSuXomDTBDKMQqmxL5EyGCgnv\r\nJFE7zIi+Z7GiADMicpQ9fHmbYT8bFoFXWCpk8JbF4FcDCT+7vJdeJ/xUG4eJ\r\nExLJ+PF5ywAQeqDk15bTWJYBcG47ZAq51QkeVHQo1Lz+dnouv3lNZ55U68nC\r\nBzyDlB12wR/aeLm+gaMojC9mknoYvzK4jEs=\r\n=6dkU\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"27b1666f888eda8d1cb76bacde2060846d1a5e9d","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.50","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.324+27b1666f8","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.324_1670558631858_0.14169781419395955","host":"s3://npm-registry-packages"}},"4.0.0-canary.325":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.325","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.325","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"9199ccb4ce49e6345763e29b8f8439066c71f290","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.325.tgz","fileCount":22,"integrity":"sha512-LAegYyQa73shKMNPPQCWtC/HkUz6fkmasL50r7SKcP/EMZzvCcbHx3aCt2pDeZADKwsqNxR8xDi8xm63QorsGA==","signatures":[{"sig":"MEUCIQCYJg87RLsiRS9Yvg9ugGPPHTOr9zKzh9YkmW0O1NlpYQIgNRYUBJxuJAfrrkF1potujrC/LEt3scGRV5xyeQqW0Z4=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157063,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkwXwACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmrd7Q/+OvMQcwLfaCxSJmkBTK6Uxw6sPZ0EGQd7KlRSiS5Xyjx5N/ny\r\nASYUFNj2jamD5XtefAh9XpYseRWzGe8MB8skVKAQuecslvfi1/xqzYNxFUMV\r\nPWpUtrfguzbH1snWqbaCOB/GXLjczNyYoGIsScL6atup01qqlulAcIT29p6/\r\nsfrYWjj/NqidqXlyGNd+fPrLA7qozsyNm+rjIpcQvCwcMu0qZ0YM5Neo0TTK\r\n+zD+TBEdGsXSKmtJcANHktPvcP5iJnKxgvFVq4yJ8v3ecedLEDV0pbci7BB/\r\nfqpeB1xNtirtsKKTd7qe3z9gCctgzFNTzj8YVO/30bv2kSxYnyXFYD0nRJsI\r\nARMiT2MfYNGI/cheoDmrQHV7ZoQ5rjuEc1j+8fpMhrP4ANaq8d7B4BK81Yed\r\ngSXs2rCqAqyKtK+b9vHttJu79gPzYzt4UkJEGizVuRx2AH5HDzRrbjFxSC0F\r\nIcoQYGBTFRGVS9y9YeBVp9z7q34bjUBqCJgxc3ROl8KHcPgM/sC5KaFOn6JC\r\ne5qVSCoIvW/sRuJOYQEDE088ttfWEfF4cHgi6nfIW7ITMFEdIorsyFdvAt0P\r\nKx5AIiQTcgBUvShNwZP3cIOOfXk+ZjYsOZLgbE+tXy39fmTRJZilx+Hr6zoq\r\nUzYuxssgYwNYORQawzwsaxPckS4BASBllnM=\r\n=qZi4\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"b480d88606ce33c4311c52302ba346f1c9b5ebda","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.50","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.325+b480d8860","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.325_1670579696574_0.5081873566755273","host":"s3://npm-registry-packages"}},"4.0.0-canary.326":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.326","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.326","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"ea9c4c0b04c5fa66edc85179ef6c1d676a3274fd","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.326.tgz","fileCount":22,"integrity":"sha512-EjW+qWI81oQhKJORHqhLgjnB/Ln85T9an7GBIZeOIxZ4MPf8Tc4Fec641I+KiOLin67xwIg+SjxHBQX1MBYQzQ==","signatures":[{"sig":"MEQCIF2w6Bm8F2MRfj0rNDoZd0Sa34np7IbJzscuaKLeo4ghAiABnHKCFpqupSt0nitAOeuWtg86oQ2aCeB61op4qLQSIA==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157063,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjk1OCACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpnrA//cbC1QywtvP7MZn9ERl058wOmi7sxbAt1VQFwiXZqYoJsSUFE\r\nsHAf2dn7TEMenYdndVUdllzPVLub1wgpR4FU8kQtuqtSflv2WxSZvIhMYBt4\r\nA5NQ2w1lJrMuLaqLtQj74r8U5GrTPw3cd3/5oU7zckupsFnavOF6nnsyaj7d\r\nQZAHXUHtAruMMqpEylvUTEAqkhqk08Gvcv5N8X6MC+4tVN26SBaEjbf0h8LZ\r\nyeHtYzkXfVcaWCMZdB03ZqWEtpmo0qeyVgygiJMWjiZY7eBOeePgv03rNXoE\r\nakucG/i5PyioQFzENTHN2MoMO9SWV3+uYqI+mxexU5ftC3Wdc7o037OgSuEH\r\nqnaSC8WypOJrIPqd6ku9omPI5AnWoRaVvB5uaOyHkz+HHkX745hVe7JKzn0K\r\nzt1pxvB7PsTQENNEaJLWICkfbyyGtA922smtjwi997jgvpMWefEOZ6hZRQ6I\r\nSURDfUt13y/VjqgbjJsqwvvTPcSX555s8zOlTi0+Sl9GmqQKPTUfMzht9CNF\r\nFuL0h9MQnVXXCW3IYn6EyeBP8vRrIVPoMRLd6i6UC8XcG9wsfx9hiYpD9kWd\r\nyUcCx2Y48nfr7Bpb0bA18bVjKHAgNjA2DCX3ou5wX1BQKxADfOcVdxGQwTFQ\r\nxlfjNXk1pMtJwJcoYUSaFSmD2t3RcRRnlkc=\r\n=0z/y\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"808fb276433e9e103bc939f65fb747bc31376a20","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.50","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.326+808fb2764","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.326_1670599554257_0.038837665746972894","host":"s3://npm-registry-packages"}},"4.0.0-canary.327":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.327","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.327","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"1941b798f547b2ae25ff952d204f964e56477e7b","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.327.tgz","fileCount":22,"integrity":"sha512-Y48dirRASSkzoCsBCMmEOks4RzvqaWxJRisiRcrJCXfzDhxWbVox8TR3ii8f5ZY8M7poFYQ8nXUipjVpGgmNpA==","signatures":[{"sig":"MEQCIDsOzbX2udZaSsO3ZYeKDtJDQISr/GwePR355xfIznIdAiB9Bd+usXPD8r4QFTz4UtxY46JCpBRdZqYFpEiDIWUtRg==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157063,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjk2lqACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpKsxAAm7XdloUtC5GJeRUcHa/jmzli1v7lrGkbP++SUYxtnMVxZ2RC\r\nWMdiud4bh5m3y5Lz6H39otq3RJVXIgzV2asYw90EjsFlL87WoauMrXmn7F7T\r\n42khn/MgWJ+OPUeDBlpu2xktCfwpa+5nDp6DyB5vvWI0TImfoqVx2mwqT7FR\r\n05ugDnGpZ9mCJd/zKRr5yDNSw+7jZs4d8Az6UQMvHMCCYgydVLRG6JsimL3J\r\nttghBYabBop8VfV7cR16BDGr+JsvzVNghrMRAGKg7Qj8LIAVJF9tr3RygQfm\r\nhT6kzZAXGYXvIWRZmS78m5D6gzMgquhEy2aJYPxpEpYSzDRoKyyJ0AFs5pOm\r\ny3HfLj0jNvAt85FfHGTCZPY+eIzVLP5aVO9Kzov03kc9tjpwIKqKUK8HvA6X\r\nDmwaVtTB6teN8JHWe3EYZdlDvf6s9t1UavhqgLJzMWIoV9UanAd0OpN27lxw\r\nPIlMllP+m6tqMcJUjhrqnSOQM9QXPZH9xjGw4CtqD2cawk5/hzthBeV6l0PT\r\nJU6w1NomLMY/dFKOeu79T40m4i/endXLGkwRrUNiYU5AHcAFBssbbHB4n8or\r\n4FfynHNxH1g1cQiajiAmIrCBat5hUEi+VKdYBioo9+v1mvsnWb5xsBNGPYzQ\r\nQ+4/5udHsl6oikNEwlJgSJ6o4/QtOi0Sjuo=\r\n=OkW8\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"ff58c53fa943f942d162f50bfeda5a69e02f2ea8","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.50","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.327+ff58c53fa","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.327_1670605162003_0.1122523453393891","host":"s3://npm-registry-packages"}},"4.0.0-canary.328":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.328","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.328","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"f67495b98a48ea2d771cd66ed53be5c1ce813a52","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.328.tgz","fileCount":22,"integrity":"sha512-nzrxUuHP9NgOJabWe7S3QdvoBqf2MfJN7vEpaTrkTCMTBsYoBGv2UlScOIfyNUNzlEhh65gYD/yvyyCSAcvSgA==","signatures":[{"sig":"MEYCIQCX6YLxC9qSxQQewi4f7BkyHhfPfDL7V1E6DyWtvmb7OgIhAJCkK3qgM3VMAFeyTlggN9Dxvr+vqZugYoesqF0EF3fw","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157063,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjk2ngACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmocqw/9G30OtNwjpxwUwszIaID2SSt+C5er1RjdB44RW3RCf+sNv221\r\nf89E8Gvv4O6GmJ8Qtfpr9Idth6RtxjmQ1VBkAyTmTbukOea6gS4beZMOBd9N\r\nZ5Ns/dNjCC+//mncAmsPZ5UlhAFodPdslko4cs8sQw3bUQF0exCXqqaKqbnl\r\n2tRvW1FGTLXo+wSLtZRXvSMrJCmvrRv8jY6Om8ljiGtxS4/hzYV+ruA2WXaa\r\nS+AC7+StzJs3j/5puKyyJH1t117EaXRziJ3zy+e5lJ4On4zRxqeUA6ec2lK9\r\nKG3+4wL7jTRHyxPYIJ/nFd6pYqPYxXkM272X6YqqKaiJExJoAMsSTf1UrEJT\r\nNz/FuHW2pdhDpi4ip9MR51AL20eMHdzBTSgMdbxo7E9/pYHOriQY6ZtoMC8z\r\nnb/0ghVyyq991nZDRIeBT/KzgdOACIXxu92YvCp397i2f0wXKpNfw8Q9hl5A\r\nDnoQEEODEHk6Y/LyQQXjUAX62Qi8El/5ixWXlha/TUPvqtCEzVcJM66KURbc\r\nzQaWT4LHZOEdLQFHwOmuX6hEuf7tCe24b63RAoT9eonpufpdrdor4P23Lb1A\r\nIsIb3hSQD5F0iGxfhEcXjyRpLtC+8QJRIqMkso56iv2fHIz6fRQq1TdoxEr7\r\nflD1Cgq2LdF58wFXQTt0b0pTLoHCTi57vD8=\r\n=Aw5J\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"9db6bff71824f0b2042d97cc516a14644841d7b2","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.50","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.328+9db6bff71","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.328_1670605280525_0.3872636895036399","host":"s3://npm-registry-packages"}},"4.0.0-canary.329":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.329","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.329","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"d615fe9cb6b701462a9f63f59de86ca57bd047db","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.329.tgz","fileCount":22,"integrity":"sha512-/BQ5R8kXfgfaAiIoUn/Udz3ujTwLpM4Lfl26si8u0NGA3N9eBC9dpa8jfomUUwltpK3ZgVpo8k3MtryeUaGUMA==","signatures":[{"sig":"MEUCIDucoa+ab33Xb8znHLNc7gKjUnxM5jNx20RMlnhWD8E+AiEAxoJzmqhEQrRGpjF3e2vGWF96ty6vqh+Jenf2pVk/SKM=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157063,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjk2p8ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqZVw//eepfNa3OucgSlrJ5IreGizUCHyokMu/Me1oc3Q0urlI6VobI\r\n2W9Z+yQdILWYbuPEuwFYdJ5jOjQ401HNvvHWO49ID299VWf3BusDdIseh7eJ\r\nBJfAmrBKIFzkw8StwUmOCII3WVdPu8xUxXAiACxWJ4mfLUqY96YqErCUlr7/\r\nd58l9YB1zptcs7WKu0/nfBlZysvOdqRnFoNr435YfttLLMjuTRoStnMkdyTz\r\nPH6Z4HaNiXVq63TpU/c1XNkGLEdNZEuFwUihtdvhGgm0Af7umGsRVxsWaq9s\r\nV3/HyoCLy19OtjsUGkTGSZyMuKHjjs2KKsrM8pMmanqw3Yjo4QqxjsJlg6Ds\r\nQMLOeJkh8CbITZ2N1b2x7qxjVl7r0CVDckJ1wJydv2oLzpIyaHMLcbXWPlrD\r\n0Oy7E3FMtZa+1Fdx9wSoDlt1T/Houc9CNoswhMAHNzpjkheKbb3Zckv5+LS2\r\nlA/XG6bPggMDq2s6nNilKgXQ06mOuhv/i+tJhJeV1BevfvaTlqrU1+KbdF37\r\nucOTskN1VKhx4dw4suM7tEV3AuZ4lNDN8UVaAj75egK3fEl+NcWJths6Ex/2\r\nNil/Iy5pPHWxEa1a6DOFmYjdhuZMUosS3w/UTynXCkuY0BPy5WLzKCcZzkAg\r\nyDo2Qbmftx9E4xSEZqtDkN9m+mBYATuRAe4=\r\n=eTjC\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"b997c06f2228a8a73bc6e1a2ebe98e7a3904b004","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.50","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.329+b997c06f2","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.329_1670605436559_0.6703707334918758","host":"s3://npm-registry-packages"}},"4.0.0-canary.330":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.330","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.330","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"f3166efd732eb525a0533f47e213c6828fe00626","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.330.tgz","fileCount":22,"integrity":"sha512-qfD/IWE8uZG+wiIRVqmSXUitw5fHRBYTldOXUA1YMO9tlEkbv5pJHrJsctC3M+uqsFhrhjY31w+IwBL7DO2sXw==","signatures":[{"sig":"MEUCICoPnIpvJ3oVSLK5Vu0EAcQwC7Hv0YpqITPwE45bobg1AiEArYWw8HspSauzlEl7b8CMERs43rv+DdOpZaPp8qcf4o4=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157063,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjk4S9ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrLOBAAgV+fh/jpS8Y2jvfXgE9THahskjlbMdQ3X7J4tFPBc8VL5MD7\r\ntWLxGRj8XB8Uuks1sU60dH4Ft22XrTfqx0cv/GvpxaC30DvMwerE2MnrAHfc\r\nZk+wCTeA/1ndnbuR+FPb4PXBt1+3AIWJmwsoxBtDoQLZH5LpaKFGc5idErrs\r\nVlAGdke1scARsgJLp2fHhCtYBWtcusd6aeGZxxosF4AofI6gvDM6GoBM/LbO\r\nKlFi7PagWawiDFgrPEIYHPJneTG4VcXgc6qfusaR//M3Xe0TBF+keeLQ7C0T\r\noG1jQsF+k10U5nObeHiyXIkOslTn5K/a9P8ktRSw4Y+jhoIdlMAEjKtQ1RTR\r\nRpYcNp6VWNsaCIC//n7HVF/yDQ9N/n83shDNnh7P8coBF0Zrf6E0S4JIcG1C\r\n54FMDAWZJ88ZC8oaIdxxBu0QVjMWnEXXRtNJn8LkCE7MMEPIpDDvjVcP89oD\r\n0RDRvq6VKBmeDcgtvlt0Vtnj9G8DaLtucB3vfRZqcaPV39sV2jaJLwf63VH7\r\niKIMGohxqrdNYFqQHO7DCVuXpTdhmBNtBUMrZtt2H2D/L1ng0qdjV1/Z/g4L\r\n0aGaEQOF43Vve83FPe6WcdEd6xSDVqxfRbM8zjp0jbBINwqG1chwdYtieAUz\r\nog4e8cI6H5ZzmE/cRG8XYFyiYXCZFLPT53I=\r\n=Oc+a\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"05c8b66ea9637412ddb377684cb90872db55fd9c","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.50","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.330+05c8b66ea","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.330_1670612157676_0.43108465901218485","host":"s3://npm-registry-packages"}},"4.0.0-canary.332":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.332","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.332","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"2f89291b06b51764f548f9000cfa55576b3138fc","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.332.tgz","fileCount":22,"integrity":"sha512-tqX9XajiBxowt2AcqX0+qN5PUCXwvw3Y6DKl7QJJ3doPc2yY1B4JBatkBjH2533tRLplMjjgVlPcJKE4pB0dXg==","signatures":[{"sig":"MEYCIQCjgICNJ4AmpQ3SAo/z5dIGW+/3Vswj5oIZfxVbhzbAlwIhAIRa3BomXrdS1Gb7j9TV/uADS2fzF/Fb9eBEdccb8rxO","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157063,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjk6KpACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmq8shAAgl6we7kveswHSfX+XM/Kcp4MmPuoomqhSPrTmpYInCBSCjKy\r\nShZFANQOzT8hRoqVN3IcW0USNvOzcN5F0DEZQNXQHFZwgm2oRD+KJ+u8k9Fj\r\nqU7BXww68avnUmOaKw+6us9HmMVHCb+OY05UfeBXun4fj45Z6+hCwBZGzeLY\r\nYgu4uUoHPJmfUzFucnKYdTH8M6K4gFI6NRpw539i2ad6Tdgn1/sxUFu8k2IM\r\ntqJ7H6nFTWF/yLGUS+Br/J6WiK325Bh++vqMHkCLlR2Kb/i2alE+Nwhs7u8Q\r\n7Kn5zLpIyTNyeS1iess2wRaXmaHGEKzh10lNpEmA1DtBcmJRaPTeA4UeHXUk\r\nEKyiutEK+UjIFCozFrP4Zu3RP9bB+Vb04BPX4rLlrbdpxFbuE5uGxB3WfT4z\r\njmUkNkrQJgx/Le2a+tW/efaNgwiVCeg1mFZTWSNKVIB1thsOEmJwhnfot3P7\r\nYHeo/+aOM7N+DByrfyIREOyr0ZsC0gCwSEBX1fmlLepJBK6Zo8lc82GyYERk\r\nvzuA//x+fQv9tGpXOk5izTWbiBWzdnXVkd/CuxmxxtqAQFJW+/lwWgb1lEPL\r\nCKaHBtXHHRiy3oPYQ6ZEsHE2VSc3m7CNG70vCHJVyDQ0XxpTXPAzK3mlWnyf\r\nkUM69QqZqRSGbA7HwFGU6zJ4aat9z1hthxM=\r\n=I2M4\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"e903c90927a9dc062ef0aad5ae3004b556d4cd26","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.50","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.332+e903c9092","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.332_1670619817066_0.4363822938019488","host":"s3://npm-registry-packages"}},"4.0.0-canary.334":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.334","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.334","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"5b451185a4c1c3b329f23b96baf2a9c4db186e57","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.334.tgz","fileCount":22,"integrity":"sha512-YuTsyI09AL08WGuhSeG6Qi2w1ifUvnP7A779AfSdw+npUfDSjih70HpA8skauSIPdw80+pMDRb1p4MVqC1k01Q==","signatures":[{"sig":"MEUCIQDunI17Xd0o0TgEU1dNnX/O+gaZhNyd8Q7K9Z+uxRNTSgIgJqi15GkgVz4S/HgJzqa7r8YP2yjEWH6LOcdB8/MaYz0=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157063,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjk6LhACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpwQQ//Y/6kRfd9WswWw1ygmIzCOA5dRVNX5Yn06EDR0jO4oKrQWCkX\r\n9pY5NjnfLxBm/yNS2XLh2/GYvITTxYVeIcD0UMbUQOt/t0KBcvCYMTyo/4HT\r\neLelV6E7vKYTopUZlPNh2dLyJTbCzqMgR3nEkZkdWpsKm8Ybp8ahtR861x2Q\r\nLHBJPQOq2Pv7HarTAFgngRFsslSTBY4NT06Ascvv8eeN5XxMUQeJDrDcXBEO\r\nkHYkYM0vESzfLxARYkFIRkqAUXmmFeTTNvnJz4Xm5GBEPxwCMhbsv56DyX+6\r\ntBZDEmT7EJMG6dC40roRmSskpYJ8MexDGn24bPx0R1xI5ELkLHXrLB9aKWiH\r\nJUfhA6S4ZQ3cTbSyJihBhXnDxu5r4kt9gBc62ouBQh+7Ax9TA9yxFgOLRKEz\r\nMgjOoylpUXsGQ/iOos54t6cpkrgW0T9+eVXO1e3MaOWXUmeCGtSnaC3CEnsP\r\n+hKnt+0XXT+AEPmVXYOfArOnFbn2CO60iKzkGsK0UX6Qr16OWYwM/xQuT2lv\r\nekqf4QKSnWyixfVKSEWaiIv44Oq6h/W2wsE8ftaktVJdGvnSRFSups/Rwr1D\r\nOX9v+VB2Zqm59gZFfiDFsVsvm2gESHcnf/y/v4jleX7SYmtGlvvgi87CpSO5\r\nor35ewVBujA9HRj1NlJAmVTCaImSptR+Q6I=\r\n=d4sX\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"d305bf35a9360e6227d98e69a273ba38905b6110","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.50","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.334+d305bf35a","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.334_1670619872881_0.8057602773414032","host":"s3://npm-registry-packages"}},"4.0.0-canary.331":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.331","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.331","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"0af2d4dee5cde249013f24bbc7cc7d6452365ec1","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.331.tgz","fileCount":22,"integrity":"sha512-LWkd5MuajI4Vt5Cs8IfsO/oU5F+bHnPGkAOdNAoUh00CKjipzQOtSEmNC/aDwN2yofXLPhP+6v0E1+QAmeHsCQ==","signatures":[{"sig":"MEUCIDCoQq4MOO6H9BKslsSJDWU5WeYpvpQ5BBCl/09OH+xBAiEAzVnOQrxMkh24htN4v9zpxe1qfhkv1JZNxcHL+WAaaic=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157063,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjk6NtACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpTGw//duyO9GOoaEuIZDPbYefO7L9UEBO7GrmbVsBDyOclAcuER5Dl\r\ntiLQpJpV71WiOYQv/xHHReuapxZc0mvEGiqnVQMi+UaVQxxAVxsdMLGMiZDy\r\ncc9T+STzvlc83aYBQYfjXGbUWVKdyKRF6yFwJcZsQTmQgy0ziioVKyuYmpBa\r\nBw4edxJkqkpNPiomoeX2NaEosYDAMWXOuzUiUlJNuf7FqJ5P5frYcZTkg1m0\r\ntORz+aU1yurP8V9QA1rXC/wiZS7hilQ2e3SZjzFGtlgZzOWCEKtUr/kNHhJQ\r\nbjNLjcnD6asyLtgVdmr2wz+DKI+SQAITr2ERGaGuObK+6eK7Y/+s9pxASLHx\r\ngkuXV8KKx5OvfGbHUt8TE/S614dZ63bdvzevUpa1xi/o5p5i680d8nWd2aS0\r\nSXBdx0jgPUuD7zX6X/Gxk6FkifM9UbzUWwJrgkmXv8axSNhdYLt7eTuD3Q6+\r\nbSosixAWonvGYPymL9SrWs+yPGEnF4cyZhVHOp8Yro8MYZEnzjjhoW+VfeO4\r\nPYvMiQVoq4UmQd2JjHuisQ/RJBp/62Ra1ITt4af9qHdfkqf8kv++ZxHTPS3X\r\nflg9GPmu5m97n34O89ZzHxCRjCdwLvdQDr/aWA+I//MBkOihh2DwST8K2OdU\r\nLLxoj4QfjLqkYBRYXKXM4MvwaRZnNpR5ZNo=\r\n=zZVa\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"44e28b657df90ef88bdf63c2b89d1c723d739a57","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.50","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.331+44e28b657","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.331_1670620013658_0.5638304601303741","host":"s3://npm-registry-packages"}},"4.0.0-canary.333":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.333","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.333","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"004bef879d336c1e16c28bee5794e3714c47392c","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.333.tgz","fileCount":22,"integrity":"sha512-VedMUTudL6I0hsc7C8YO3VYoOxMFJY2GHWthAMpUEacq3E8pcfd1koqHPhpecS/xtFXxe8Sn5pC3g5BX48C/nA==","signatures":[{"sig":"MEUCIAyUBt1rzfyvUt7cthhZbZBeG/ufWWnOyvMatZJT/IQrAiEA9jYrjS6SSIVXzF90wZjpKj+zP7cyBw+o4ATrTgGpPBA=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157063,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjk6PZACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpIlw/9Gl2dWKEVhXv+NM2BXDbGH5sJ6W7o4rEuJOWSUXDpda830AR7\r\nlued730Il0NBzOCfb0B47LVluInTEPfzJ8YgIja8zX4Cl9sczrulajQ3bgtu\r\n+XIWGlMA4dYb7UKtExyvfj9678BrCqbhS15bKSN0gyC7EdVlcMLIRnleT9mb\r\nBJTkd9q32aSKs6MUxi2RcdWfwYPFvjaTArk1ZVoOH1wlupJDNjC76SNW8HJd\r\nn4If8VTA/2qM1DsrI0XAsjweyV5oh2TE9ocxS3czYyw0jn2ZYM5lnmxcNSSJ\r\nyvTKM51Nu7AokEhMKJvIwtmkvUyZmbBY2BIsvI92/sHC2f0POdJ4liD+Y20n\r\n1FvieEcjOOQ4Se+h9+TunpeLNfIu9IKkFegBowdFFCXUmVPcsrF9sMeHN7zF\r\nqfwGrUYjbJmYXEV4KwQdEATtKWpmIEhEfwCj4+FmWZeHgGBitt4+xUZnRaSw\r\nrtJuIEqPcV9ztbUYo1ZhFhyGgDO/ED641hDVzDMECtnsCK5IW7CwF52yB10b\r\n1kUJZI9mkpkir/uqMTy/Ddn3TO4IYqGDjKqhnz7QxWPQIaOLhnsuewln5eDe\r\nRxjoPlI91pzQlxxkHyejpLtCnxBs++yv+hH6etzgOwflb4DTzlsRL35JQHno\r\nJYx6nowGknXjvgcaP0Aoikp0jTOrz/Pc7Ho=\r\n=h0zg\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"61d5d587986092488e13d37ca3c65e052096c58e","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.50","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.333+61d5d5879","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.333_1670620121268_0.15578315559761213","host":"s3://npm-registry-packages"}},"4.0.0-canary.336":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.336","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.336","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"9e4adf00e6d87ef8b45bffe85891e3e0c64bf2ef","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.336.tgz","fileCount":22,"integrity":"sha512-/TxjOd3nOCrFFjP7FfcPWxhHVrafGglpskjZBh7z/+ymhSIO2CO6m4Y/T5JmJYrzqMPFoaaLUEkup1tv0Bwd0g==","signatures":[{"sig":"MEUCIEYuSPA3YZm6uuJrQlnResvzwRK3eBzdcU/EjrIhOzXTAiEAjrlRtQAbxjkp974KBRybuOKVeaxrYw638MnMSnowz5w=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157063,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjk8RNACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmqg5Q/9Hrp1/ooXaT6Ehv4Ma9Jwf49nOUAdP71Co0kfGutErAyCNheu\r\nfhHXNlHcsxkxGAbCcyWcJWCxom5NxxbxF4pcP+hfrxIbdsgKzmVo1VR3YRYS\r\n/rOoR88SqtdV6FErDYY2Wn+u5q+ZWxpu7UF/xwSQZ31MZjuPsQn0UwprRAeT\r\nwUBwFEs8orMSKnAqePdnFd2zFxpvtgfQLp+svv/XvQHBaSu+qbTji15DZwTP\r\niZA5Rv0XBBDm7PVvQUPya0ePXjxHDv+tL6UIVCF3fQUnvhaCeSozqFqr9RnV\r\nUwArSoFn7QqHDXopBb9kGF5dLJaTjoMRSlq7OOc+Tu/2a32laJm/oNlRySu7\r\nJPAk5XT+k8fb+3thk/F19DllCiRuXkivDcmiNM6A3BZwnQDC5qLw9Z01GqqH\r\nNLRqANnFKg37JdvLqr8yDmoVVd/BzzhOoMZdWYw8+jtyzy6TiNwD+v/EMUz3\r\n8+MbmwZjXISlniFhSG3838cJEGgpC+oMNMwYBb5nSx9RF4qnUlm72Kb8oUY7\r\n4HWeKTfbn9KTezrWkgjo1xHCN1JQgcztQgu3U78QPRUJii48t5DS6MLH+Hl7\r\nBNMP6BkA7D+iCRzmVijndouHELJ1ksxGwi3g8fRVxG9DhnNiIaK0UBdbRQXo\r\nn8AVWPgeG7ayAmATOQ2j3vd+sdKEMHfIwzs=\r\n=1jyo\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"6895e7286184d2ae6f2b6d3246d99774bd193891","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.50","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.336+6895e7286","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.336_1670628428952_0.2742999407747151","host":"s3://npm-registry-packages"}},"4.0.0-canary.337":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.337","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.337","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"ff0c5c4bf55449b2c7846ccfd35e56f66f2ae946","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.337.tgz","fileCount":22,"integrity":"sha512-Shbej6sZ1/JpombRjnzPs75me3VqpK5RaIiUDERmVslgN5bgvKkOvttNAwe/Ec+Fq5+m14ylRq0bzxAMAGlcwg==","signatures":[{"sig":"MEUCIQCe1AEGut37Jm5z3IFkZBMAgsIuUSohhOU5WiehwROqbAIgXF9f0GdMjVsf0XKnI5kKzk1pRuwC2gCHrENTDhPCb9U=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157063,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjk8TdACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmocpw//Z+uLyJXqXI4vfpxUoil3UEa9JkZnvQM2HTGaWYalZEiFyRc6\r\n5E0A0mGV7TwrdiVbr9TATT0CdEKfIB5jS0Dgg5dasjMsM0nP+ABJiNXunmpy\r\n945w5Stnnbs21tmZGxxGiu5zLEPy03u0wOuFJ4spF8nXcVBa0oWOjMjGw/x5\r\nJq3MNwibsW7PJ3r944+Wn/u3JMmfW8NOJUqAWwhFaxb43/vdzjo4xkOYFlXJ\r\n0/dN6QTsMQ21Y+ekmkgOH2eR/vKIqqbo0veZMI5Z7Ysuo7+IXoibHN6Xl0vt\r\nNMJbwZPVnU6DIpF955Iqkb1qlZ6jnbMVKxV3tKm/2Rs6FMnrA6+EVaSpVYgD\r\nG4TpYLHKp/OkjidmHH6uayt88LMuUEUrtKqMMW36gK3ieW5XOILSGPjZu5wr\r\nM1DzSgdjAJmj531hlD2NnDFI1peLmzywNWWEpWfgqivmV2XeXFmBhrKmINzd\r\nuJu+cLUEVyqinoPBKWTTHEjHqlsSVXETNKp5Mi2aEkT3vJinMiG+0aFobgSK\r\nuh+mTaMBCv+cVvEaeKEFFaVKJ/C/1G3QhIc1IUevc3ubAUdwbuQzrME3ciiy\r\nPE5hZMyd6tdobdwAZw5ikzHdmrDclMoYRCLTnzOZinAowriCYwMANtucDUxN\r\nW58PEnKqdfjx/3KKKjIxX18yPpaUW4+yhr8=\r\n=HMQK\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"44aa04f7607cbe08db8ece83bc1f24d39c512c26","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.50","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.337+44aa04f76","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.337_1670628573327_0.6480581627294562","host":"s3://npm-registry-packages"}},"4.0.0-canary.338":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.338","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.338","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"3910dac893ce098d2681ab5c725e81c21964a0ff","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.338.tgz","fileCount":22,"integrity":"sha512-KjO3zDPEUWWdGUlz/dSGxptelba+Ys2eR8HXtPmMPR/YkOviSnTGNC3CNR2ulybwT6ZQIktqnlG2WjjOjqeKDA==","signatures":[{"sig":"MEQCIDQGMb+3h9HEMMq3zaNk5GEM3oP1p3uWBYhfZEUFUD3EAiAeFBhU+cknsv3ZeRGFhtZwmaqtjD1rpIJaowIxGrTetw==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157063,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjk8UsACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmq4VA//Q8nSjfZKS7ezJm5eO7xd6jezRYt4DspKEdru9JSSUqZkQDEn\r\nJYu71PogoT3iIeMkKKjqup8B0fKTHqgklYxpdGyAIsxplH/bBJMOD5CrktDv\r\n9iZ8S0DSHDB08Mr50OC1PLbNOQNLmCr6sbQIsFBZdfYJxq0CHsQr8Vodkr0n\r\nCocINjySl9qKfMhl/1pWwnYtNSTbK5QHj4VRwCs3JiuDIyoAkZGxZy5dn4jK\r\nQ3OxKwbSz+kARrqp50fBj7lFM84yoEtcPiYZN+nFwu8sAmgJ+Eyk5DijVaXj\r\nfiQXer9D05kLfTVPGX6ImzjyzjnkGgoYwsyLUs065WE+vWe3yDVrE/CwIMCR\r\nvZ1QSHxMSQ2dJb3utpHaWxC1UHZ96zJJl8Dv8WIollC5Vd+WXugxNtZPjheU\r\nD8QPaKiXhSgB95LgqnHFHhf7a8z/O9tXlcNmDUQUOkBxGm97kmzpf45gnOG6\r\n63C4YebQfBaiP5eerkNBYim5NX0M05GkbhGfiyuYFtOifXZRl7fcGofHCQvc\r\nnIreApe2pmuQeR5LCj6bSP8Y1mBPVn5yWg8+3nWj8bymb/G/rQEtEDZ83res\r\nSgPfPR1e8bx4WC6OBdjVGq3iMyTns3oQVOADghtL5ZKai29+fgSeRAvs6KLf\r\n5ops4JYdt7DnhUbaQ8gepJqLYvh6Otakyew=\r\n=zkDe\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"afeff253347718480b822f961d0cebdbe094b3a2","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.50","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.338+afeff2533","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.338_1670628652357_0.3243490580210102","host":"s3://npm-registry-packages"}},"4.0.0-canary.339":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.339","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.339","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"4eb77fd98737f60834e0a4ec40079a4a750fd703","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.339.tgz","fileCount":22,"integrity":"sha512-ogyrOhc9qbmgMTR/HJg1aMDRdBW0S3AfZT7o4DayuJQv0SjDyjxpUDMcABOMtVNavviRKlfsxiQfR3kgDgxryw==","signatures":[{"sig":"MEYCIQCVPocLFgz+9ylNvq/Yd8Tvgn5mpzv/oulDCY8A2WvEKwIhALf2tnoDMYxuvtpJ71FsQNUkBnLXXUcgOlFx8D8plv78","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157063,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjk8ZZACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrMzxAAiOTRV5KyLHoMMbu3QSIcHaPNSht6qVJcZriA88rP/DFxqylp\r\n0LAls9oKVAJH74v67hewYuZUJvMLa1D9p5QimcDbPbyJ9Pqua/2hpHtmYruk\r\nCnVZMXkK8dIaVBBfxKtSOBX7GfQHbRE1kyavpR2L6I3lcz9af845M+5RZW9z\r\nJ0Hss9RlNIMGTo1+XDZS8cqrLjVUl1qgf6SwwkKzPe/8igL4TUiZiMtanl8I\r\ns4fc1oNmL447GI7eaXvbhlAwY7kUmBbIHCjMa2sS9HBj4+Mqkn7HsOzgv4PX\r\ngJ8VZ8F9IpaDs4Byz/A8FF0xJHfwOcFeS4IV4C/Eyo0PAIcA6RrkZ4QTADWe\r\npufOQmj58qj7QLf7d4mcjj0aJ/2KAGT6PWq3aenHnUjUEiU6/WefWzC3G9LS\r\n05uXL+cJM4UpneS//JQ+f/T+G8Xt/x7VV2AMjolaU48f2FrW/HSJLrquljVn\r\nQQThmiPK1j30Pi24N7g9IUvnm35xgjxkNy31Oz3ENpVf0S9b2x9GstEboy5Q\r\nRCj1scM5QZK2YpA1ameKJr9HERhvfLUjXoMQGKSbIg9mhtCxrjoRzPupQ1Z5\r\nQM5NrXXfwk3QALwoebMkCc5KnZXndimqgxSuCLD992B+VG9W/brvJYh4DQq+\r\nXoLom7dcRLqs5yxe7pYJbqfugtXeRAQkuxU=\r\n=UQq7\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"43d21d1952978944cca731fcbe862454c5ea0b43","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.50","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.339+43d21d195","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.339_1670628953423_0.8989611484187168","host":"s3://npm-registry-packages"}},"4.0.0-canary.340":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.340","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.340","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"8d3a636f7216564708c31066a8f947f31ce54f3e","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.340.tgz","fileCount":22,"integrity":"sha512-HHkmQWS36e4KKJR/QavAvTJzkU8YM07ZMaNc1dctdHzxr7USX/b1GipFL8bf6k1U2LNkX8Cv+IySCXiGkG+b8Q==","signatures":[{"sig":"MEYCIQDwEDcO1NVBsloij/93S5GV/aQdcXWbtuW7ZJMQsSIQlwIhAMxbtJll5NDw/vWSXwc1NOfEX4ZQsJNZKxEpQfE8yXYW","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157063,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjk+3EACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmp3Tw//fXbpWQiUYl/KaBbBWc0L4v6Aec7mnag67eG8n3am2UYDUJZ5\r\naLYNnPcuDXCE+qJPPlA7KO+rSfVUog8VT29Bh/ZSAFKoa3/UuM9mOybIj+UN\r\nlx/RWvyCyxlv1stlZkMoomKHFcf/fTGmebdXbcG2tQthCnanoRZrxIpUHWR/\r\nr7T4Lfm/Nw97ayqlizCAZ3OlRCkZDYbynGl055N1wH/7NZ03e+tf0e6KnXFL\r\nx34V9THAPQTzpESWnWLLIoK6ZMhy10sAgR078UCRD5+deA6PYetsGmXhRsbv\r\n+JUxDmDYcv1Z3Hm2lDmhphB/KElQv5TwfLMLDJpoWAG9DRFhnHrbLTrFw7J4\r\nkosFNwcymPYFr+e3n8c8lV/+lc+8UbgnPyzDdf3J7K8UdhEAcD4i3f6G1g5m\r\nBps29drgZ2HfWIy8cdGrmXK8J71dZa4PEcZST2OmnmQulQrNqdmsS+nrmPSC\r\nvi6Gfhmum2Od9dEc7kS9jiRyW2xOc40MTEw5iThqBj3lcRM1i7hOdZscSaFY\r\nlhPRKFi4pyEXl/UqJLbHucQ3JyZycetlgEaQXb8CrNLFVb0Fkux/6grX6aKg\r\nwpG8m9Z50RjPf6jp8VBvjGJadZQNVq1ixn7DDoCAeH7wBepJ4GlRAZw2mDgf\r\nYAk8RMjV2wbpRTriezAH76pzQhtg9E6xETc=\r\n=sv7S\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"9696505ffa17d93d2a333ddc257f8af3a50aed64","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.50","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.340+9696505ff","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.340_1670639044491_0.07988111416140509","host":"s3://npm-registry-packages"}},"4.0.0-canary.341":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.341","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.341","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"296d171583e78b9ae453f76951290fffa1a6371e","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.341.tgz","fileCount":22,"integrity":"sha512-OszSCOLPF8+VvH3uxwRE8NF4ay8QxJDy3PpFpc2atnXuNtGG9RwDZAmNx6ICYFLpESpF1eQdPE7Thxt8Y2fcMQ==","signatures":[{"sig":"MEQCIDTTfYku13TrVlsKxDs5XnqLILhrw1VPQhzmZoleoI/wAiAmd/eYdNOyZbLGTax5apmUyqQjqyD2nHe1o8exJTkNNg==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157063,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjlBKVACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrZVxAAoJT4fAI3I+ROFi0/ngizTuDHx9tlCBKVedYVQpNjMmkU95Np\r\nOZ+o5WIb+qlp3wSGLvhr6IRsFApKLiDJAnKFVaR1J6LpW8lQERn8Fz7N5q3/\r\nAO08lIyFjZgq5cMtVbRoRXUGaAp1uCKAhE/iLAIOrL/A+dXMPnFkj/7NrW1F\r\nnbKJ+jOyORSFjI4FBPP7UewRsEMteokmWnsaZ3pJVXd4mIgTbftp68OW/MPB\r\nvn+VSL2SD4yONBv8cLszbJNa9Po88+vbjogxd81YHt8MvQ1QnynApxbaEu+u\r\nxkYadY3iKrCimvNCU2w8+/xgGBwD9FIn191IcgN8kZsV7NTcTb3GAQCIqlMO\r\nYD7lI8+uwDnRrBstgQRzC5IlfjxKix4LD5C5NwxVFZr+n+AQTWf1KZWQC1k9\r\np9QL9XxV1XgpDYm2TcU1jclGyM7/d5ZGbHUVSIolWoJCK1iASALnuHTswO67\r\nBik3Wu/ywBSp8O6D2Pcgi/ZLu0aIOXel78UJSaD/eWB6pmgsqHBYwC4SGu8j\r\nWa/7ibYXuNHQ0B5W3ywE8Bk+6Cc22jApctIsea5rbmR5VUSbJOuVMw/S43NX\r\nrWR8+8h588Fegsr6cR79gmGEpNAz/hsireqk92OsmHIhawQs+2jSeH86h7JB\r\nhOGzwz82M16BNmmoSYehDo5mvdzYks214uk=\r\n=fYDg\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"8cfcbac57d23b6a2731c75fab565c1fadcdc03cd","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.50","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.341+8cfcbac57","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.341_1670648469260_0.7128176785789189","host":"s3://npm-registry-packages"}},"4.0.0-canary.342":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.342","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.342","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"2faa64e4b85906fc587b54ac8ee4f0dfce21d3f4","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.342.tgz","fileCount":22,"integrity":"sha512-GjMrzBAd/DAWdin8MTBqp5pBl7M36T/OX9K0Q7hXCVTCbM0Ge8I7/yONFq7REF6olBDBR4MbR2Zbq7BaiqK5iQ==","signatures":[{"sig":"MEUCIH1O4uyOvLwsUFgW6Zw8ZhX7w6DBpwgjHdSRcK9pPqOyAiEAmxU6FSqm7SdmZHpDH+s6029bHqPsCq8mZJw/LTLtFuQ=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157063,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjlCUeACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoCIhAAnyQnKqFqY7M1GZMCKbzJRXhlGWgD1xnX09QwYixucVdiPt5C\r\n3MkEsuLhWX6Az66gxrEcGpLOaxswGA5iLzukzM7Lq2MlyWws2TCZR1JMRUap\r\nlMvtBCLOgMLgkRMb+NdkLe4yG4bggAcizahZeY5hEIKHh8nbZw/Zdswxmj2K\r\ntn7GN0dC46YTU0qIL3HkKTHsaIxsOMOVF4lNnSwkzUwWcHYLRpodOfJo/RAX\r\nn0bfIAhk4SJ6InpxIeE9QvKXRDX7DBUe6seaNpBVmcV5EPloMUJr6CpxwKcx\r\n71DkD0J6PyHT33vGeQJ9R+V+8W1A4SqvZ7dYVgQhIQqZ+Mq6ykwIyXqKH6YC\r\nawwNoJ8P0Z9DZ1oImYlziYEcaryunhfhFg5rrsq+dw3IN4m16lHBvyz/Vafe\r\nCqMLOSUg3B0IKR/RneiSXlRn9y2z5z9XyE4QqcBvSy7g2mYUzTnVQobSVPod\r\nmkgpBLJS2DbUaZ7eHPPt4bRqBmK8un72dNsm2R8Gd0vRezIAzA3Mv1yodOHr\r\nZXpVtD0ghYwNzDO8A4HXxlSu2+viDMQUDp7gn91v5x6b3c/69x4lFdsE/EvT\r\nAXkbJdcuKRLOkWoreqrvyhIXsNpETdh7jqhr1W8RpnOl/pkRKuHGrugrUNN6\r\nbiFc2IyL0yYlojeqp6cvMgG9+EBGO/I3ZR0=\r\n=k2Wk\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"eeb4fda1ed15e9e141957eb7ff654544abd31b3b","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.50","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.342+eeb4fda1e","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.342_1670653214333_0.6818107610846063","host":"s3://npm-registry-packages"}},"4.0.0-canary.343":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.343","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.343","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"4305a0a71d05f65182bfca418523da055c6a04d6","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.343.tgz","fileCount":22,"integrity":"sha512-UDTGjgyyx7EReucwnXa73tqhXtvWRej+jTxaFYl3CUkQB9Weqj4VZoY/V7waPpR2q0nLJ09WkPOUeYG3HcJwcw==","signatures":[{"sig":"MEQCIH+Uwbt/4eyG3zIkYBvOlKDadEccFuWVFrS6QpPBzjYQAiBEkfYRlxra9G3e+A1K75nAfaTtPLkGjPW9UQ1Qv3zmpA==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157209,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjlE15ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrvJA//bf3AYSPB5Jp8MsYkqvIzOwLlt7Hj0IsIbAgRBLF310nkXm9M\r\nPiHSnBU7fyGtTDREcGh+111H9edQlt3Rpp6dxkLrYKbkp9DJkukKJNIh5eSH\r\n1teNX9BzCDmjgCudyGXmjPZWEi1kcW8/91Uco0LB/c33Hm/hznb/EoxGRQb5\r\nLeML/ijXbu6Xd9EcwguJU02ZIzG1829tAo9uZtq4OJgrN2qOqcEZVkjy0ba/\r\nrLB0CHRSBdIRfWEDR+mb6vMsSWovL3T/rc9kvTrNOcYmTGYGUZWND+Xwun+M\r\nTw70YJC+bKVYMvBJ7QZIVTgEq/DMar9LvNTcUF3QZm2oAULRB+1/R8U8EvsQ\r\nURl5+i16lYNaYtq2o8v2rOdEb8M065RwHk5TZDqJHsO4lYimrxyQRXQn9xz2\r\nXlaCqVD1biosuxFL3ZjrOa7iO8+foqBntQRJ59iu6Br+qQBu4Lg6sE3kMVDE\r\nM4kJgjRCW8UepRVyhbI+LrdAfeBozq6r3EewC2bWzGiJUd16MHH4Q5Y9vRwY\r\nbYfUSHuI9Qwh181s0xgrteXoQzh2Q4GcxhVDFNZy0FB6DkvhhcELgGXN4Y2H\r\nJtAj6Hjj/rIBPu5Q4ynRPTttLmP/iOx9YipIzYdRAFCTAM/bDSePjlMuPbmR\r\nH1H65xknZVJgRa4Yx+lOYEvv12BmjsscW68=\r\n=TXiH\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"62da2df8e9734724304a8a013b0f3ca131df60dc","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.50","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.343+62da2df8e","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.343_1670663545155_0.3897215259208373","host":"s3://npm-registry-packages"}},"4.0.0-canary.344":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.344","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.344","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"c19e116bf5d8ba2001b42768a9fe5ba324007a57","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.344.tgz","fileCount":22,"integrity":"sha512-MWYOzeggwqbXkN+E2Jb5WbjIdEIKHD8xlJBm5skN4M4cPSePsc9MWhHuZGnOLjpcQ1vP9Xk2S6/3hnjX6G38Kg==","signatures":[{"sig":"MEYCIQDepoKqB+Wfor33cuyM0+N0yOeRJfc/W1H2xP1S9iNFkQIhALYEGvJ8cIcazNnsR1b6BrKMeD8YJyyNvJP4Bzc354BC","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157209,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjlLIhACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmp5lg/+O5L36VVjwGKlcFWF4YzB5jwzqB2f1YnG7OvGdU6pB9L6h6uv\r\ni55PR9S8LafzkFsuKliiCN+rDM1w6iWYsD+yz+VdATPDw45GjLj3tZTgOXB4\r\ntWsYtZ3iN1Y78UUIuoDQ92fsNl7A588f8uMCihaONKCENNAFcYMB3pCrIGR9\r\n95eCcMoehTfUBac6n8I0aZvQEckWVLX5ct5k3zCS2P78xZ63N/Rg6RgmZLst\r\n6ArBfHtmXQgBQiGA0ZDHZfLcT07ZgA0YjyG0ino+mbPFyzVXPCO78Neb67P3\r\nkLr0E8+L/q9/8KEXp8drL0cpZIxNVVSYaV0IvxGmW5D3P23QuUo8hF1F3/Mw\r\nas4DikFSoTPUijosYOHG02a+cWP+sqwGzl8a5YqtvWJMzjYFM87apq6v3H+i\r\nIKOifPqaAvGOG3wnR7PF5YMgd5DASrkNQlekFNe2PTn7Kw5yjsB9fWkcp0n3\r\n7ciQfPwkdboq1/rlMpWkgc+xuSneNGQKldSfWNqyAy+gE3JJdfnlMxCAo8l+\r\nXBaa+3J5UpI31zAvctX+nqYgZJ6s9FI62Oej55FdRl8JV0Ze3Q5tclReEFTp\r\nVcpIBjXmauPLRB7LVj0Xn6+2Uwo2p6nznQtQ0/lCg0dACX0XOMw/oYtL3l36\r\nWW7JO9YMBnDXkxMIANf650ozsrBCmao4RjQ=\r\n=7F9h\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"8d6664cc5bf9f760161ae8cdcc3084612d078943","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.50","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.344+8d6664cc5","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.344_1670689313396_0.9305531832739906","host":"s3://npm-registry-packages"}},"4.0.0-canary.345":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.345","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.345","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"9137da8c84f7cdb32c7dc80d61956145a80d6bb7","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.345.tgz","fileCount":22,"integrity":"sha512-wDdHNy37LPo3Uj0kfSiACSrr7wHxxkKW4CWnBB1KYkL4+93/IXenPhTKSOI5L8K8jvMOty8LSlR21uvDctoQCQ==","signatures":[{"sig":"MEQCICd8EbxvKWBesUML/PBXBQWTT3hVWXZA4v/oU9Mc8VdNAiBwMdBWEQVtKQoqWTHHi7A3V7rVbbT6TFcrL1SKxBhYWA==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157209,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjlQ/pACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrjNg//ZK3Q8TsbbVfYFaliho4AqLCRec0IXi4RW0nATnhCSy/wJ7P5\r\nqI6rFxyiOnVjQqOHyKNxlwsgGxeOVJWBbRf23rkIlnbFvY2ad3DuxkVRMiKo\r\n01CTrlxmcdvs5y2H1Kf7Rt3Zsg4ErIA+s2PHWgyUQS5t6+n0H7kk13zV6w2+\r\nNMUGFZF7l5qH4la598gFEKPJOYSI6KT4RbJRKUulgzudbWyGWrSsRW9+kNZ1\r\ny/Wyyxqc/dkM59vmcAeOs7LvC4aBzneJ8YH7gtGcv1FFPPi/fvWntSfGOi6E\r\ngOYtTuzl7ApLfvh8DlPz729MX6CBDKWM7uAzpofsOe0DdWpPpb68aZRdN1ds\r\nlI2a+Th66N5ko9KlyxzWXdFouLW6CrYCkvEV5MIdGbUnlLh6nVQ05kRWIFWq\r\nLL2xSV7eNYXG8eMcv4rAGBetX2i/syuVmUWXfRKl/B4rQDRQ/uyYjX9Yhkk0\r\n8TdMkIE6DXH/mt3ru9YEbQM3jK2LlEDfgvVw4FDkvWyS0Ov0riR7UGm1s/MR\r\n3pR14MpgGAYwzabDOfqp9WAuBcTZJDt5pvGL+5Po/fj8dJXu054T5+PoPBAL\r\nSr8vzoZkGI5CVxM8IbKON8G2g4xQJ85mVT/wjbOAz+Fd5BG3BzLyJvULs2mF\r\nP3Lm562RmCh+PsxrFyy5j0xEXmkOQi7TWGg=\r\n=2AEc\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"ded69a3e9362bcfebbfd6b8be56e46441fb52d68","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.52","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.345+ded69a3e9","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.345_1670713321781_0.3507907902465217","host":"s3://npm-registry-packages"}},"4.0.0-canary.346":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.346","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.346","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"7775f3e4a06ccd002c28543479822b0177877f3d","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.346.tgz","fileCount":22,"integrity":"sha512-HRvEh3fk7RwFXi8vJSNtEAVQR3Gq7x8IPHaXeT725l5bNDqF+mtVcc1scF7MTisY86O/GjheMvF2ZMbgHqz8+g==","signatures":[{"sig":"MEUCICNjrh1tcNAynlVtOM9PEtixjQd6SgyIuRyOJOXAq4EBAiEA+FYGRm3Gsim6Plm7DaSoLqRNjMbG57j/0SjbL2FC9g0=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157209,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjlSKDACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqM3Q//QuWZbl8uKQ+bLyJO4nZfdQU7As24m53DJV2YSHQsjDrXTbEE\r\nd3FHOYav8bLuhNb57WU1q//LGvmaHUTTRY7rWTBrTVHMGnkDpk0DB8J2+xJC\r\nOJc2MDdpCCX5rRmx/to/0lfo1G8PyJyNakJYOAoFnRs3Jotv5KMkcEuUUeGY\r\nAus/qOJgXVY+5lIFCiDBYcIR4mtqqXbSVnkP6Us0CsyFCVc4XdGIZ0IscjdJ\r\n6nlHf0QvMzShbR7BLsad4ueuCbFiiiP5HzpquPPfAMd72IrPJ9pvZHXVO8Ob\r\nK9fsGnMNxwHio/c16AH0ZIJcolbOeUIPO4PQHvhuPOK5hcH7Pk7i8TmUZ2/0\r\ncodFVoSBW2ax/3t3n8/BPWw/tMOQqBXNEjvhNiTSpq7h295JmWf6pUD4//Bw\r\nkiKRKlGhLTaxQbiCJkbB3UzPU+XqSyfKtucGicOtac2Qot39FvqAKnoV6s/B\r\nYV9Mw2yW2U5qqRhDFhbj8c6zXN9IMixkyAQ2FCqG1n2lXqGa0SUOqOT8VNvd\r\nANroj9PNLSCPDIFsuZOTtQ+Kds+8ka23jVaVK70BAaF5KHC2DnQb5SBhthVT\r\n3FlI2NpGddAVjB8u/EsQCB9EW4+1HR3P9jd2JhUAE9rnPTPpN25TWkEvus62\r\n8jiLau9mFMInwOTxi8uyfOqRr+ab6trM6sY=\r\n=CMpY\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"871addd33b370b11c21c734eb59e53a9ad7dba58","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.52","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.346+871addd33","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.346_1670718082902_0.4685714777750918","host":"s3://npm-registry-packages"}},"4.0.0-canary.347":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.347","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.347","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"c007358181978b07b1282f906c82bcc9ef0205c6","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.347.tgz","fileCount":22,"integrity":"sha512-msd6WIyA2EF7fZuY8n/piMlXj0Mpu6Zok8GtDZpT55Qb0y+9yTiWOVUMR9BxSYwFv2+KrlPodrLIRlRRj0J9DQ==","signatures":[{"sig":"MEQCIGrwRD+b+1D0bIYQCyqFgw5TXINrEX3i6rvm5OU9QamhAiBt6IMQwhgEkjvozDZFvsH/j04nTDAki2UXL9xV8VxeIQ==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157209,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjlVCUACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpmCA//Swb8X5cez6aJzld1XIe8odQXU/V3uhnyJAXiQsCh7SEFnQ6A\r\nF8xUkMAieJcx+jYolnhUGipbAV2wg7dcJOK+XEPgDuk/LdsK87DKlE4w51Hw\r\nReVLJg8u7g+Ukk10vvPClhhl4JMQNNkja7pQ5Jl80gD/PFK2sx06MXnLgylO\r\n94mCNQsBXoCgK1/lOLyWIEmKKmefl+w8GwXp+ZauqpGCrhtDDS1RO91PZsqf\r\n+fHQy+AcmZqREB/jD3aoiWYVcvBZH3oubfKaOe3nwTMFDzow8XR7G2PAobat\r\n15emAODMLgVHMj3LNQ5vBA5Q1wOzbhX333qEvIzTfjZbFUE+A+XGlCFhdYJY\r\nBAekr/h3cJgvfkCQSFvVvM9JL7KFs072gWd/w5h8C5eMgewz0rELqUYd252Z\r\no3DQ60fE2qECFNoBJ6/reFPGyaEACW85dTzXXihjEFE2S1kaVTLk2Ff5XslW\r\nf6F/6WZmQJEipdLkM7sxaNXhtNeuDsBZTSvIlZd2XNN52/w6Hn/rUPWV6FjJ\r\nvLJEn8CYvGrBYigKYhqsf/UoyQlR+zD0HSq8FXez6QW9Ne05x5yOqjgx2FEb\r\nyDIWpZsUW0A/TVuK8Kj8ECpxsZYVRxzMUnxq5XymFXvRmmHO5g/As45aylr3\r\nR2DjJdkdnhHVExSpO4g1vNckLhTQJIeQAlM=\r\n=6PEu\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"fd44ff3f552374eca00d6d881e7e75dd25e6a45e","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.52","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.347+fd44ff3f5","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.347_1670729876503_0.17146763366767326","host":"s3://npm-registry-packages"}},"4.0.0-canary.348":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.348","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.348","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"d40bfa723c08471ef7d40e2ac13da33bf1f7bbc7","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.348.tgz","fileCount":22,"integrity":"sha512-Juc1z2R4st7KBzuRHN+KnvUcjRryUS0a3w7MOGrSHYOFth0UdmsX6s61McUZFZIbSNyu1k7epWKDC9ssIkOL4Q==","signatures":[{"sig":"MEUCIARhVT/1UaBMnUTfBwdwfkxUZMTRW5/HJHec+rK8j6v5AiEA8JgO2GbhZ+Z0lfYRZ5Zss/nq4vwB9YOL2nuqskOTeBM=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157209,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjlzmdACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrmOA//UROG1LRDOH1C5q4pRiOcJaguzzX46LuJL1M88mWPel+UYLy+\r\n6/jkjWLcmbCPhVxKbumBw6V85rJEZwgeT5LMtiV8nVOiBny1XahP1tjb57Kh\r\nSyDfeQH91t+u5MEkQ4R+N87YAiGVk/h+mVW4wPsRYeAEFwzqsXDIhe3oz9TV\r\nAPNunWDHi+fFXFscjhz5T0FNESGJ28N/3emq5Y0ozH3sChveIKpZYVMaACiA\r\nmiw8JOOQmxmbsoXTAgLCS9iNCiXj9zRqi3gD4MKv029ccGL0GJeH83ejutS7\r\nhdh4iPBO5Dz/xcwHInLDiAzMhuI/qqEuDvpaGeQE5/5i8SFgj+mV5Hrr249K\r\n7fpVIVaJJ3QzorjiRpB0+WGWmlbCdD7wemt/7gMezz3IQfNLGChEYV0e71ZE\r\nTbD0fjt3AcQUyovj3x5jyLsx1XIr+d2IYcnTf1+PElC3moopsNdJzlo5p2eT\r\n+OSeZOpLSZYROADIi2o04qUiEqKZfLe347fj80+tTBCW7/T5O0zIA+f//FgG\r\nf+L+jdO/nqZu51yY768AmDYSHxesVGWxMuTbtJMSYcCjKeR9//askD6VCBo6\r\nu20pKSNEgZb9iWJe/0tH/X44DCbxE8faSd/FauQMjQqLsxvtdVMOiXH4yG4U\r\nb5+yv6vZhMcQMBXFf8Xwcz9ImS7SrUEWfoM=\r\n=I9sF\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"0071302ec6b0241f47925d480c41f39ea82340b8","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.52","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.348+0071302ec","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.348_1670855069325_0.07592946711483228","host":"s3://npm-registry-packages"}},"4.0.0-canary.350":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.350","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.350","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"3f2a00e65f849bdec10b5bb847430c94029b33fa","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.350.tgz","fileCount":22,"integrity":"sha512-2Ezk20DwTy+cbF6vMGxUz66qTAECxy53Ap3Wm8GnT+EcDvW2Hw46evmDr6FZox/2KxOMKd4rwgrJA/y9Mse7BQ==","signatures":[{"sig":"MEUCIQCaccwgkYAZWJzo7ty1tFmpGlsKkum+J6tn5XWowg34VQIgGYyt/dJ0s8N+oZzan5wLElFD2OU/pAiNyb00jWlu+qM=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157209,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjl3fsACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmrfqg//bea1nYuVDV1CCECnBaqYNxYzYOcCOfoDKh2vl2YTABu1az7h\r\n82NAIBtjM3iOzm1HL+MXeT7i9ff7c4HjtOjCuLMNz6JBPIbkY8ViIqOcKxtY\r\n8ZwLZ4upjgSzk1I406o+cj9Wi2v46+M5z1OZgtpGnYZ7CgfUvYAdVwG9Zw9l\r\nXpmAUlPBKWQc3sduB23GVWxuSMc6LdxnS/NX0uUHnKs/uj4x1k7pyAnUrrLE\r\nk59mXn53o1DZNrJwTL9jHfQbDTx8RjBXJXE2rHh4pnbxuVEE0nvNScJcfZgy\r\ndMlxAUCkMsf9rTAk2zlqUm9OMZrUT3yMcrmFPuEujLBiI3xgJ3K/RUbkrrMF\r\nMLxzvPvPkBU0ElmK8bTm87QrljWhcMWlxvAvEA55iqUsoo3PXpoLEwn32+FO\r\ndXTZ3Ft0PL5bRCLUxcY2FgbN5vW3MGkemr79B1fRdzcM57VYYNRxf95xciYk\r\n2HhIG/E7iTN7BuWDmD81w3/FGAus57rlJA/F0RPocmqp+T+qizLdy54pevsU\r\np1TG70MQdJH9wuBjYTGxt6rEMGgZ9g7SrT+A7WK/Eu35HHUf38kD72CIA8XL\r\n7qyIyxYS72jm0OO4teELOcD3LbZfCgTSiih049QaagT/8fBISAZZJcdwbjk0\r\n449Gr4aFr8ekSgSHma+VlLcuIYsvKYJg4t8=\r\n=X/5H\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"8de7b4460fe8b81680498a98b1c90c822fd1822f","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.52","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.350+8de7b4460","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.350_1670871020517_0.6980631212082011","host":"s3://npm-registry-packages"}},"4.0.0-canary.351":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.351","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.351","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"fdb328d4a8985928f1856dace133a7928515d7d4","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.351.tgz","fileCount":22,"integrity":"sha512-0Knfuu757f2kln9GwPE9O4s12YNioqRCH3qg/fsrbGKOqMme578FrA5E9oFamRP9GDJ6VG2zCerG2NvsvTGWRA==","signatures":[{"sig":"MEYCIQDxU6IbWGLlfTWH3BYuSTVbIwprC9ZuxWZXdlPyvlyLEAIhAKjnZFvCOVTH1AYnBuUCaR5UBQ0PC7z4A3y3VRvX2eGU","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157209,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjl4rMACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpG8w/+KX1S3Q1MrQnckI0IPgLpiwxOXZiSQftmRHoaX51QAzmVQBVK\r\nP3z1I1hfoQd0bplqK97kELCkk14+aalmftYW0M1aEXcHscOdsBrI2uSFuqwx\r\n03JwFGM+OpwhsqfJAOyCFRFCpDhnXSnVoASfpIaRBaeoXrHgu4jKdRabuewT\r\nG+55c3wUV9XEuHjsqhOtNUaJJY/nydAS+mDr5n1SFIb6KlTtnITDg0oDn2op\r\ng/rjMeakzV5ElJfpc9d2+Ah/DXVEQSlsf4fzekwVTYyYCsnF9VbfHVuoYp+c\r\ncQTdqdlU/AFpA1ZyAFLA3WuquGsp87Mec3X9nAMPURurNigkvSz7aNQ5AcxN\r\n66BXjhJAV5WSh20SIsnmAFzLdmSzPwAxfsnpHugXiA+qyEVmvR7/H5GijYej\r\nJ1LwheRkK8N80R3v7jc5v/2/53/ET3x/qhwGP/LFPiWdMIDMhVWx40xLkU4v\r\nqx4U6pqiDuTiF8emHMRD4jg/SKVKoAVd8IfocwPvxQLPeDL/GTa0ojgGs+zu\r\n+YSCZHxzioVtsADyDrDmND7pBt49svRoB8IYIWTfhLsUGrb8yK0O8Vn/Yylf\r\nPMCb8zJwN2fQDEk93w9JQYQfKuwobKU4jQhwwQp0bDrX2V7fNiG0r8vXamkR\r\nHkbHL2NscQ4p0m1rW13IrSqsGkSKUnGb72g=\r\n=PjI/\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"df1b410f264710cb7b4a1419d04882cc4f0a8441","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.52","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.351+df1b410f2","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.351_1670875852514_0.8183331103082818","host":"s3://npm-registry-packages"}},"4.0.0-canary.353":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.353","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.353","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"3af8c36bccbd8bb00db41fdda85f5d9c7d367ce2","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.353.tgz","fileCount":22,"integrity":"sha512-wYFMS1v8kiduEtfdswQeL/r0ZQPiexYQPU6VBZPDmy3KQELM0FZIer/tvTjVuUyY/4kclkPyC9Qv+ECqRoZ/xw==","signatures":[{"sig":"MEUCID3HSXpwot24TH5a7lWDPe4HYGf54qUUu/cUaXH6qGuXAiEA2st2t97AEoVXRnp13AZ/hRWCJ8NtKJ6IBNHb4qk5fH8=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157209,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjl5kxACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoMng/7BHvIxPgdW6yq2zqhZs4CnNH/gCE4Y7DSWifbYNvN+DiIDQFA\r\nCD1RakYrDNxz+lStAiLyC9ik7Hq3uNPFiWpUgsz8E/HrHLEeM/AlZGSswF1S\r\nET6O7CQJKVxTjUx+czlA6rr1pIg7hJKPpxcvIAkfFQUTSu1WRTkQeE7W2KkU\r\nd3XwHkWTbu7rdvYT3yqaxEl6HAtawSsWXF4/GdEJeykYJSRGrDAktxSlA/jE\r\n3AMrh5r+pPS3ZEKz3TCacTK92jduCBrI69OxCOJVvBta2StWLGw/eoGanniV\r\nHZ0DucJrpmzS9pzrtaFiJOVEg2acPWwHw78Yp7/DhZZElg8cIxWZTkI/SuEk\r\nd0nhsqpXvgqnL9/n/03SH42Xz3UxF96mTnbfs2gX0gvLR8RcVcAxnzTY1uN1\r\n5oNBwtSlMb3S87dnXn7gwxGVsSamtoehaMmpmLaj5Dz0apbnBWkmtSp1vJ4w\r\nD3sPGwvNsdMsWmnyvbduXRB83MeKZLzzzdnSmFiH+dDt4R+JRl3V3Y4kh2yA\r\nX5Fmzj4FORM6HSJXpNn+lIF7EwN5/fqvBLWGOWvxdxt/CWVOnqCTMeVcG7Dz\r\nmI+EZQuXMvVL0Mgabw48Eq9yCEEcQC50whgUsuhoYkzppAOrIvfka0gpmeG+\r\naqnJXte6HLmI34cKGKr9+5cQuEe1vbeYwlQ=\r\n=vf1u\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"b98b2a7aa70e091560d93a77e0d8777f4273a276","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.52","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.353+b98b2a7aa","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.353_1670879537075_0.2907830951256771","host":"s3://npm-registry-packages"}},"4.0.0-canary.352":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.352","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.352","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"24b0aea0971c4d205890284a07b7f9d9505bbc01","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.352.tgz","fileCount":22,"integrity":"sha512-kOhVrYFrDzNI76dBBePgOk7TpZj/hZEtU68yg4IpZ8yTzoYS6mDxiY9cplsJkgmKcdD5/V1EGt/kkDb8khsApw==","signatures":[{"sig":"MEUCIQDJofJUClCnKcKLAgdNJa7gpABYylilF2q/R6wUsnZlEQIgSWRo6B2JWm/9XIdm1LtHH6Et3BL6a4W6u41XTusJ+ns=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157209,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjl5pRACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmq97g//ZQzYCAZSn60iomu8/tWcro8YnqIHQCUUE6GNcsPGwisCaF9k\r\ni6pX8czHLSddBhGsEMlYBguhW2VysLRqogGP2pQwGaCImmEwiD+cwuWGaaf1\r\nVNjO6KhPe5wcVyaEzpkJYN0HC+jR5e4TnGkvcx7JB2AcUj10f7FX0cOFIY5v\r\n+Td7/ZIKOCX98ZFxel5i443HckCPA+9WL9c4CId8s0oDmL7pKL4ab3N+2Xuj\r\nS3IrINhnaG8crRj81Zo4h2mezDh+vN+PqAD/qy84odmc5CHoEWzqwn2/wjKA\r\npQ8f+mrd5Ds478qb0MjY+nCVs4LKTPib8njvlfTVfAf1XlLuJ5i2l6Ri7UUP\r\n5TEXTarnQQB2WyKgAZ9x3QqRzLjVThKVOyxJjmdaL5hVSrdK7nYfbXySlxvS\r\nEbIHJV0ecO6OY28WydX2BTF1yk2OrHToFUX4/lhJQJgzwVswPGobIP/5SoU4\r\nEPsBCvz26UUKkO4ilVJuG0ZB9/4ezuLL2Ylg80Idw/YicxlYonFe6q0wrHmt\r\nxSANbmy+8r9SBF1zvOUCc0jAZXScloWW8wAeugtUs8+fJ/JAvDTz7omQ0+wZ\r\nwZdkev+OTPYPfbTsB1t92dC5JoxgyKjEqeHvMkxZjF2bVi9PZKMDiRsyrPm6\r\ninbJ0OCM8r6gQzAC898zkvwFoN0t+gZrXwE=\r\n=GiGZ\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"21b6b51dd0e38d5891da1fed8e7c8ffefcdc3d8d","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.52","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.352+21b6b51dd","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.352_1670879824883_0.5033762798835313","host":"s3://npm-registry-packages"}},"4.0.0-canary.354":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.354","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.354","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"aacef26d09b952a8b2edd587fcf432e0b7e7d36d","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.354.tgz","fileCount":22,"integrity":"sha512-RRQ7AEheDmjfrxRM8K5RdrJN3HKx8FVgn6URKJipx31rE7A5OH+2zIaA+6ovM5257sJEzqViojMAI0v6oyRHuQ==","signatures":[{"sig":"MEUCIQCMntlXP96ld8BIDcjFn4AQRQTrKrE8r+LWIv8bfsqBfwIgHpb0VGNbPbbMPsrpRlzowUEaRCEGFUiQIFz0W7njuxo=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157357,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjl5wSACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpNcw//UEC4vV3sjnPH0hBXPl2Upj/zNp4VOLZwIePQ4qbX49zqqmbm\r\nEVlCb5UjMSsF6Rp1KRsj9A9IsCoT7xS2PZgALInpud7WG+QXevYpENado703\r\nb7rNi4eAdeLyFDeNLPyzN9gQa/AQWY3GiAWWfDe3uzSPaBm9AzMigohv9uR3\r\nhU0e6szeeK852yQcVyRuOjejGO5kgfPQcS5FJAVh46lNkPQIYCsfu8ZZfpQD\r\nBqFZZFN3C8D3eG5B//WKRjz5RoZARxPQ12eINiKkk7+Z8F8NR9cAy0Drp5v2\r\n8Z3KbrIo/tzjaNPhl0/EROOGHxSPqrp/jAlcA/mGy2iIoi457tcvWMlMAf0E\r\nOhI6CfG1FewqakcMXKnPJCsLbbuRsVP9ZUDh/eHyCGM65+ah5I3+4l5XIpsu\r\nGvLFrN30eOnOJ9DKScXgqp+MISxvxU2wLydHUVuB5tvf8qhxUJvGrjvQcKR/\r\nZ8NONxAu1y3NVwoG0tv11pwWPd0A83+h+x9fl+3SZYOb6R5kbL4ic++kcx7I\r\nTLhZSShBURmGw3ayaplIEfrYUji+faMmL8s96A9UPWTjb+UmEQOILmpKj6UJ\r\niWRW2+76cIlz4QoufFFHArWbmU7Dq5E69benDs45mS+Xtg+GMmfx5wEVzBi3\r\nSorncKY6utfWDRyow9UnzUqYZ28sHAjzvwU=\r\n=hFPS\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"a9fc646485acb068cba2335d1f64bfb16842edf2","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.52","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.354+a9fc64648","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.354_1670880274116_0.7171321670079522","host":"s3://npm-registry-packages"}},"4.0.0-canary.355":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.355","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.355","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"0366f2b7716112c327ce50f20c04b065fe624a20","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.355.tgz","fileCount":22,"integrity":"sha512-FSdOlCFWOGleH3v8+2Y1zB314y1yvgLfC9EwyxhR2hqjNywdgn3bl1TAzrxda20DmrK0SeOMPTHzgJKv8dRDaA==","signatures":[{"sig":"MEQCIEpPt4Ze0fKTtImElAuToDjvzGN/qq1TXMfxkaC9mWbZAiA74I/ec0JanwkIi96v9Cap2HQQzTBCiZvc4iI/lmXVWg==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157357,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjl5ziACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrFWRAAn2XojbhVFRd99O8M4x6+0Y1roe+K6JyOebg2uL72UxC2ODRO\r\nUey3zJ1h9qiiMDuVeSUTuY37561yUrFDIE/vQiuphxMMwBFpxcdShchI8f0P\r\nXoiytB3QFCe9OYFnrojo6CJOVD8H7+2ke9t9xBgVI4uJCzdQ28G4LmrJXyEu\r\nnSNBscyvbylvU9iWiMBRL6IB2eoXJtFUPvRnMA34Bn2lvkpa3QSVz824MRZU\r\nRSx3ZT2QjoDPnmvot8CVZk2AonhCmWSy6DDI8e4Dtca1osvMymsk3vDZ1ph+\r\n8+h+Fn8ct1FoJlG09wlhOLnoMemk//pGf5N9JULV5tdmqrKTc28DvpX8XJN5\r\n50tBxmQMIzOX4byyVe/ZOMPB8adc5q9kK/cxw/0tc738T2cdZhjsafqEW25j\r\n9h4ZkyrMrFe4e5SWovdVWfXXX0AGe55u187kK7RQUIJZH6Gsqfzi1x1ozwsJ\r\n9ogRslD3WS+PRHgg+pL+4RwXHWFZSifVeOoJK4zj++dP1QNmC4cuBy33HFe2\r\nh21RVPSg+kMZqsbvLFr12XQbwPPg42sRBhOpBQi1rLf5VcJlAjDUrIb9DvVj\r\nu0wyyqtG2rKBu32yEIgx3JLsmhTZWdz4guZMv6wthprB3zgXR8nSBumx+MUD\r\ndNOP67R7REFUROiL1a/z1Rz1wJ0hfkHdY3s=\r\n=PQ1O\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"05ef6a40caa9bd765659f842d23ee0e267c292bf","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.52","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.355+05ef6a40c","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.355_1670880482241_0.4091599729718398","host":"s3://npm-registry-packages"}},"4.0.0-canary.356":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.356","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.356","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"a0459bf8410fb9808b3b08027a72c2833f975500","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.356.tgz","fileCount":22,"integrity":"sha512-0EUms6zoRLczFXIrWPsWWNuJ5ZWOUNrps4c6F+e0d3EY0BNLuTnMAIN0T8TgDeDAajQbY0Msgf5qiMYgAwbATQ==","signatures":[{"sig":"MEUCIFD7aAXpdaDBa9ZJUzrNriMoHbp5hG6zduTFtnDPRSruAiEAiLwXTF3owWpYqQ5Vzkqu/k83IEgKGVj+58kkYuH2UAs=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157357,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjl5z3ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqA0g/+JnPVo4/6n1YZKC48JhP+2u6ItzDEXDeHNq7DUB2EYE15Nm3e\r\npundUQk0u0jspiCY+wTNZT1JcLsKGC1zPMvQOpfPrNfV0Z/dieibZQ5mMusk\r\nD7WCrUW4P9bUy2OG80ZLrTNTWZ0LPr9g99QgATF3fdKKKCHkRqgUtdRFvZfq\r\nLJVdjOi/xvgBdqy+la/kCz1wLicTqqjamBfRnkDW2DbarqYMTKCJdbFqI+iP\r\n2K8rP2K4Pc6gqg7HXo/zmaj/G7OWQkaxD8Y6z5hAvbiPsactmiUdWApsjOXw\r\nLZp+SBd/W0xl259HLROa2Bd2Adrqn5RHHVZpzHR43OOQ2G0fhYlvjh2nRZ5t\r\nSWuJLCE3NQZg1tHNcbuv+khGXqIvy17SmKLoSkiuy+iWHGFB2Fsq739r7Yus\r\neBBW1K85BFrv5NrqJ8wtJ5ehIOj343QfBD+FBdk6QInisi3tJy4UCG0fn8/H\r\nmxincTIBeAvij6RCR/U9GmpeVoIfaf6/7/16sOQEKf9YB414qJLREc/VhHVx\r\nwu8K7NqGR86/ROKDDuVwZ9ZIoqVva38JxONO9nYvKHqaEb7GnrGFECPPIPMM\r\n5cHFK1RnbEXM4Hx729PxyaGoU5uk0dDvrqzY3kCPVr958dVZEAyobZgrvXze\r\nOdUwnrSxbcCmoYxoqVVX+ymM40pZp4V1VyA=\r\n=ExMu\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"256cee55c7124571a9d243513df4939ca30cb57c","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.52","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.356+256cee55c","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.356_1670880503021_0.9450049905681488","host":"s3://npm-registry-packages"}},"4.0.0-canary.357":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.357","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.357","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"96e29030fa075ac8cd1834e442427bf34c4766b1","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.357.tgz","fileCount":22,"integrity":"sha512-ixbvCqz36jK/YorQB9ow2j9xSTNaTZHw79Ul6oNZ++4gmQTee6+USoxICg2kFc69Tk9kaAeBrttTYlQQVgCD9g==","signatures":[{"sig":"MEUCIQCPn04Xy5y3zV0gF3l/OdGQ+IhSO6ZXVcty19avF4M2BgIgShPpNtOqmvbsacFZdCWffZ7TdSagEM+DC5FcFQU+JXw=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157357,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjl6PhACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoBBQ//bKH3cFfhFbPaacyeCShkEyB9b4H/7EkaObd3UKF3zhsfru+3\r\ntwonFg9gs7gQGYpfHie43kPhPDbBJc9LR1SiAdqWb/bCHa8BU+Me9An1yfy9\r\nfdlu/KphTvSw8U1kf2O7OIXVWjn3zRMaOMdJ4A0PJC6dJ6f3UnfQMqNpb9md\r\nUiqaMoTfr1Y8UcOsYOe7b2pPYpBY2K16YfswIk54czAKtbKUI/KpSJf0dL4w\r\nn/q1S1f/23xxS7DjlF7oMA+e3K64lDYltJmFjSV9a07fZgsMY5IWPQLlEXBN\r\npx2+TWcs7Kte01WOpgrnX+BB2AhlV5uFISJK61te3IwYRB+NE6kE5mtkxYDE\r\nIQrgBQbUczH4u5M4WvXbdjN5NmrE5ZF8LyLoifDZlPxeteLSgn+WfG/2waJU\r\nrlBbb3bRHM0tlcVnN1NFcCHFfG+JsuJzlUleXbjhcexKUee0gGvxBlvkW3Fp\r\nzD4oRMo+j3BvxKau1jZGUBNGtaq/Z4W6nioGLSED1BWmbKj0TsdBajO+0mKU\r\nGhyuu5lQFZ0AOmRRTKaGoUPcH9qhF9830GzNfzN7fOw5pNxJgx5QoygToIwT\r\nc8eUd5DV/6hm0U1KqRak8SJKFO3H0CP0F2eJ2FB4zvS+e77eepNs21IZXysK\r\ngQnCRDAXaQgjy4yIbLZfPjbxey0hhnX4ehM=\r\n=Qa/D\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"58a18fd08a30724d0eea8927d9408e75da623ea9","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.52","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.357+58a18fd08","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.357_1670882273423_0.6648868024780559","host":"s3://npm-registry-packages"}},"4.0.0-canary.358":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.358","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.358","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"09084a6bc5e85af7de7bea32958a385a7f03f6c9","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.358.tgz","fileCount":22,"integrity":"sha512-G1+JBGVsnsGKSOlbI7C4oGGuW+/UaswDBFt60YDoYneqJvy+X4e8RWwwg7bdIXiHk12rSRoTTGDAK2UQq/qVaw==","signatures":[{"sig":"MEUCIQCiMpUhdJMtScG+5Xb3a3wcONy4K+tJhWZjgPZf2qye5wIgT7JPesaQfjFABOxIY1NR8j/YCiN76gDdr6SyWx4DgCo=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157357,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjl7GkACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmp7SBAAnDSjfEqL+to0y4XSF9x4y7figPU+9e2cFZXUJDvE3DNQgvul\r\nQwlW25L2na0gpIfD/7JcUsiZATLSGEiK70eBIvOutjlKO6SGPkeHuchj+aN4\r\nOkgWoQwyqoQzyWAcHrF+97hbpGl9oodZewfF+Nj3iZOwUnmTbEhO6JNiKzjS\r\ndJoKFLaydWHKt+dQM8x4m7usH6I69V0W/mhsJmKEeUz/u3hOb9VxO/JyG4RP\r\nbsOYR6vBbkQf60WQe5YgGazja5y6FA1cIFM+cwgL/Gzcvkma6cyM3SgP4sWw\r\nhGX1h2gFJ83aBPnyK0ubQ1qYrx3xmMp6xmRDoIgb9RpKPt6jsKFvle3WuAtU\r\ngFsniucVkVagEY/DWx+DlGdSU6CwIdOyl6UNMlYFFrNCjqmDp4UZ8w8S8gYS\r\n44PDX0VKDoDSik2Sy1yW1R3vrpUKS969BfSLqnzeJDCM+8FVgaTcOd643BtS\r\nBYoQKvVbzGkufngvchb19kIKkLbtrkrhcuMfehkrgOs5x5TY88cRbQjgYMGm\r\n2p67SC5m4zBQXiP9vSi+qb8zRu17Rd/OmY49LSBIf1MXU3FY3+Kjqp33Ev52\r\nmXSz8z+gci1Zg0B5xIsBxFkuuaX+7EoWddGMi0me7bPJcEiSD9QF8rplKb9q\r\nOtVrX7Zc+JxH3zoC6+fbHkZhX1r29gBwKr4=\r\n=lm5O\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"bdea4808f42115957d11cf86fb057118dc733a3e","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.52","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.358+bdea4808f","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.358_1670885796282_0.26210673119101835","host":"s3://npm-registry-packages"}},"4.0.0-canary.359":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.359","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.359","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"31d3406af60296274400703a2d8c258a5a428f13","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.359.tgz","fileCount":22,"integrity":"sha512-hwdf0q4MOgeLJknJeCP+/tz2Kcq1QbBN+vuU6Uf27XzXTzehvOudnVZFzG06VQv7chHuB++Y0wnx7dHEP6qvmA==","signatures":[{"sig":"MEUCIQDWJzwXS5z+mV/D1eYATIIqx6mZMfHWZYt+HA6WEp+p3gIgAc08lbZ9a0SNKGRdhKWjQs1AHN8MxviQH6yICjKvuc4=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157357,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjl9J5ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmp5MhAAjKvwv3Jx7DkHN1JdLJJUbKg8f6/vKS4i43DWDGIijNkVh8wb\r\nEiy9B5eCLXubnhUef6bbNQ4A1xyyPpsAj/scEmynsXXDyysYK+NZUeHzqqU/\r\nlce4PhfWSq7MSYNaGG0NXPIaowYZsr/xlIafnZ7VAG8Dj0M12i1E4E3GoT4A\r\nCrdL5Y5M3Sn5bZ2P73tgQFLLQon/gw+hZ6fuCA5OCwa5tTWYVGBnFx128EZs\r\ng7R9iqPkZ+9iaHsgMiQPT4Bb1S5WtJMKnmVaGSvyDObLT55OSrDq0oUJnqFL\r\nHmwODv4aeQNrAqv04Zf/7pAbKPw0REfLx80caDhkUpKkY8Z/Q/12PKoV99gZ\r\nakaEPupNdcP0gp1f/uxktO3d9CCdAbP/qXufe7JGIptEabmRr3fkOeNE+LaO\r\n/eikFmrwLmB0wCH/dwzq6ZGoMbYSHQNDqgJ2v9SA04y3tyjfF1AnIhTljtPS\r\nT5Bd3OLIVC7o86hL865J/rT7sgCJ0wKcZsaDLh+nhX1IKnw45I+wxNhJf9A6\r\nPaKdywg8zOhdf2yrEFGUZodWWO/nlEQZaUQV6tmK4keDxjZ+nhu9mQKPXpai\r\nd7IAE0DTmCnPa0/lCupyW+WHYlIR7nVkb2TpmOzLK4RG26H/CNmDo4iqZLZI\r\ngvDo56Q7CSkQb34wvUCfnqgSQS4GfNeQef8=\r\n=iXUy\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"ef3600d14ada83c0265f52f623e19b43793562d0","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.52","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.359+ef3600d14","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.359_1670894201616_0.5587422363015804","host":"s3://npm-registry-packages"}},"4.0.0-canary.360":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.360","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.360","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"bbbcce38eca61ff05a41d66c27cdba08b5ed8656","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.360.tgz","fileCount":22,"integrity":"sha512-YWcxSF7bH8SjlbYEjdwcKrzogiYhtPwg3Bnb55w2685g/fFI7lsIUILjqfx5fjiV9ZU2b4BPVplkEVGp8ZGm1A==","signatures":[{"sig":"MEUCIQDvyVHwvUzcrJMW6SpbxCe05P50TMFoYXEBtCXZ1IDTMwIgcpE13dRsRQIgBxpFnLzc9/X4tb2DrVeJAzExu3TWkIQ=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157357,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjl931ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmol/xAAm1PSwkyvqyPofWzh8rdpoy6lQ7EZBhE8K9XyhoAniAhLClsW\r\ntBmidqQyykLRP884JSJPmqsRD7D7vQaBDS4i1KjLTe4rM8bpY7Cg7i2psO5U\r\nEqLf0YS6aKc7YSYeeTORrQCbfOHt6PR/PHdZpwHYbFzgAPfG2QBQqHi0x+vP\r\nLiI58EQ1t/44Er05dv9xgG4mjQrX0yK0A4tiJTe+bvWJ8rMZ+wQTW4F9jmZ7\r\n+RlQaxYzraMuz5Fgy2X8mPmyw2m8918S8UkyLHsd3XFpekPkuoPWd/ZXM+3d\r\ng8HXoOKRT58oKMlVmqpjgbPiCXNcooqaIu/wDHwJvDIPkyC9zNgq8PIpmXLY\r\ncs8D6Z8Tg7EIe4NOiriqXmGo11B7y8PRG64ApuQp/77SQ/VcSbbnx9yXTH26\r\nWYeiqnbHSlOBKvDYCLVpwGtvOiRl1tPv/sNGRSzBNVm1zjR0n7lIT1xtRyiX\r\nkb6HUMu5oyfgsksHpyK7j7cwMt90AXLGRK1wzXv6U6Osaoc/5WsH0/52LEmd\r\nKPpPqROXsJjait36ZehKt+q/CZYMp329yS1uXQMWO/zCmFzErc9VYDFbT0et\r\npCekEWg4bPUinC2KokgI7bX7nwM1iQMPcLjQfjnzWWz7M750LNAwyWZzXe8z\r\n5GJI+gn7OfbSfxkDBFavCjrOOAuGqOEeDtU=\r\n=/I/M\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"51d21a00cea4fc1bf8c5e0dcc20f4cadb0d809ae","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.52","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.360+51d21a00c","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.360_1670897140870_0.12147845376737365","host":"s3://npm-registry-packages"}},"4.0.0-canary.361":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.361","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.361","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"375ad08088030d93a31d3b84790180e89b0e7ad6","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.361.tgz","fileCount":22,"integrity":"sha512-9sTVG7l2uBO3mKSfX9DxGhX/2jdyselSm++ctau1kvn+8tC/rKO2ccFWTPD5SJVqoi2N3gZupmA+jIB0DejzCg==","signatures":[{"sig":"MEQCIBvBsQHRBjjsBtRaKPtOnT3glKVw/Es8mSOIt8Wk1RUyAiB7YTc5qfPn195g5W0XqER5bk2GA5cHIBIDH2HRGHRelQ==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157357,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjl/SdACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrBwBAAkYYwI0bIz3ktd6QKD1feDzYaJsu/wME5mkCQcP+B8+6di8XP\r\nQ5Ti5cN6reexoL6u8R2RsKPChcqebiX7cf4K6eJVHAZ9LDCSeA4Oo0d8sfD+\r\nZ7qWkodl5OGZp3AY1/52+tEyBuLo5C6alcm54NuXVPbFr2oJJeqhbBHW0wrb\r\nYIKSaERWAvUAi60yJ/S+GZavMCbwuhGhwFXw4JXdJzg7a7PQnSrZh39zal6K\r\nI9tlC0o2v3XRZd1X//pXZVHS5FGY4nYOZsR8TWHdxOygoA6mV9wfkr7m2uif\r\nBy8QeTUmMZNsrq63W+GURUtDGaoL0glAwfCgUzw3vwbbjADpLIcfkSibCjFx\r\n86kFOmrsTk2UdAmOMDHHhX+DvKIT+wa/HpRLeOoQopilVblZuhWThQyHg/ft\r\nzM/T+nhGYLaKBbaQXx2ENinrvfzLd5F5WDd5yXM7FPYSgFUHpzzHBQa2y6yB\r\ntLU8MuLLMzLrFOLMlV0Vo1I6171qpt08d3idto9WkrrCKhEeW5lw8hQ6HFrx\r\nct93vIPYUiZNouUgFBrLQ+83JDiF4air62CZcghsy4OC5qyl/eBF/Pt/ZWnz\r\n1epmgtvqd3jW4kWB7RwlFd4lx+/uf7Eka8UvdgTkDKtr6mX+5c+hU4z320oI\r\nZ2C5zwEyWB9bH6j2yHG9rid92/Y8glIV5To=\r\n=A3Gu\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"680a2b5a9fab2318e6a4a5caaf47bcb4a4e6d136","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.52","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.361+680a2b5a9","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.361_1670902940848_0.02371641938177249","host":"s3://npm-registry-packages"}},"4.0.0-canary.364":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.364","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.364","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"09b735feacaceec6d40087d057d058b19e50ad7d","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.364.tgz","fileCount":22,"integrity":"sha512-QsASMz1XrXpnuQA4UeQ/0KMygPIwP0LPOUMlyo2bOzi1f/x9WrMmI4k2G90WD9oAwcoKbJosI+wG0f8NaM+VWg==","signatures":[{"sig":"MEUCIQCDbzZgOOpGYSAYdImW/uBLhimEug+KYiPKj47nOdl+XwIgYJfdQT1r0GG31sAITN1muYwnVU558fyBjqlfv3QDYe0=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157357,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjmEXOACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpXaBAAiHIGPNYfYSXrYWTVYsLTDMjzEOB580B3qdVuclY29rbSCFvh\r\npyY2HAE+4PYo3gbNe64tp487fpUtzdRJ5sI+qaFe5mhe+EosPNDhlxQ+rat8\r\nGU2yYoa9tK9c9E423W+wtyeSAFGzNs+zb1YoLJbnuEsXWWO1GF8CuXbOevR2\r\nMJbaAC4AXLzGPkqmcV4BSHu1VY0n2KHvja2vauFOQYHVgRoLHoeSYY27kFML\r\nXBr2sOcGbAVrwhlWMcLLo/k/qy3iNB5syncJW988SwccfORr9EynjEPVz9p9\r\n8WVcgRoAfTaHO7EglIWvahXv6wzQvEgKlv6qYr/HqMVDjPn03zIXLhuXOX5E\r\n9owT9wvgVKtFmPVCVM7IMKL528fQbazECGhxsdb63ogqCVpb1Vrz372aWVJr\r\n1TNpsKsap+ZUO0hmrWcr5AhewSiSTRrnysHwq8jR9ZeTzWHyo6SAJ/CkubYg\r\nTIhbeNl4hCuFXVDm13nBRngKUBz14bRZPi2v4Jw+iu2zCchKTmzRt6V98pet\r\nZ50Ldj/grf5BRPjdKw7+GTIPzv4UsaJfWefp4ec5t5UXmZVfRNqcW2d/bZVu\r\nS8BaRIebDDfv4R86ozjFBfaTv06Ht0kkXRDQVGTm6YP/OHoGFo11RnzZy/iM\r\nnwttH/QDGZ58BXc23OXDhaBXt4nrWrsSXlM=\r\n=DtU7\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"d7e7af355c70bcb56f548e93702ed33b946a9418","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.52","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.364+d7e7af355","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.364_1670923726006_0.6403649278435406","host":"s3://npm-registry-packages"}},"4.0.0-canary.365":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.365","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.365","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"bebf32c6d7f7200cbfe4df70e2ee643c4c653bb8","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.365.tgz","fileCount":22,"integrity":"sha512-kBSBKYVSaulZJpBi/o0TLa/rkyXNJ5pgWJvVHcbsj2Jd8OnsfMdw1o5kTi+0KZsw9d3ClQBbc7rDxc9kgZpblA==","signatures":[{"sig":"MEUCIAdFZkFzBQiD66FIeVrjFbSIFQ7zGCXD/GjHI+S4jwKxAiEAnbGOfociiHU7gMSdQuiGZ2R3pjWEyYiYQG9Kik7n/YI=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157357,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjmHbbACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqjNg//cvanQxRwBrjFIA1BZ0DprMS4str/yJ0uSuC7a4f5ULonbi1e\r\nQ29PtetMvzWmBBM/7JaIFtyFEoswl/z1FyUq1c3xcgvcWAPR43T2ZtfQR9eo\r\nAxwkUwVhy442J3tAMuYz7imZTrR2do/oy7QhZvhE7djNwBGR+7BBsupanPO3\r\nyRY6LDuccEc0owA6Hv4LRU9vtxLt5jMYOP0Kik3pPjnPtWVTdjiAuBjYx/Z5\r\nYfYwALXZeMA3vO4tSHsLZbVTnJ8ci/V9vJ/BnVyyhR6n9wQAOrs3e8E9UoX6\r\nHCk4cjYcRzMOKQmaKbZRgO8pzLAI44Zgqo9fsDiQm+/09oDa2uAP2Q4ZVn6v\r\nyhXXN6FBZj8Lrnh19LkYow/dB81ewBcMzhCgjvv2KUpKxeWwUnCDlMJ2c+1u\r\n1q2wRjIvRkxd3Q/+iLfsGTWwME9ECfEuWmsxiDjbb+wlQ3XrAzvhII7DmZO1\r\no2qykDSuFCotBF20tPt7Gm+dmUpdNGONpQdaoy8gbHIG97sMxsIuAs5wTD1H\r\nNeivHx/P7nPspZBeU9RPtquTEb1RNsdCnM4ogymMeyF1uXTeKS8Vt0NlRmsi\r\n8m79ITircUXk2uQFpXJil5dKuOdsN2EALBUKjdT2ZIZdeg2iHCXK3BP/VV4i\r\n59yhBQEvZ+4/yWs2XYN6yPpP3JJ/EoqyN8M=\r\n=bIW8\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"0cf872dc32a525a4449dbabc23745a8c11215746","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.52","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.365+0cf872dc3","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.365_1670936283588_0.9639853232960447","host":"s3://npm-registry-packages"}},"4.0.0-canary.366":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.366","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.366","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"bb20267bd37a398bfa86ee309e37856bdbe4278c","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.366.tgz","fileCount":22,"integrity":"sha512-z6axDvN9X3YhAYS7Z9wnlt6dhvGQGiLRS2K2Oz9P6tI/lVa8d7c9rLWXxKSXZtySlJavDAMcB4MWiTaQXFGKkQ==","signatures":[{"sig":"MEQCIEjcUaD6Ql9He53wp+Sg0kOBUDbtXk3+bGCvvDWrG0XlAiAw5n+kyVfaJ+8whcKla5vhGL0NovwH5ON8dPmpGAZXfA==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157357,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjmJy7ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrZCw/+NNQTcY3twtNSZGYLnfk+65J+idlKdgdhOBNZ5B39n5hkc/NN\r\npm/P1O8EimO1+7Weu8mP5a3AjpcM4vEbgl95fwmnRbaKkUvu6vuXx6JKnIJv\r\n4nNheWf3tlsyUtOZzJaxRn+utfojR76REMoJR5xwu7tXScn0Pdj/DonahezU\r\n1WffIkYpZoAa/CiGBJnjpXkL1gbL2bjP5+M5WkjtNWfjOrHr7fir1cHt7dyu\r\nzJD2spixq/+3UOjjHrWo6Va4MqRlfgDLzNNovMDMqzseq2MQI3q3/R+izelr\r\ndcnr2wI8DvGEEXlHSb0J+tM05OqR1uaZYKaKNOd0eiOuiS6k1rrerj/0zLG6\r\n7vUhaOu/vgLzqqJzSHst5GfhUQa4iTe3tW1dPqcF4pJvXAz434bNPxA9JwBR\r\nVw6iw/oU8R1KeXHjFPp3FHnz0f38XcxFI/0ED/qq/Dejy7w32bLQH0Znjkg+\r\nRZCdb2PXkXNIr4XdRKIIty5m4uN7ZlMakyWJzk7+IT+hRJLnvzV2b6H0ogMj\r\nFD1WBIdADYDtpk4pcVYHf4OtDeK0e02EJjFjKyNI+1CcOL0PvWt5VpNHwnCv\r\nsqGT4z41V7IywivUxnk47N8dtAhc4ZqpcJhBBVEMELGRtT7NwVVsgvMORujq\r\nqTi5mlMG6u3cUHpd4F3QPmLO2VosfgaF/lo=\r\n=JYds\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"6539f1c4bfb6dc4935a84ce32a7f762da4c9795a","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.52","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.366+6539f1c4b","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.366_1670945978908_0.2114854281640457","host":"s3://npm-registry-packages"}},"4.0.0-canary.367":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.367","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.367","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"af99db39f9f86b4fa81362817ade8173c16e0b2b","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.367.tgz","fileCount":22,"integrity":"sha512-pH/wetH9zkoiNV876TYQ8otqDdiEjHLf24tjMEoS6aAwqJkzyFnvM4iNIWZz4rRS/uEJImhq9WDPq3Swr2Vslg==","signatures":[{"sig":"MEUCIQCS+bUWFZT6zi/nCDnBF4YWfRKa5eaHzmnk7CdBgcoYZQIgBjsZqO5Co3oIzXRXvjujVqG6urSPAY4OlxWNBlEo6DU=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157357,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjmLQGACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmonthAAoFerj3DfvoRtImcRVdnJGChoFhKGGLubtwWu/gYQEVqRAZDv\r\nryStX8cPUqPi+6aS2btIVD83vI+7TPe6G9y910YPMK7AhC91Mz+8Sk+7FfDz\r\nrrX6JpdjfbJ7taaO/LjGHVMyqLD9IcngK6RFA5ZdrJ932BPGtgxHqj+/AFw3\r\nJgvamkk8B/Rd12Vl9qd0RwXgnS0MxHtGatnr0ixATy5msRuTRnWfChrGXuvY\r\n1LknvSAvqUzj+IqbNM/lykfcobTAh99jvWeE8ZOUqlcegm042cpySi3+iTDm\r\nf65t/JkWnQ5FJWGj7Xvk64Y6w2W7+ti669jYCqY5sDO7+BCxwxUN+V9g/kKM\r\ncFWuI8ylgBDjjJs4k+etyFmXG9wACtcEi6DAg2q9igXNAPTTPkef5FBkeo/8\r\nMGDZ+FKPZ9hK8YUo1/WyQiWNoeWfUeF3d6VgYu0DVN4biAR1jq2Z5dnzdeB/\r\n4o8YUwwq2ITFfRb8FWpW8engFBIq3TUZeZe7Fw5hU7v/OUiX4HFic5yoItGS\r\n7hPqbJbnbXDgNZDVVwGzpSQxfkzJbB6GhwIcfKuK5o71ZUZndTgZIZ2IUbCn\r\nFJATvGtkMZufOh1INYC+ZZmYPwIkex1JQfTYY/MBbp20SnVfFg7ygkYG8Jy+\r\nKNVT0DWh9UPw08I5V+0J27y3X3xMduRuwWw=\r\n=8koy\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"0b33c59d950c2d78625f4ae7adda0c69b7cb8e4e","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.52","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.367+0b33c59d9","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.367_1670951942466_0.2903022639690995","host":"s3://npm-registry-packages"}},"4.0.0-canary.368":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.368","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.368","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"ad702bc105e911a33ee3e6db13b8672b2a4e4b5e","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.368.tgz","fileCount":22,"integrity":"sha512-thFt5SgdiDPlJlHJg53l7cCjfBYmL6dLKKrNc2lhwMk1xAjka9Ztl2E7m/2XdCOoNmmEM+t77P0yWy7TlgamLw==","signatures":[{"sig":"MEQCIC7zJfgcNFF9goh1Y5xsbcO6CjSPWoAvZc/7F84lVHuxAiBK3tgE0qatdnGZR9C0wyLCptNnX2Xla4MSz78MwKdtXQ==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157357,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjmPfcACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmqlug/6A3/R6XRPViipVF910YuZuUF6tC2U0rXt5fQJCl+n7DW+ZWEk\r\nozB8A276/5g+b0mkMoh6sSXco8b82k3hV1A36upKORLz/r6udQIFgyJAvZQY\r\nPPtVBF/zlNKV9yuNWsofStjXOXBbrxOBmZG8iI7ZszIGUFGBz14HZQSqXxDy\r\ncCyljnLwmgxacn9AiHdUDEynucYWZNxOdzIktK1nzEDneqtNrh3Esk5vzAyX\r\n0cdjGmGeeRBMu41OCN3WX+W+YgJzZplEkeZ2titJZa5Uei9tCZK8Nx9urtPv\r\niSM+YvjG6U8Z/IsgXvGjqa/NMO/HMb4p5Y1LcNJHESsMorjWd8GpPnY8EyP5\r\ne3ZUDA6raHb8TI25O5dX5seYPh+fL0DIH8Da6BEPnJbUEgJZDZtuMHzjMH1K\r\n0i7jHvMrIWYyyZN3wsIAcixakNBziXNSVmx9sdWrTdN1pbODkDyNKc7OsK2C\r\nWpNcPh1jgCGLprs2s9dZuXfBM0jwU1SLWubACqkQMUz9iKW5tQC/L9bWqpvq\r\neOpXjQsv3VgPt+TgRXJ5b3gDAafvPhgzkRB4NxV+PyMLyrwpWcVZekgsqM3b\r\nEtCTn/oeCMUN3i+6s6gTVTUJbpQddSdQX9WurDr1g7AoMny1DMPQUzDopWgv\r\nGPp74XNDtoi2g6aAc24mlLWZiRFp7IlWmSw=\r\n=9kWw\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"aa6fb1e09cd4a5876fcd775f3291190c8b9b2c6b","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.52","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.368+aa6fb1e09","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.368_1670969308222_0.07469475433978556","host":"s3://npm-registry-packages"}},"4.0.0-canary.369":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.369","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.369","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"e4549c04a61e063170339b478a6b1cf15c424237","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.369.tgz","fileCount":22,"integrity":"sha512-MDfXrXKF7hzs6bW6nxe5C3ihYsSYfK4lKDZusLEbNd6ns22XOnRaz7/0HLPm4lQSMsCM3r8oxyO72wAhPy3MZA==","signatures":[{"sig":"MEUCIEXqWhfMW6zhoeY+QH/K+QguxmNb+5nErq9Ffmb/9Y9OAiEA+NMXlu8T3RPWCGBYfOu4YHjL9PrffcRlhN30h88SpO8=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157357,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjmP7aACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqylA//dvsAZg2tTDtvw86KhSsv3mJnQaUrO7z++mNE9jLlOrRzjNcL\r\nXvbDv0G5vRlyjrAXSOgZjlM1jxRvOrUtYPX4fv4CiCxhMU4u7b2ghmd62NsO\r\nMcM1azBvPHI5ao7XGDSWDsraRzJJJsjSc5DqC4/8gn2VW51TDTiuru8K3cXs\r\n9eZwF0/QyybXH7zlroKg2ZdN15nJaQQAauhmbEWglRgsJelpuIvtBFugo3pY\r\n+gEDjFXoIeiYeACaREJq9kTddRvxFJQ3WiHqBycJ9yhvheAXWC62lmd0S5Bk\r\nd4d2hXVW3k4+bRIIfWja9k8Mqm0yKhMYegkG/Lft4yzN04nsxYlwWxufJHB7\r\n86cUUm9EJsstUi8MlVNTgtKxws9c3AjsScqy3+jr6jeivVotU6XeGxTaefam\r\nlYzAp4XY63+lYvC8aCdkc/35Mh0QcefbwBSKXyL1+i1WkQOhsg41nmWXdYga\r\nwiSvbLOavkyJGrfyuLSnlx3qsFpUf4ezeQFfGxZ0mxlKc8JQKxYAcASnHxiS\r\nj2y2hYAVS2BSLJuuIFmWisXk4HwIb4Y23l2URiXkDjh0FLhm+dva6FknBqOt\r\nEWtmb6ak4rtO/hqv6gGKcw5DzhJRH89caLKyByiclpqtfrntvos9zwu7aMv7\r\nwkXpbB1J2LQaqvN8nU1pd3GN50hCzgO5qp8=\r\n=FrXN\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"2f65ef0a385c137d6a770c385e06da1ae7a63e0b","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.52","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.369+2f65ef0a3","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.369_1670971097813_0.6891540730333483","host":"s3://npm-registry-packages"}},"4.0.0-canary.370":{"name":"@redwoodjs/auth-providers-web","version":"4.0.0-canary.370","license":"MIT","_id":"@redwoodjs/auth-providers-web@4.0.0-canary.370","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"694a0fc4335ae3f681abc50b9b38ebcf1cd46496","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-web/-/auth-providers-web-4.0.0-canary.370.tgz","fileCount":22,"integrity":"sha512-S6wR35mHQSe0z+zoyWxWU9qHE93g3zq04P8GTrh5DTM79M4yCU1hRiM+kR8QafFU4MUFfBT/4x2NPit1xRQ+Cg==","signatures":[{"sig":"MEQCIBjWvrwQQ1RVA40woFAjoyHRDAr58Q1+tGzgjscaIGBWAiAEgbH724sg03QlEYeXBEXQw/6pU3PUKgy6Za4WjTPQDQ==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":157357,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjmQP8ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoBFA//dJ0xEERNqRwGBYJb3IfrPSJ/ONNr0NaRax/tKfRImE/quNGD\r\n7DC3ZxNSIiHXfQnEsVUWr6ARLo47pMABEds5E1U2uflviM4tecwdx+Mzq1vM\r\nu5OK/38VTQIgPgUxlraP4dacJoChC8DMXlKCM7f/wpNqzj4rUxhm7L2o01GB\r\nTkfd5D3YymWdgn7dpdF39XzyYZ66AcVcFq1BY6IwQ6B3ptVuFB3JM+A50nOS\r\nThLh78la4zRrBDZ/ZtXUI3rnUhVZ7xUq5sxOdqy8eGNISmq5dTnrwj3cNeK9\r\n/qmFy+7RP2QSPNa3CviUhuh815fEH3wExmpx50ixcg5Ncz0R7QLVTA2vQwDK\r\nXumZQEUir+9xxgAM1FXrjgEXmjym/O0ZfY3n82lWTfskFRJLnXZtzNtx3lSS\r\nAMokHrjVMDvXmEIgIVblHJp1ku/qZ4tcxhTB7OjbnH8CPsqfFIIgXr11Arli\r\n+C0bUEKNBMFuRRHDO/M+qAiGMvVijp0H4UIflEauYFmzarBB8VzmaQNlabym\r\n+QM12H2nFrmkaVtJ2fVWlGNzMWNMDeA+1KzVSp90tKphQYMK1/K5oRyFySDH\r\n10KWpHA68Snf7YYAg1e6aS105gUEHT1Lffh8jfw4LhvMDezr+kid6eizvNIu\r\nosJDIPV2GL4iGpmy/X2xhwnIwcHKCGN9xWQ=\r\n=9lIJ\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"3d057db199487ea0b17240317d66ddde3f83f332","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.52","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.370+3d057db19","@okta/okta-auth-js":"6.9.0","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-web_4.0.0-canary.370_1670972412143_0.057315142104111816","host":"s3://npm-registry-packages"}}},"time":{"created":"2022-10-13T21:35:36.156Z","modified":"2026-03-13T13:39:21.454Z","0.0.1":"2022-10-13T21:35:36.470Z","3.2.1-canary.123":"2022-10-13T22:20:17.321Z","3.2.1-canary.124":"2022-10-13T23:30:13.095Z","3.2.1-canary.125":"2022-10-14T00:19:24.032Z","3.2.1-canary.126":"2022-10-14T00:53:01.612Z","3.2.1-canary.127":"2022-10-14T01:25:49.138Z","3.2.1-canary.128":"2022-10-14T05:41:43.789Z","3.2.1-canary.129":"2022-10-14T08:07:43.362Z","3.2.1-canary.130":"2022-10-14T12:19:52.812Z","3.2.1-canary.131":"2022-10-14T12:57:48.367Z","3.2.1-canary.138":"2022-10-16T00:19:25.586Z","3.2.1-canary.139":"2022-10-25T22:07:28.780Z","3.2.1-canary.140":"2022-10-26T23:22:28.393Z","3.2.1-canary.141":"2022-10-26T23:48:17.461Z","3.2.1-canary.142":"2022-10-27T00:48:05.460Z","3.2.1-canary.143":"2022-10-27T00:57:54.257Z","3.2.1-canary.144":"2022-10-27T00:58:47.367Z","3.2.1-canary.147":"2022-10-27T01:06:05.829Z","3.2.1-canary.145":"2022-10-27T01:06:59.976Z","3.2.1-canary.146":"2022-10-27T01:07:55.197Z","3.2.1-canary.149":"2022-10-27T01:13:57.459Z","3.2.1-canary.148":"2022-10-27T01:16:26.114Z","3.2.1-canary.151":"2022-10-27T01:28:56.142Z","3.2.1-canary.156":"2022-10-27T19:41:53.043Z","3.2.1-canary.158":"2022-10-28T00:44:20.032Z","3.2.1-canary.159":"2022-10-30T00:15:46.202Z","3.2.1-canary.160":"2022-10-30T21:46:52.505Z","3.2.1-canary.161":"2022-10-31T12:28:17.841Z","3.2.1-canary.162":"2022-10-31T18:26:42.654Z","3.2.1-canary.163":"2022-10-31T22:14:41.274Z","3.2.1-canary.164":"2022-11-02T02:21:37.629Z","3.2.1-canary.165":"2022-11-02T18:41:34.034Z","3.2.1-canary.166":"2022-11-03T02:59:57.861Z","3.2.1-canary.167":"2022-11-03T07:57:25.973Z","3.2.1-canary.168":"2022-11-03T20:55:41.199Z","3.2.1-canary.169":"2022-11-03T21:44:38.012Z","3.2.1-canary.170":"2022-11-03T22:00:37.084Z","3.2.1-canary.171":"2022-11-03T22:02:59.783Z","4.0.0-canary.172":"2022-11-03T22:22:59.250Z","4.0.0-canary.173":"2022-11-04T17:27:12.412Z","4.0.0-canary.174":"2022-11-04T19:28:47.581Z","4.0.0-canary.177":"2022-11-05T07:45:19.353Z","4.0.0-canary.178":"2022-11-05T10:30:29.580Z","4.0.0-canary.179":"2022-11-05T18:49:58.979Z","4.0.0-canary.180":"2022-11-06T00:15:20.124Z","4.0.0-canary.182":"2022-11-07T17:36:14.908Z","4.0.0-canary.184":"2022-11-08T08:04:23.880Z","4.0.0-canary.185":"2022-11-08T13:41:52.613Z","4.0.0-canary.186":"2022-11-08T17:11:10.983Z","4.0.0-canary.187":"2022-11-08T20:37:48.625Z","4.0.0-canary.188":"2022-11-08T21:33:29.805Z","4.0.0-canary.189":"2022-11-09T00:43:47.407Z","4.0.0-canary.191":"2022-11-09T06:55:07.804Z","4.0.0-canary.192":"2022-11-09T09:23:56.295Z","4.0.0-canary.194":"2022-11-09T23:42:58.432Z","4.0.0-canary.195":"2022-11-09T23:55:34.310Z","4.0.0-canary.196":"2022-11-10T00:12:37.689Z","4.0.0-canary.197":"2022-11-10T00:38:16.817Z","4.0.0-canary.199":"2022-11-10T01:19:32.915Z","4.0.0-canary.200":"2022-11-10T03:01:28.292Z","4.0.0-canary.201":"2022-11-10T06:38:50.742Z","4.0.0-canary.204":"2022-11-10T23:02:20.009Z","4.0.0-canary.205":"2022-11-11T00:42:31.293Z","4.0.0-canary.206":"2022-11-11T01:44:08.710Z","4.0.0-canary.207":"2022-11-11T01:45:52.474Z","4.0.0-canary.208":"2022-11-11T02:37:02.463Z","4.0.0-canary.209":"2022-11-11T20:43:21.625Z","4.0.0-canary.210":"2022-11-11T22:25:19.091Z","4.0.0-canary.211":"2022-11-12T00:05:45.796Z","4.0.0-canary.213":"2022-11-12T00:09:02.960Z","4.0.0-canary.215":"2022-11-12T00:09:36.837Z","4.0.0-canary.214":"2022-11-12T00:10:37.390Z","4.0.0-canary.212":"2022-11-12T00:11:06.392Z","4.0.0-canary.217":"2022-11-12T02:22:20.576Z","4.0.0-canary.219":"2022-11-12T02:24:47.220Z","4.0.0-canary.220":"2022-11-12T02:53:47.358Z","4.0.0-canary.221":"2022-11-12T21:03:30.924Z","4.0.0-canary.222":"2022-11-12T21:05:11.433Z","4.0.0-canary.223":"2022-11-13T00:16:23.690Z","4.0.0-canary.224":"2022-11-13T02:39:10.801Z","4.0.0-canary.225":"2022-11-13T05:26:49.558Z","4.0.0-canary.226":"2022-11-13T07:51:42.760Z","4.0.0-canary.227":"2022-11-13T09:39:02.171Z","4.0.0-canary.229":"2022-11-13T14:38:29.224Z","4.0.0-canary.230":"2022-11-15T07:37:08.340Z","4.0.0-canary.231":"2022-11-16T18:40:23.232Z","4.0.0-canary.232":"2022-11-16T23:41:48.302Z","4.0.0-canary.233":"2022-11-17T19:15:53.320Z","4.0.0-canary.234":"2022-11-19T02:26:31.144Z","4.0.0-canary.235":"2022-11-20T00:18:27.503Z","4.0.0-canary.236":"2022-11-21T17:54:15.674Z","4.0.0-canary.237":"2022-11-21T18:44:49.757Z","4.0.0-canary.238":"2022-11-21T18:45:48.381Z","4.0.0-canary.239":"2022-11-21T19:22:33.925Z","4.0.0-canary.240":"2022-11-21T22:23:02.038Z","4.0.0-canary.241":"2022-11-21T23:24:09.537Z","4.0.0-canary.242":"2022-11-22T04:13:55.775Z","4.0.0-canary.243":"2022-11-22T07:54:45.683Z","4.0.0-canary.244":"2022-11-24T01:36:37.302Z","4.0.0-canary.245":"2022-11-24T01:38:21.965Z","4.0.0-canary.247":"2022-11-24T02:26:41.891Z","4.0.0-canary.248":"2022-11-24T05:50:55.451Z","4.0.0-canary.249":"2022-11-24T07:21:27.746Z","4.0.0-canary.250":"2022-11-24T10:47:02.466Z","4.0.0-canary.251":"2022-11-24T15:19:04.635Z","4.0.0-canary.252":"2022-11-24T15:54:31.596Z","4.0.0-canary.253":"2022-11-24T16:05:35.907Z","4.0.0-canary.256":"2022-11-24T17:57:22.673Z","4.0.0-canary.257":"2022-11-24T21:14:54.440Z","4.0.0-canary.258":"2022-11-25T23:56:54.054Z","4.0.0-canary.260":"2022-11-28T15:12:53.205Z","4.0.0-canary.261":"2022-11-28T17:07:41.327Z","4.0.0-canary.262":"2022-11-28T18:54:31.012Z","4.0.0-canary.264":"2022-11-28T20:14:18.537Z","4.0.0-canary.265":"2022-11-28T21:29:52.737Z","4.0.0-canary.266":"2022-11-28T22:11:46.748Z","4.0.0-canary.267":"2022-11-28T22:13:06.491Z","4.0.0-canary.268":"2022-11-28T22:13:35.879Z","4.0.0-canary.269":"2022-11-28T22:13:59.702Z","4.0.0-canary.278":"2022-11-30T19:19:09.047Z","4.0.0-canary.279":"2022-11-30T21:57:38.263Z","4.0.0-canary.280":"2022-11-30T23:41:33.406Z","4.0.0-canary.299":"2022-12-06T06:37:28.948Z","4.0.0-canary.301":"2022-12-06T11:36:33.423Z","4.0.0-canary.302":"2022-12-06T16:24:37.406Z","4.0.0-canary.304":"2022-12-06T18:28:21.253Z","4.0.0-canary.306":"2022-12-07T05:56:40.810Z","4.0.0-canary.307":"2022-12-07T06:54:30.869Z","4.0.0-canary.308":"2022-12-07T10:03:55.388Z","4.0.0-canary.309":"2022-12-07T14:12:00.806Z","4.0.0-canary.310":"2022-12-07T19:36:20.150Z","4.0.0-canary.311":"2022-12-07T19:54:10.585Z","4.0.0-canary.312":"2022-12-07T19:59:09.816Z","4.0.0-canary.313":"2022-12-08T06:34:24.635Z","4.0.0-canary.315":"2022-12-08T06:37:28.847Z","4.0.0-canary.314":"2022-12-08T06:38:13.053Z","4.0.0-canary.316":"2022-12-08T06:38:46.271Z","4.0.0-canary.318":"2022-12-08T17:38:09.682Z","4.0.0-canary.319":"2022-12-08T18:26:41.684Z","4.0.0-canary.320":"2022-12-08T22:33:12.926Z","4.0.0-canary.322":"2022-12-08T22:36:39.753Z","4.0.0-canary.321":"2022-12-08T22:40:11.093Z","4.0.0-canary.323":"2022-12-09T03:54:14.270Z","4.0.0-canary.324":"2022-12-09T04:03:52.111Z","4.0.0-canary.325":"2022-12-09T09:54:56.840Z","4.0.0-canary.326":"2022-12-09T15:25:54.412Z","4.0.0-canary.327":"2022-12-09T16:59:22.200Z","4.0.0-canary.328":"2022-12-09T17:01:20.724Z","4.0.0-canary.329":"2022-12-09T17:03:56.854Z","4.0.0-canary.330":"2022-12-09T18:55:57.838Z","4.0.0-canary.332":"2022-12-09T21:03:37.286Z","4.0.0-canary.334":"2022-12-09T21:04:33.221Z","4.0.0-canary.331":"2022-12-09T21:06:53.812Z","4.0.0-canary.333":"2022-12-09T21:08:41.535Z","4.0.0-canary.336":"2022-12-09T23:27:09.112Z","4.0.0-canary.337":"2022-12-09T23:29:33.544Z","4.0.0-canary.338":"2022-12-09T23:30:52.504Z","4.0.0-canary.339":"2022-12-09T23:35:53.608Z","4.0.0-canary.340":"2022-12-10T02:24:04.703Z","4.0.0-canary.341":"2022-12-10T05:01:09.438Z","4.0.0-canary.342":"2022-12-10T06:20:14.524Z","4.0.0-canary.343":"2022-12-10T09:12:25.313Z","4.0.0-canary.344":"2022-12-10T16:21:53.611Z","4.0.0-canary.345":"2022-12-10T23:02:01.952Z","4.0.0-canary.346":"2022-12-11T00:21:23.144Z","4.0.0-canary.347":"2022-12-11T03:37:56.724Z","4.0.0-canary.348":"2022-12-12T14:24:29.473Z","4.0.0-canary.350":"2022-12-12T18:50:20.713Z","4.0.0-canary.351":"2022-12-12T20:10:52.667Z","4.0.0-canary.353":"2022-12-12T21:12:17.258Z","4.0.0-canary.352":"2022-12-12T21:17:05.042Z","4.0.0-canary.354":"2022-12-12T21:24:34.306Z","4.0.0-canary.355":"2022-12-12T21:28:02.431Z","4.0.0-canary.356":"2022-12-12T21:28:23.185Z","4.0.0-canary.357":"2022-12-12T21:57:53.603Z","4.0.0-canary.358":"2022-12-12T22:56:36.526Z","4.0.0-canary.359":"2022-12-13T01:16:41.759Z","4.0.0-canary.360":"2022-12-13T02:05:41.003Z","4.0.0-canary.361":"2022-12-13T03:42:21.041Z","4.0.0-canary.364":"2022-12-13T09:28:46.207Z","4.0.0-canary.365":"2022-12-13T12:58:03.779Z","4.0.0-canary.366":"2022-12-13T15:39:39.079Z","4.0.0-canary.367":"2022-12-13T17:19:02.645Z","4.0.0-canary.368":"2022-12-13T22:08:28.420Z","4.0.0-canary.369":"2022-12-13T22:38:18.041Z","4.0.0-canary.370":"2022-12-13T23:00:12.317Z"},"bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"license":"MIT","homepage":"https://github.com/redwoodjs/redwood#readme","repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-web"},"description":"## Contributing","maintainers":[{"email":"peter.pistorius@gmail.com","name":"peter.pistorius"},{"email":"justnvdm@gmail.com","name":"justinvdm"}],"readme":"","readmeFilename":""}