{"_id":"@cedar-policy/cedar-authorization","_rev":"3-515906d5168ab6053715bd7e1b1f15b4","name":"@cedar-policy/cedar-authorization","dist-tags":{"latest":"0.2.0"},"versions":{"0.1.0":{"name":"@cedar-policy/cedar-authorization","version":"0.1.0","keywords":["expressjs","cedar","authorization"],"author":{"name":"swolebrain"},"license":"Apache-2.0","_id":"@cedar-policy/cedar-authorization@0.1.0","maintainers":[{"name":"szegheon-aws","email":"szegheon@amazon.com"},{"name":"morevct","email":"morevct@amazon.com"},{"name":"kevhak","email":"kevhak@amazon.com"},{"name":"cedar-wasm-team","email":"cedar-wasm-team@amazon.com"}],"homepage":"https://github.com/cedar-policy/express-authorization#readme","bugs":{"url":"https://github.com/cedar-policy/cedar-authorization/issues"},"bin":{"cedar-authorization":"dist/bin.js"},"dist":{"shasum":"6d9f95db930fff232dced2f774386cfb2a4f5fd3","tarball":"https://registry.npmjs.org/@cedar-policy/cedar-authorization/-/cedar-authorization-0.1.0.tgz","fileCount":15,"integrity":"sha512-muBBtzXpW+kFPUK60iyplkHHz38U9hBG/X9iaV4VDPiuIAzhCrBPiwl0FuRK0E8gJJ90scMZrrw/1bqn4cJjyA==","signatures":[{"sig":"MEQCHy6vrD18K0RIIWwl/0Y10y514+Bhuu/8wHDEMzSJElUCIQDFY+mPmzU/dd8bclXltuZZ1hMK+yd0UaeGsA3/0DixiQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":264654},"main":"dist/index.js","types":"dist/index.d.ts","module":"./dist/index.mjs","gitHead":"011ca22fd602124e240c4a477bce53d7f2afb4ba","scripts":{"test":"vitest run","build":"tsup","test:watch":"vitest"},"_npmUser":{"name":"cedar-wasm-team","email":"cedar-wasm-team@amazon.com"},"repository":{"url":"git+https://github.com/cedar-policy/cedar-authorization.git","type":"git"},"_npmVersion":"10.5.0","description":"JS/TS tools for authorization with the Cedar language","directories":{},"_nodeVersion":"18.20.2","dependencies":{"yargs":"^17.7.2","lodash":"^4.17.21","@cedar-policy/cedar-wasm":"4.4.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.0","vitest":"^3.2.3","ts-node":"^10.9.2","fast-check":"^4.1.1","typescript":"^5.8.3","@types/node":"^20.11.24","@types/yargs":"^17.0.32","@types/lodash":"^4.17.17","openapi-types":"^12.1.3"},"_npmOperationalInternal":{"tmp":"tmp/cedar-authorization_0.1.0_1750085627125_0.8266574099230775","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@cedar-policy/cedar-authorization","version":"0.1.1","keywords":["expressjs","cedar","authorization"],"author":{"name":"swolebrain"},"license":"Apache-2.0","_id":"@cedar-policy/cedar-authorization@0.1.1","maintainers":[{"name":"szegheon-aws","email":"szegheon@amazon.com"},{"name":"morevct","email":"morevct@amazon.com"},{"name":"kevhak","email":"kevhak@amazon.com"},{"name":"cedar-wasm-team","email":"cedar-wasm-team@amazon.com"}],"homepage":"https://github.com/cedar-policy/express-authorization#readme","bugs":{"url":"https://github.com/cedar-policy/cedar-authorization/issues"},"bin":{"cedar-authorization":"dist/bin.js"},"dist":{"shasum":"410e8b1fd7480873b349234109bfc20e4175a4f4","tarball":"https://registry.npmjs.org/@cedar-policy/cedar-authorization/-/cedar-authorization-0.1.1.tgz","fileCount":15,"integrity":"sha512-YhjKQsS8+TO/6QNidxBbVlcQdoKtbiFFBeBZWAuyeId01Js1gGojhsn5aZZ2C86LgMEfWwaRDgRhnbxE0KLlug==","signatures":[{"sig":"MEUCIQCB2a7kzq+XvzxLSlHAG7I2en+//PiWwUFfnOEEJjOpigIgGB+wcnCg2B7yE1zO0GPcoEh4uMy1u9IfoqmlQYS3vnQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@cedar-policy%2fcedar-authorization@0.1.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":271632},"main":"dist/index.js","types":"dist/index.d.ts","module":"./dist/index.mjs","gitHead":"435451372502b4798457f6d7abf5103905a31f6c","scripts":{"test":"vitest run","build":"tsup","test:watch":"vitest"},"_npmUser":{"name":"cedar-wasm-team","actor":{"name":"cedar-wasm-team","type":"user","email":"cedar-wasm-team@amazon.com"},"email":"cedar-wasm-team@amazon.com"},"repository":{"url":"git+https://github.com/cedar-policy/cedar-authorization.git","type":"git"},"_npmVersion":"10.8.2","description":"JS/TS tools for authorization with the Cedar language","directories":{},"_nodeVersion":"20.19.2","dependencies":{"yargs":"^17.7.2","lodash":"^4.17.21","@cedar-policy/cedar-wasm":"4.4.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.0","vitest":"^3.2.3","ts-node":"^10.9.2","fast-check":"^4.1.1","typescript":"^5.8.3","@types/node":"^20.11.24","@types/yargs":"^17.0.32","@types/lodash":"^4.17.17","openapi-types":"^12.1.3"},"_npmOperationalInternal":{"tmp":"tmp/cedar-authorization_0.1.1_1750951065645_0.5182229586039542","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@cedar-policy/cedar-authorization","version":"0.2.0","description":"JS/TS tools for authorization with the Cedar language","main":"dist/index.js","module":"./dist/index.mjs","types":"dist/index.d.ts","scripts":{"test":"vitest run --pool=forks","test:watch":"vitest","build":"tsup"},"repository":{"type":"git","url":"git+https://github.com/cedar-policy/cedar-authorization.git"},"keywords":["expressjs","cedar","authorization"],"author":{"name":"swolebrain"},"license":"Apache-2.0","bugs":{"url":"https://github.com/cedar-policy/cedar-authorization/issues"},"homepage":"https://github.com/cedar-policy/express-authorization#readme","dependencies":{"@cedar-policy/cedar-wasm":"^4.9.1","lodash":"^4.17.21","vite":"^8.0.3","yargs":"^17.7.2"},"devDependencies":{"@types/lodash":"^4.17.17","@types/node":"^20.11.24","@types/yargs":"^17.0.32","fast-check":"^4.1.1","openapi-types":"^12.1.3","ts-node":"^10.9.2","tsup":"^8.5.0","typescript":"^5.8.3","vitest":"^3.2.3"},"bin":{"cedar-authorization":"dist/bin.js"},"gitHead":"a4d1b706acfe021ef9c2d8e9e2a9f58ad261d101","_id":"@cedar-policy/cedar-authorization@0.2.0","_nodeVersion":"24.14.0","_npmVersion":"11.9.0","dist":{"integrity":"sha512-GIAb7sk209ymU+55uPEzqM9cv4I/5VeOAqEH9CcNMuI0zKbEL1ZcY+ZtU6mK3O/mcwRjKdTuQl9pe230MyzjnA==","shasum":"b54a59df94715131202c80949087dbd562f6bdf3","tarball":"https://registry.npmjs.org/@cedar-policy/cedar-authorization/-/cedar-authorization-0.2.0.tgz","fileCount":15,"unpackedSize":271732,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@cedar-policy%2fcedar-authorization@0.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIEDVW9Xuey8rgV4Qj/+iwOHtODEzyuEbinairqc1FU1DAiBl0+fpUXKWTWDhRRF2+ZpiiKZde5uTRcYJ3o/cj87qWQ=="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:84e984c5-ce0c-4b7a-acd3-85f95351e5a7"}},"directories":{},"maintainers":[{"name":"szegheon-aws","email":"szegheon@amazon.com"},{"name":"morevct","email":"morevct@amazon.com"},{"name":"kevhak","email":"kevhak@amazon.com"},{"name":"cedar-wasm-team","email":"cedar-wasm-team@amazon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/cedar-authorization_0.2.0_1774615456508_0.6937622933404566"},"_hasShrinkwrap":false}},"time":{"created":"2025-06-16T14:53:47.010Z","modified":"2026-03-27T12:44:17.023Z","0.1.0":"2025-06-16T14:53:47.299Z","0.1.1":"2025-06-26T15:17:45.817Z","0.2.0":"2026-03-27T12:44:16.682Z"},"bugs":{"url":"https://github.com/cedar-policy/cedar-authorization/issues"},"author":{"name":"swolebrain"},"license":"Apache-2.0","homepage":"https://github.com/cedar-policy/express-authorization#readme","keywords":["expressjs","cedar","authorization"],"repository":{"type":"git","url":"git+https://github.com/cedar-policy/cedar-authorization.git"},"description":"JS/TS tools for authorization with the Cedar language","maintainers":[{"name":"szegheon-aws","email":"szegheon@amazon.com"},{"name":"morevct","email":"morevct@amazon.com"},{"name":"kevhak","email":"kevhak@amazon.com"},{"name":"cedar-wasm-team","email":"cedar-wasm-team@amazon.com"}],"readme":"## Cedar-Authorization\n\nA JavaScript/TypeScript library for authorization with the Cedar policy language. This package provides tools to integrate Cedar authorization into your applications, generate schemas from OpenAPI specifications, and manage authorization policies.\n\n### Installation\n\n```\nnpm i --save @cedar-policy/cedar-authorization\n```\n### Features\n\n* Authorization Engine: Implement authorization checks using Cedar policies\n\n* Schema Generation: Generate Cedar schemas from OpenAPI specifications\n\n* Policy Generation: Create starter policies based on your schema\n\n* CLI Tools: Command-line utilities for schema and policy generation\n\n### Usage\n\n#### Authorization Engine\n\nThis package provides an interface for an \"Authorization Engine\" which takes a Cedar request and entities, and returns an authorization result.\n\nYou may find example usages here: https://github.com/cedar-policy/cedar-authorization/blob/main/tests/cedarAuthorizer.test.ts\n\n#### CLI Tools\n\n**Schema Generation: Generate Cedar schemas from OpenAPI specifications**\n\n```\nnpx @cedar-policy/cedar-authorization generate-schema \\\n  --api-spec path/to/openapi.json \\\n  --namespace YourNamespace \\\n  --mapping-type SimpleRest\n```\n\nThis will generate two schema files:\n\nv2.cedarschema.json - Compatible with Cedar 2.x and 3.x\n\nv4.cedarschema.json - Compatible with Cedar 4.x and required by the nodejs Cedar plugins\n\nWhen generating OpenApi specs, keep the following limitations in mind:\n\n1. Version Support:\n- Only OpenAPI v3 specifications are supported (uses OpenAPIV3 types from openapi-types)\n- Earlier versions (like Swagger 2.0) are not supported\n\n2. Namespace Requirements:\n- Must have exactly one namespace\n- Namespace must follow strict formatting rules:\n  - Must start with a letter or underscore\n  - Can only include alphanumeric characters and underscores\n  - Components can be separated by double colons (::)\n  - Each component must start with a letter or underscore\n- Cannot use reserved words as namespaces ('if', 'in', 'is', '__cedar')\n\n3. Schema Limitations:\n- Only supports local schema references (must start with '#/components/schemas/') - can't link to a separate openApi file or url.\n\n4. Parameter Restrictions for operations:\n- Only supports 'path' and 'query' parameter types\n- Other parameter types (like header, cookie) are skipped with a warning\n- Parameters defined as direct $ref are not supported\n- Parameters must have \"name\", \"schema\", and \"in\" properties\n\n5. Server Configuration:\n- If multiple servers are defined in the OpenAPI spec, a basePath parameter is required\n- The provided basePath must match one of the server entries\n- Server URLs must be valid URLs that can be parsed\n\n6. Operation/Path Requirements:\n- Only supports standard HTTP methods (defined in SUPPORTED_HTTP_METHODS)\n- OPTIONS method is explicitly ignored\n- Each operation must have valid operation objects\n- x-cedar extensions, if present, must have valid appliesToResourceTypes\n\n7. Resource Type Limitations:\n- Default resource types (User, UserGroup, Application) are automatically included\n- Custom resource types must be referenced in action definitions\n- If a resource type is referenced but not defined in schemas, it gets an empty record shape\n\nThese limitations mean that complex OpenAPI specs with advanced features like non-standard extensions or sophisticated parameter types may not be fully supported by the tool.\n\n**Policy Generation: Create starter policies based on your schema**\n\n```\nnpx @cedar-policy/cedar-authorization generate-policies \\\n  --schema path/to/schema.json\n```\nThis will create policy files in a policies directory with starter policies based on your schema.\n\n\nCLI Tools: Command-line utilities for schema and policy generation\n\n### API Reference\n\n#### Core Types\n\n```typescript\ninterface AuthorizationRequest {\n  principal: EntityUid;\n  action: EntityUid;\n  resource: EntityUid;\n  context: Record<string, CedarValueJson>;\n}\n\ninterface Entity {\n  uid: EntityUid;\n  attrs: Record<string, CedarValueJson>;\n  parents: EntityUid[];\n}\n\ntype AuthorizationResult =\n  { type: 'deny' } |\n  { type: 'allow', authorizerInfo: AuthorizationResultInformation } |\n  { type: 'error', message: string };\n```\n\n#### CedarInlineAuthorizationEngine\n\n```typescript\nclass CedarInlineAuthorizationEngine implements AuthorizationEngine {\n  constructor(config: CedarInlineAuthorizerConfiguration);\n  isAuthorized(request: AuthorizationRequest, entities: Entity[]): Promise<AuthorizationResult>;\n}\n```\n\n\n## Security\n\nSee [CONTRIBUTING](CONTRIBUTING.md#security-issue-notifications) for more information.\n\n## License\n\nThis project is licensed under the Apache-2.0 License.\n\n## Publishing\n\nPublishing to npm is done according to these links:\n\n- https://docs.github.com/en/actions/use-cases-and-examples/publishing-packages/publishing-nodejs-packages  \n- https://docs.github.com/en/repositories/releasing-projects-on-github/managing-releases-in-a-repository#creating-a-release  ","readmeFilename":"README.md"}