{"_id":"apostrophe-proxy-auth","_rev":"45-b028c4daea3bebab1c8e13d435a2a711","name":"apostrophe-proxy-auth","dist-tags":{"latest":"0.5.5"},"versions":{"0.5.0":{"name":"apostrophe-proxy-auth","version":"0.5.0","keywords":["authentication","apostrophe","cms","cosign","shibboleth","weblogin","basic auth"],"author":{"name":"P'unk Avenue LLC"},"license":"MIT","_id":"apostrophe-proxy-auth@0.5.0","maintainers":[{"name":"boutell","email":"boutell@boutell.com"}],"homepage":"https://github.com/punkave/apostrophe-proxy-auth","bugs":{"url":"https://github.com/punkave/apostrophe-proxy-auth/issues"},"dist":{"shasum":"4b245ccf86822634e2c4a17b9315bf28651bead8","tarball":"https://registry.npmjs.org/apostrophe-proxy-auth/-/apostrophe-proxy-auth-0.5.0.tgz","integrity":"sha512-qS6Qtk6rcHQy95l/xgUaaSR7xXdsuNzUIMhlaq050f/dP67jVgTbNpmeqNjcxCvtXj+z9K76dERNNZDY1Loj7w==","signatures":[{"sig":"MEQCIGloIwkCNZ5ZlAOMEumwOVjUvhUp2abDBowiWar4FmpUAiA9fZeT4Iu2v6cQrIZ7oTQvvYynqbM6R46FxE93daSUlg==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}]},"main":"index.js","_from":".","_shasum":"4b245ccf86822634e2c4a17b9315bf28651bead8","scripts":{"test":"echo \"Error: no test specified\" && exit 1"},"_npmUser":{"name":"boutell","email":"boutell@boutell.com"},"repository":{"url":"https://github.com/punkave/apostrophe-proxy-auth","type":"git"},"_npmVersion":"1.4.9","description":"Log into Apostrophe via weblogin, cosign, shibboleth, basic auth, etc. with an Apache reverse proxy server","directories":{},"dependencies":{"async":"^0.9.0","lodash":"^2.4.1"}},"0.5.1":{"name":"apostrophe-proxy-auth","version":"0.5.1","keywords":["authentication","apostrophe","cms","cosign","shibboleth","weblogin","basic auth"],"author":{"name":"P'unk Avenue LLC"},"license":"MIT","_id":"apostrophe-proxy-auth@0.5.1","maintainers":[{"name":"boutell","email":"boutell@boutell.com"}],"homepage":"https://github.com/punkave/apostrophe-proxy-auth","bugs":{"url":"https://github.com/punkave/apostrophe-proxy-auth/issues"},"dist":{"shasum":"77e5c7b6d0521b73923108b9ba6310c5d0dddca5","tarball":"https://registry.npmjs.org/apostrophe-proxy-auth/-/apostrophe-proxy-auth-0.5.1.tgz","integrity":"sha512-9I+4pgL64KUTUHiUbJXvj3OSaejHb5ms6l/XTT8EJAOz7c5JA7voFjo+nZy5K08Vj9swY91p/eNoAqPxie02qw==","signatures":[{"sig":"MEQCIF8g8nKBzT0JxtgnaqOgkAQFaUJ4548rxpdHXOqKUImVAiBkG8PZYM0fAFSOFhwEI/c1XOGqYR01uDlNMtfESCr5yg==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}]},"main":"index.js","_from":".","_shasum":"77e5c7b6d0521b73923108b9ba6310c5d0dddca5","scripts":{"test":"echo \"Error: no test specified\" && exit 1"},"_npmUser":{"name":"boutell","email":"boutell@boutell.com"},"repository":{"url":"https://github.com/punkave/apostrophe-proxy-auth","type":"git"},"_npmVersion":"1.4.9","description":"Log into Apostrophe via weblogin, cosign, shibboleth, basic auth, etc. with an Apache reverse proxy server","directories":{},"dependencies":{"async":"^0.9.0","lodash":"^2.4.1"}},"0.5.2":{"name":"apostrophe-proxy-auth","version":"0.5.2","keywords":["authentication","apostrophe","cms","cosign","shibboleth","weblogin","basic auth"],"author":{"name":"P'unk Avenue LLC"},"license":"MIT","_id":"apostrophe-proxy-auth@0.5.2","maintainers":[{"name":"boutell","email":"boutell@boutell.com"}],"homepage":"https://github.com/punkave/apostrophe-proxy-auth","bugs":{"url":"https://github.com/punkave/apostrophe-proxy-auth/issues"},"dist":{"shasum":"0c2b186ae4e2004f0b3aa07ab880469e26340c65","tarball":"https://registry.npmjs.org/apostrophe-proxy-auth/-/apostrophe-proxy-auth-0.5.2.tgz","integrity":"sha512-gpSP2WleLxfp61oiXrbMJTxdrQoe8Y7ZgxF3Bm6wZqme6249vHoG6jQkZgLBSsjCzCBED3+BSkp9WDNdgZXVbA==","signatures":[{"sig":"MEUCIQChUx1IthTQTRMMCeFEjVeV3aTOjZc5cHQN0KHhhcTLvQIgOA6Lk/k2gw9s/Z6e9kxPfUhiD4M21OMjR3o2F/w/3vg=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}]},"main":"index.js","_from":".","_shasum":"0c2b186ae4e2004f0b3aa07ab880469e26340c65","scripts":{"test":"echo \"Error: no test specified\" && exit 1"},"_npmUser":{"name":"boutell","email":"boutell@boutell.com"},"repository":{"url":"https://github.com/punkave/apostrophe-proxy-auth","type":"git"},"_npmVersion":"1.4.9","description":"Log into Apostrophe via weblogin, cosign, shibboleth, basic auth, etc. with an Apache reverse proxy server","directories":{},"dependencies":{"async":"^0.9.0","lodash":"^2.4.1"}},"0.5.3":{"name":"apostrophe-proxy-auth","version":"0.5.3","keywords":["authentication","apostrophe","cms","cosign","shibboleth","weblogin","basic auth"],"author":{"name":"P'unk Avenue LLC"},"license":"MIT","_id":"apostrophe-proxy-auth@0.5.3","maintainers":[{"name":"boutell","email":"boutell@boutell.com"}],"homepage":"https://github.com/punkave/apostrophe-proxy-auth","bugs":{"url":"https://github.com/punkave/apostrophe-proxy-auth/issues"},"dist":{"shasum":"d7a2d89580a68a1cc7f99521e8e3e72a8e686284","tarball":"https://registry.npmjs.org/apostrophe-proxy-auth/-/apostrophe-proxy-auth-0.5.3.tgz","integrity":"sha512-xS2oSlDG5bT9+I4YLGFuhKALxkmSTsAEdP8Eck/gUsTnAhoAu9xmWnYkR55wVkL1vNkXQbSahcOacDNaLbst1w==","signatures":[{"sig":"MEUCIHXPPdjUt1tlmvGMt4pSFY5n+o7DZyclszhUObOFuYS2AiEA5KVyE23ft31yxHONGW5rbuC4IhO4CaBpN41eZdG/+hk=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}]},"main":"index.js","_from":".","_shasum":"d7a2d89580a68a1cc7f99521e8e3e72a8e686284","scripts":{"test":"echo \"Error: no test specified\" && exit 1"},"_npmUser":{"name":"boutell","email":"boutell@boutell.com"},"repository":{"url":"https://github.com/punkave/apostrophe-proxy-auth","type":"git"},"_npmVersion":"1.4.9","description":"Log into Apostrophe via weblogin, cosign, shibboleth, basic auth, etc. with an Apache reverse proxy server","directories":{},"dependencies":{"async":"^0.9.0","lodash":"^2.4.1"}},"0.5.4":{"name":"apostrophe-proxy-auth","version":"0.5.4","keywords":["authentication","apostrophe","cms","cosign","shibboleth","weblogin","basic auth"],"author":{"name":"P'unk Avenue LLC"},"license":"MIT","_id":"apostrophe-proxy-auth@0.5.4","maintainers":[{"name":"boutell","email":"boutell@boutell.com"}],"homepage":"https://github.com/punkave/apostrophe-proxy-auth","bugs":{"url":"https://github.com/punkave/apostrophe-proxy-auth/issues"},"dist":{"shasum":"bc824213f5bcadd2fee6ce853b72b62a9e4eea2d","tarball":"https://registry.npmjs.org/apostrophe-proxy-auth/-/apostrophe-proxy-auth-0.5.4.tgz","integrity":"sha512-w3f3LHazYDwalzsJBLYJwa5iGbaxDrMr9RgFvEa6MG/Q8hAY+UV3DFMnLOq8v6muA8kqrbOZ6o+34CYdVqOoOg==","signatures":[{"sig":"MEQCIFAyyBqgSIszLCysXapHqnNUx7auf/S+SFl0e4HF5HbOAiBh8Nkjcz6D1umRZx+UU/Kyzsn2QZysPvNNp65a91ZFEw==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}]},"main":"index.js","_from":".","_shasum":"bc824213f5bcadd2fee6ce853b72b62a9e4eea2d","scripts":{"test":"echo \"Error: no test specified\" && exit 1"},"_npmUser":{"name":"boutell","email":"boutell@boutell.com"},"repository":{"url":"https://github.com/punkave/apostrophe-proxy-auth","type":"git"},"_npmVersion":"1.4.9","description":"Log into Apostrophe via weblogin, cosign, shibboleth, basic auth, etc. with an Apache reverse proxy server","directories":{},"dependencies":{"async":"^0.9.0","lodash":"^2.4.1"}},"0.5.5":{"name":"apostrophe-proxy-auth","version":"0.5.5","keywords":["authentication","apostrophe","cms","cosign","shibboleth","weblogin","basic auth"],"author":{"name":"P'unk Avenue LLC"},"license":"MIT","_id":"apostrophe-proxy-auth@0.5.5","maintainers":[{"name":"boutell","email":"boutell@boutell.com"}],"homepage":"https://github.com/punkave/apostrophe-proxy-auth","bugs":{"url":"https://github.com/punkave/apostrophe-proxy-auth/issues"},"dist":{"shasum":"e128472100c64370cc46a02e321536e91940a6ef","tarball":"https://registry.npmjs.org/apostrophe-proxy-auth/-/apostrophe-proxy-auth-0.5.5.tgz","integrity":"sha512-2zVmtyUOQtuQ7AYl2VM3nvxZsDEdRgKoTtgrBj/8A7DChBzPSULDQpoTr3oOxZcOskXAv14UcpwQnwGO2SQMlw==","signatures":[{"sig":"MEQCIB1xboWk+8Uj1KhLsteqJwQXfpUmzBBU9A8crM5wY4WXAiAGnQcY9i2ttp7Ofl4Ve7O8SODhcJolc4iTxZ6HBszTgg==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}]},"main":"index.js","_from":".","_shasum":"e128472100c64370cc46a02e321536e91940a6ef","scripts":{"test":"echo \"Error: no test specified\" && exit 1"},"_npmUser":{"name":"boutell","email":"boutell@boutell.com"},"repository":{"url":"https://github.com/punkave/apostrophe-proxy-auth","type":"git"},"_npmVersion":"1.4.9","description":"Log into Apostrophe via weblogin, cosign, shibboleth, basic auth, etc. with an Apache reverse proxy server","directories":{},"dependencies":{"async":"^0.9.0","lodash":"^2.4.1"}}},"time":{"created":"2014-07-29T14:47:05.922Z","modified":"2026-01-26T19:09:51.884Z","0.5.0":"2014-07-29T14:47:05.922Z","0.5.1":"2014-07-29T15:54:19.083Z","0.5.2":"2014-07-29T16:02:41.795Z","0.5.3":"2014-07-29T16:04:27.500Z","0.5.4":"2014-07-29T16:51:41.993Z","0.5.5":"2014-08-07T20:26:06.637Z"},"bugs":{"url":"https://github.com/punkave/apostrophe-proxy-auth/issues"},"author":{"name":"P'unk Avenue LLC"},"license":"MIT","homepage":"https://github.com/punkave/apostrophe-proxy-auth","keywords":["authentication","apostrophe","cms","cosign","shibboleth","weblogin","basic auth"],"repository":{"url":"https://github.com/punkave/apostrophe-proxy-auth","type":"git"},"description":"Log into Apostrophe via weblogin, cosign, shibboleth, basic auth, etc. with an Apache reverse proxy server","maintainers":[{"email":"alex@apostrophecms.com","name":"alexgilbert"},{"email":"tom@apostrophecms.com","name":"boutell"},{"email":"stuart+npm@apostrophecms.com","name":"romanek"},{"email":"robert.means1969+apostrophecms@gmail.com","name":"bodonkey"},{"email":"kerry@punkave.com","name":"colpanik"},{"email":"stuart@punkave.com","name":"stuartromanek"},{"email":"mcoppola832@gmail.com","name":"mcoppola"},{"email":"jimmy@punkave.com","name":"jimmyh"},{"email":"austin.starin@gmail.com","name":"austinstarin"},{"email":"ajchappelle@gmail.com","name":"arti5m"},{"email":"grdunn@gmail.com","name":"grdunn"},{"email":"bgantick@gmail.com","name":"bgantick"},{"email":"matthew.mance@gmail.com","name":"mtthwmnc"}],"readme":"# apostrophe-proxy-auth\n\nSometimes you want users to log in via weblogin, cosign, Shibboleth, basic auth or other authentication methods that are not available natively in node. In these situations, you'll want to set up Apache as a reverse proxy, and pass the authenticated user's name to node and Apostrophe. This module allows [Apostrophe](https://apostrophenow.org) to recognize such logins once they arrive.\n\nThis documentation also covers how to configure Apache for use with this module in a typical higher education environment with cosign (aka weblogin).\n\nThis module does *not* implement weblogin, cosign, basic auth or Shibboleth directly. Instead it relies on Apache to do that, and accepts Apache's word for it when a username is presented via an HTTP header. We'll demonstrate how to ensure that this information is authentic.\n\nThis module is not for CAS (Centralized Authentication Service). Use [apostrophe-cas](https://github.com/punkave/apostrophe-cas) instead.\n\n## Installation\n\nnpm install --save apostrophe-proxy-auth\n\n## Configuration\n\nAdd the module to the `modules` section of your `app.js` file:\n\n```javascript\n    'apostrophe-proxy-auth': {\n    }\n```\n\nNext, make sure you shut off the regular authentication system. This is a top-level option in `app.js` (that is, it's not inside \"modules,\" it's at the same level as \"modules\"):\n\n```javascript\n  auth: false\n```\n\nNow the usual `/login` form is replaced with code that simply recognizes when a username has been provided by Apache.\n\n## SECURE YOUR SITE CORRECTLY\n\nOn your server, as the non-root user with which you deploy Apostrophe, create `/opt/stagecoach/apps/mysite/data/address` and populate it with:\n\n```\n127.0.0.1\n```\n\n**Otherwise admin user accounts can be spoofed with this module by any moderately talented monkey. You have been warned.**\n\n*What this does:* we'll be trusting the reverse proxy server to provide the authenticated user's name. So we must only accept connections from the reverse proxy, never direct connections. We accomplish this by accepting connections only on the `127.0.0.1` interface (localhost). Here I assume your reverse proxy runs on the same server, which I recommend anyway for performance.\n\n*Never run Apostrophe on shared hosting. Always use a VPS or dedicated server.* But you already knew that.\n\n## Configuring Apache for Cosign\n\nI'll assume you're using Ubuntu Linux. Most of these steps would also apply to other distributions.\n\n**If your node site is already up and running behind some other proxy, like nginx, you need to shut it down and uninstall it: service nginx stop && apt-get remove nginx**\n\nInstall Apache (all commands are as root):\n\n```\napt-get install apache2\n```\n\nEnable the reverse proxy module and its HTTP protocol module:\n\n```\na2enmod proxy\na2enmod proxy_http\n```\n\nNow install the `apache2-dev` Ubuntu package on the server so cosign can compile:\n\n```\napt-get install apache2-dev\n```\n\nNow [go get the latest CoSign 3.x source code](http://weblogin.org/download.shtml\n).\n\nUntar the file in /usr/local/src.\n\n`cd` into the `cosign-3.x.x` folder, then:\n\n```\n./configure --enable-apache2=/usr/bin/apxs2 && make install\n```\n\nThis will take care of setting up the directives to load the cosign module on the next Apache restart.\n\n## Creating the Cache Folder\n\nThe Apache cosign module needs a cache folder. Be sure to create it. Give it to the non-root user and group that Apache is running as, typically `www-data`:\n\n```bash\nmkdir -p /var/cache/cosign/filter\n\nchown -R www-data.www-data /var/cache/cosign/filter\n```\n\n## Configuration Files\n\nHere I assume your site is secured with SSL. Clients who use cosign and similar systems will almost always require it. You will typically need to obtain a certificate for your site's subdomain through the client.\n\nCreate the `/etc/apache2/cosign` folder:\n\n```\nmkdir /etc/apache2/cosign\n```\n\n**Populate this folder with the certificate and key files provided by your customer.** For PRE-PRODUCTION, you may use the certificate and key files for the SSL protection of the website, as well as for cosign. (Users will see browser warnings.) For PRODUCTION, you will need SEPARATE certificates and keys for cosign and for the actual website.\n\n**They may also provide a root CA (certificate authority) file** which should be copied to `/etc/ssl/certs`, under a name that does not conflict with other files there. After that, ask the system to rehash the root certificates:\n\n```bash\ncp cacert.pem /etc/ssl/certs/cosign-mysite-cacert.pem\nc_rehash .\n```\n\nFirst create `/etc/apache2/includes/weblogin.conf` and populate it with these directives needed for all sites using cosign. Here you'll need to replace `myschool.edu` with your customer's domain name, and also change `weblogin.myschool.edu` to your customer's weblogin host if it is different.\n\n```\nCosignProtected off\nCosignHostname weblogin.myschool.edu\nCosignRedirect https://weblogin.myschool.edu/login\nCosignPostErrorRedirect https://weblogin.myschool.edu/post_error.html\nCosignFilterDB /var/cache/cosign/filter\n\n# Let's allow logins from a test domain we use for our company's projects,\n# and also from the client's domain\nCosignValidReference https:\\/\\/.*\\.(mytestdomain\\.net|myschool\\.edu)/.*\nCosignValidationErrorRedirect http://weblogin.myschool.edu/validation_error.html\n\n# CoSign 3 requires a validation URL for each protected host.\n# This location MUST be available without any restrictions at the registered\n# URL (so don't CoSign-protect the entire host).\n<Location /cosign/valid>\n    SetHandler cosign\n    CosignProtected off\n    Allow from all\n    Satisfy any\n</Location>\n```\n\nNext, create `/etc/sites-enabled/mysite` and configure it to protect the `/login` URL with cosign and pass the `REMOTE_USER` environment variable on to node via a new HTTP header. Note that this header is always overridden, even if `REMOTE_USER` is empty. This prevents outsiders from \"spoofing\" accounts, as long as the node process only accepts connections from localhost.\n\n**Review this file carefully, you need to change several settings. This IS rocket science, be patient.** You must ask your customer's cosign administrator for the `CosignService` setting.\n\n**First edit your `/etc/apache2/ports file` and add `Listen 443` if you are not already configured for https on this site.\n\n```apache\n# Non-secured site: just redirect to the secured site\n<VirtualHost *:80>\n        ServerName mysite.myschool.edu\n        <Location />\n          RedirectMatch ^/(.*)$ https://mysite.myschool.edu/$1\n        </Location>\n        ErrorLog /var/log/apache2/mysite.error.log\n        CustomLog /var/log/apache2/mysite.access.log vhost_combined\n</VirtualHost>\n\n# Secured site: where the action is\n<VirtualHost *:443>\n  RewriteEngine on\n  ServerName mysite.myschool.edu\n\n  SSLEngine On\n  # Might or might not be the same file as the cosign certificates, check\n  # with your customer's cosign administrator\n  SSLCertificateFile /etc/apache2/cosign/mysite-0.crt\n  SSLCertificateKeyFile /etc/apache2/cosign/mysite-0.key\n\n  Include /etc/apache2/cosign/weblogin.conf\n\n  # This setting will be provided by your customer's cosign administrator\n  CosignService mysite-0\n\n  # Your customer will usually provide a certificate and key for use by\n  # cosign which might or might not also be the certificate and key for\n  # the site's public SSL; in this example the files are the same.\n  # The third argument points to a folder of trusted root certificates,\n  # usually /etc/ssl/certs\n\n  CosignCrypto /etc/apache2/cosign/mysite-0.key /etc/apache2/cosign/mysite-0.crt /etc/ssl/certs\n\n  # Reverse proxy, only for URLs that are NOT part of cosign\n  # authentication, which must be handled as configured in\n  # weblogin.conf and the /login block below\n  <LocationMatch \"^/(?!cosign)(.*)$\">\n    RequestHeader set x-remote-user %{REMOTE_USER}s\n    ProxyPassMatch http://localhost:3000/$1\n  </LocationMatch>\n\n  # Force login for this URL, set REMOTE_USER once they log in\n  <Location /login>\n    # Cosign before proxy\n    CosignProtected on\n    AuthType Cosign\n    Require valid-user\n    # Check this setting with your customer's cosign administrator\n    CosignRequireFactor MYSCHOOL.EDU\n  </Location>\n\n  ErrorLog /var/log/apache2/mysite-ssl.error.log\n  CustomLog /var/log/apache2/mysite-ssl.access.log vhost_combined\n</VirtualHost>\n```\n\nNow, assuming you configured Apache correctly and your node app is already listening on port 3000 with this module enabled, you're ready to go:\n\n```bash\nservice apache2 restart\n```\n\n### Creating Users On the Fly\n\nIn some cases, any person who can log into the reverse proxy should also be a valid account on your site.\n\nHere's how to automatically create new people on the fly:\n\n```javascript\n    'apostrophe-proxy-auth': {\n      createPerson: true\n    }\n```\n\n### Adding New Users to a Group\n\nBy default, users created on the fly are not added to any group. You can change that, and also set default permissions for the group if it does not already exist:\n\n```javascript\n    'apostrophe-proxy-auth': {\n      createPerson: {\n        group: {\n          name: 'guests',\n          permissions: [ 'guest' ]\n        }\n      }\n    }\n```\n\n### Forcing an Admin User\n\nYou can use the `admin` option to set a username that always receives full admin permissions upon logging in. This is convenient for bootstrapping a new site that uses weblogin, cosign, etc.\n\nFirst use the `admin` option to give your own account full privileges, then log in and add groups and permissions for other users.\n\n```javascript\n    `apostrophe-proxy-auth`: {\n      createPerson: true,\n      admin: 'jillrocks'\n    }\n```\n\n### Setting First Names, Last Names and Other Metadata\n\nSince basic auth only provides a username, Apostrophe sets the user's first and last name based on their username. If there is a system of record that can be contacted to learn more about the user, you can pass a `before` callback that phones it up via LDAP or a database call:\n\n```javascript\n    'apostrophe-proxy-auth': {\n      createPerson: {\n        before: function(req, person, callback) {\n          // Try querying your LDAP or database server\n          // with person.username\n\n          // ...All done, invoke the callback\n          return callback(null);\n        }\n      }\n    }\n```\n\nThere is also an `after` option, which takes the same arguments and is invoked after the person exists in the database. This is handy if you need their `_id` property.\n\n### Subclassing\n\nIf you prefer you can subclass the `apostrophe-proxy-auth` module and override the `beforeCreatePerson` and `afterCreatePerson` methods in your `index.js` file. You'll need to follow the same pattern used when subclassing `apostrophe-snippets`. If this is all new to you, just use the options.\n\n## Logging Out\n\nLogging out works out of the box. If you also want the user logged out of a larger campus \"single sign on\" environment, provide the `afterLogout` option. The user is redirected to this URL after logout. Ask your customer's cosign administrator what URL to use.\n\n```javascript\n    'apostrophe-proxy-auth': {\n      // Optional: implement single-sign-out\n      afterLogout: 'https://weblogin.myschool.edu/logout'\n    }\n```\n\n## Enabling the Module in Production Only\n\nYou may not wish to use this module in development environments where you don't have an authenticating reverse proxy. In such cases, just do your configuration on the production server in `/opt/stagecoach/apps/mysite/data/local.js` instead of `app.js`, like this:\n\n```javascript\nmodule.exports = {\n  auth: false,\n  modules: {\n    'apostrophe-proxy-auth': { }\n  }\n};\n```\n\nYou will likely have other directives here as well, like `minify: true`. Options here are merged with the options in `app.js`.\n\n","readmeFilename":"README.md"}