{"_id":"appattest-checker-node","_rev":"5-8cd48ca3a1b523ddf61d8eef536fa4ca","name":"appattest-checker-node","dist-tags":{"latest":"1.0.3"},"versions":{"0.5.0":{"name":"appattest-checker-node","version":"0.5.0","keywords":["nodejs","ios","apple-appattest","security"],"author":{"name":"Srinivas Visvanathan"},"license":"Apache-2.0","_id":"appattest-checker-node@0.5.0","maintainers":[{"name":"srinivas1729","email":"srn.npm.mostly.ignored@outlook.com"}],"homepage":"https://github.com/srinivas1729/appattest-checker-node#readme","bugs":{"url":"https://github.com/srinivas1729/appattest-checker-node/issues"},"dist":{"shasum":"430b45a3d691fc53f27c6ed77dcfaf76378823a2","tarball":"https://registry.npmjs.org/appattest-checker-node/-/appattest-checker-node-0.5.0.tgz","fileCount":15,"integrity":"sha512-rgZFheK7yfk53nOfAeXFxALqfA0QaEEbj7ixPE5+QRB4hHo74S+zaJrVpwvANjiIKFoWMo2BBDqVLc/rDuwPww==","signatures":[{"sig":"MEUCIBi4TOvJO5GcYejB3fIe34VCvCcPN7ph1roUCF2GKpkhAiEAy5SisJgj7E56lwy8hHDzenZy/+8PKTQLsU1OVFYYGYg=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":44581},"main":"dist/index.js","types":"dist/index.d.ts","gitHead":"972dbbe507e189beb111033bd74f0fb8b20e4017","scripts":{"lint":"eslint --ext .js,.ts","test":"jest","build":"tsc","format":"prettier --ignore-path .gitignore --write \"**/*.+(js|ts|json)\""},"_npmUser":{"name":"srinivas1729","email":"srn.npm.mostly.ignored@outlook.com"},"repository":{"url":"git+https://github.com/srinivas1729/appattest-checker-node.git","type":"git"},"_npmVersion":"10.2.4","description":"Node.JS library to check/verify iOS App Attest attestations & assertions","directories":{},"_nodeVersion":"21.6.1","dependencies":{"cbor":"^9.0.1","@types/node":"^20.11.0","@peculiar/x509":"^1.9.6","json-stable-stringify":"^1.1.1","@types/json-stable-stringify":"^1.0.36"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^29.7.0","eslint":"^8.56.0","ts-jest":"^29.1.1","prettier":"^3.1.1","typescript":"^5.3.3","@types/jest":"^29.5.11","@tsconfig/node-lts":"^20.1.1","eslint-config-prettier":"^9.1.0","@typescript-eslint/parser":"^6.18.1","@typescript-eslint/eslint-plugin":"^6.18.1"},"_npmOperationalInternal":{"tmp":"tmp/appattest-checker-node_0.5.0_1706664853844_0.2688548154079047","host":"s3://npm-registry-packages"}},"0.5.1":{"name":"appattest-checker-node","version":"0.5.1","keywords":["nodejs","ios","apple-appattest","security"],"author":{"name":"Srinivas Visvanathan"},"license":"Apache-2.0","_id":"appattest-checker-node@0.5.1","maintainers":[{"name":"srinivas1729","email":"srn.npm.mostly.ignored@outlook.com"}],"homepage":"https://github.com/srinivas1729/appattest-checker-node#readme","bugs":{"url":"https://github.com/srinivas1729/appattest-checker-node/issues"},"dist":{"shasum":"062cdfad3b5d4fe3bab543b665eaee19da6ff888","tarball":"https://registry.npmjs.org/appattest-checker-node/-/appattest-checker-node-0.5.1.tgz","fileCount":15,"integrity":"sha512-NAcXFINWay4vwpLW3Zyh1+Tvtu79GDO6qOTXSbTrrvg1SB+xU+0sObntoIO/FKZL5UqI1e6Tqj9HD8UK7p0EHA==","signatures":[{"sig":"MEUCIBykRpESPSNcREQHzXnodKoygmPGpcRafY7d2FS6vCSCAiEAufUgl4cZLi01bYLD+uETeujZeTabnZ4YBsqHIll4wT0=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":44581},"main":"dist/index.js","types":"dist/index.d.ts","gitHead":"d501a3a0a7256e795086a005f431e6d425d50f5c","scripts":{"lint":"eslint --ext .js,.ts","test":"jest","build":"tsc","format":"prettier --ignore-path .gitignore --write \"**/*.+(js|ts|json)\""},"_npmUser":{"name":"srinivas1729","email":"srn.npm.mostly.ignored@outlook.com"},"repository":{"url":"git+https://github.com/srinivas1729/appattest-checker-node.git","type":"git"},"_npmVersion":"10.2.4","description":"Node.JS library to check/verify iOS App Attest attestations & assertions","directories":{},"_nodeVersion":"20.11.0","dependencies":{"cbor":"^9.0.1","@types/node":"^20.11.0","@peculiar/x509":"^1.9.6","json-stable-stringify":"^1.1.1","@types/json-stable-stringify":"^1.0.36"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^29.7.0","eslint":"^8.56.0","ts-jest":"^29.1.1","prettier":"^3.1.1","typescript":"^5.3.3","@types/jest":"^29.5.11","@tsconfig/node-lts":"^20.1.1","eslint-config-prettier":"^9.1.0","@typescript-eslint/parser":"^6.18.1","@typescript-eslint/eslint-plugin":"^6.18.1"},"_npmOperationalInternal":{"tmp":"tmp/appattest-checker-node_0.5.1_1706716708795_0.9049703425104545","host":"s3://npm-registry-packages"}},"1.0.0":{"name":"appattest-checker-node","version":"1.0.0","keywords":["nodejs","ios","apple-appattest","security"],"author":{"name":"Srinivas Visvanathan"},"license":"Apache-2.0","_id":"appattest-checker-node@1.0.0","maintainers":[{"name":"srinivas1729","email":"srn.npm.mostly.ignored@outlook.com"}],"homepage":"https://github.com/srinivas1729/appattest-checker-node#readme","bugs":{"url":"https://github.com/srinivas1729/appattest-checker-node/issues"},"dist":{"shasum":"58dc69c196e8a504cdc6687ac2fb3f50321362ec","tarball":"https://registry.npmjs.org/appattest-checker-node/-/appattest-checker-node-1.0.0.tgz","fileCount":15,"integrity":"sha512-thYwTyqVLRow1YZOLOJ95U0x8kwpyX1YHdQo1XrNd7q3iAxYbIPN2WFoWRZw662KKHIwA9HIS7OukBhlxBApJA==","signatures":[{"sig":"MEUCIQDee3hlujyGz9ftoUM1xKMOzhemRVcaqH/Ok9lK268MbgIgAlj9Ev8hKp1VN2Rl4L2MSJlI2oXp1bBfYLF485Viw0o=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":49997},"main":"dist/index.js","types":"dist/index.d.ts","gitHead":"581b5b5140b090ab290b7d84fbb63019040f018a","scripts":{"lint":"eslint --ext .js,.ts","test":"jest","build":"tsc","format":"prettier --ignore-path .gitignore --write \"**/*.+(js|ts|json)\""},"_npmUser":{"name":"srinivas1729","email":"srn.npm.mostly.ignored@outlook.com"},"repository":{"url":"git+https://github.com/srinivas1729/appattest-checker-node.git","type":"git"},"_npmVersion":"10.2.4","description":"Node.JS library to check/verify iOS App Attest attestations & assertions","directories":{},"_nodeVersion":"20.11.0","dependencies":{"cbor":"^9.0.1","@types/node":"^20.11.0","@peculiar/x509":"^1.9.6","json-stable-stringify":"^1.1.1","@types/json-stable-stringify":"^1.0.36"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^29.7.0","eslint":"^8.56.0","ts-jest":"^29.1.1","prettier":"^3.1.1","typescript":"^5.3.3","@types/jest":"^29.5.11","@tsconfig/node-lts":"^20.1.1","eslint-config-prettier":"^9.1.0","@typescript-eslint/parser":"^6.18.1","@typescript-eslint/eslint-plugin":"^6.18.1"},"_npmOperationalInternal":{"tmp":"tmp/appattest-checker-node_1.0.0_1706856720301_0.5301211231918541","host":"s3://npm-registry-packages"}},"1.0.1":{"name":"appattest-checker-node","version":"1.0.1","keywords":["nodejs","ios","apple-appattest","security"],"author":{"name":"Srinivas Visvanathan"},"license":"Apache-2.0","_id":"appattest-checker-node@1.0.1","maintainers":[{"name":"srinivas1729","email":"srn.npm.mostly.ignored@outlook.com"}],"homepage":"https://github.com/srinivas1729/appattest-checker-node#readme","bugs":{"url":"https://github.com/srinivas1729/appattest-checker-node/issues"},"dist":{"shasum":"a0cf4b8d68ad33c3d81db74b45bf2dae57808666","tarball":"https://registry.npmjs.org/appattest-checker-node/-/appattest-checker-node-1.0.1.tgz","fileCount":15,"integrity":"sha512-1ZyNyRh1rv9LIkp3lffjxb/XY6Ns2u+EUkDSKUn70NGm71OsXLmOOFjekdRQee2J6DlvrmN2+uDbN9dBAEVSLg==","signatures":[{"sig":"MEYCIQCJCA4af5jQCv4G/7/ZSht6JEw+nOye89ock3HVWrcbSgIhAKUDQ5MKffwN+FnMHrc2TctnQulGy6yJun6bNVSixkLu","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":50247},"main":"dist/index.js","types":"dist/index.d.ts","gitHead":"d1e1a0fee09b38a17ccc30e6722f458a6a93ca0a","scripts":{"lint":"eslint --ext .js,.ts","test":"jest","build":"tsc","format":"prettier --ignore-path .gitignore --write \"**/*.+(js|ts|json)\""},"_npmUser":{"name":"srinivas1729","email":"srn.npm.mostly.ignored@outlook.com"},"repository":{"url":"git+https://github.com/srinivas1729/appattest-checker-node.git","type":"git"},"_npmVersion":"10.2.4","description":"Node.JS library to check/verify iOS App Attest attestations & assertions","directories":{},"_nodeVersion":"20.11.1","dependencies":{"cbor":"^9.0.1","@types/node":"^20.11.0","@peculiar/x509":"^1.9.6","json-stable-stringify":"^1.1.1","@types/json-stable-stringify":"^1.0.36"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^29.7.0","eslint":"^8.56.0","ts-jest":"^29.1.1","prettier":"^3.1.1","typescript":"^5.3.3","@types/jest":"^29.5.11","@tsconfig/node-lts":"^20.1.1","eslint-config-prettier":"^9.1.0","@typescript-eslint/parser":"^6.18.1","@typescript-eslint/eslint-plugin":"^6.18.1"},"_npmOperationalInternal":{"tmp":"tmp/appattest-checker-node_1.0.1_1709042799889_0.954034749736516","host":"s3://npm-registry-packages"}},"1.0.2":{"name":"appattest-checker-node","version":"1.0.2","keywords":["nodejs","ios","apple-appattest","security"],"author":{"name":"Srinivas Visvanathan"},"license":"Apache-2.0","_id":"appattest-checker-node@1.0.2","maintainers":[{"name":"srinivas1729","email":"srn.npm.mostly.ignored@outlook.com"}],"homepage":"https://github.com/srinivas1729/appattest-checker-node#readme","bugs":{"url":"https://github.com/srinivas1729/appattest-checker-node/issues"},"dist":{"shasum":"724dfef3cf0da3d9b223a84382632c2d20ca4234","tarball":"https://registry.npmjs.org/appattest-checker-node/-/appattest-checker-node-1.0.2.tgz","fileCount":15,"integrity":"sha512-+Zsdol/n0j530ZNp9ENoZOKtmMfsFkOevhGq3pTqyzqsiWgJShMVban97a1UngGXtWbXO1ACtBPbWlpghgZwQg==","signatures":[{"sig":"MEYCIQCaHXQwhYENVV+dqqbzl60eq8yXr95bAqzI6VS/1JUy2gIhAJQHDvWo1Z6iAelA1iNkZ7I80LdcnrXCdwzkM262zuw5","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":50585},"main":"dist/index.js","types":"dist/index.d.ts","gitHead":"507ec1d2a1767b0914475270468c23e0378d3fe4","scripts":{"lint":"eslint --ext .js,.ts","test":"jest","build":"tsc","format":"prettier --ignore-path .gitignore --write \"**/*.+(js|ts|json)\""},"_npmUser":{"name":"srinivas1729","email":"srn.npm.mostly.ignored@outlook.com"},"repository":{"url":"git+https://github.com/srinivas1729/appattest-checker-node.git","type":"git"},"_npmVersion":"10.2.4","description":"Node.JS library to check/verify iOS App Attest attestations & assertions","directories":{},"_nodeVersion":"20.11.1","dependencies":{"cbor":"^9.0.1","@types/node":"^20.11.0","@peculiar/x509":"^1.9.6","json-stable-stringify":"^1.1.1","@types/json-stable-stringify":"^1.0.36"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^29.7.0","eslint":"^8.56.0","ts-jest":"^29.1.1","prettier":"^3.1.1","typescript":"^5.3.3","@types/jest":"^29.5.11","@tsconfig/node-lts":"^20.1.1","eslint-config-prettier":"^9.1.0","@typescript-eslint/parser":"^6.18.1","@typescript-eslint/eslint-plugin":"^6.18.1"},"_npmOperationalInternal":{"tmp":"tmp/appattest-checker-node_1.0.2_1709825856770_0.9262648588293296","host":"s3://npm-registry-packages"}},"1.0.3":{"name":"appattest-checker-node","version":"1.0.3","description":"Node.JS library to check/verify iOS App Attest attestations & assertions","author":{"name":"Srinivas Visvanathan"},"license":"Apache-2.0","main":"dist/index.js","types":"dist/index.d.ts","scripts":{"build":"tsc","test":"jest","format":"prettier --ignore-path .gitignore --write \"**/*.+(js|ts|json)\"","lint":"eslint --ext .js,.ts"},"devDependencies":{"@tsconfig/node-lts":"^20.1.1","@types/jest":"^29.5.11","@typescript-eslint/eslint-plugin":"^6.18.1","@typescript-eslint/parser":"^6.18.1","eslint":"^8.56.0","eslint-config-prettier":"^9.1.0","jest":"^29.7.0","prettier":"^3.1.1","ts-jest":"^29.1.1","typescript":"^5.3.3"},"dependencies":{"@peculiar/x509":"^1.9.6","@types/json-stable-stringify":"^1.0.36","@types/node":"^20.11.0","cbor":"^9.0.1","json-stable-stringify":"^1.1.1"},"repository":{"type":"git","url":"git+https://github.com/srinivas1729/appattest-checker-node.git"},"keywords":["nodejs","ios","apple-appattest","security"],"_id":"appattest-checker-node@1.0.3","gitHead":"d958bc5256b62621089c23c70bab09382cb69aed","bugs":{"url":"https://github.com/srinivas1729/appattest-checker-node/issues"},"homepage":"https://github.com/srinivas1729/appattest-checker-node#readme","_nodeVersion":"20.17.0","_npmVersion":"10.8.2","dist":{"integrity":"sha512-yLFbcSjY4aUwArKuR5y5fFj9QZcIt8ABmcQGgTfrCZfdb+rOBd3r3YLC5exQcvBJEvJIKgmUq73MvkjMwvpIhw==","shasum":"79dc916c2d11bbe51c6d06252a5f27d91c037de5","tarball":"https://registry.npmjs.org/appattest-checker-node/-/appattest-checker-node-1.0.3.tgz","fileCount":15,"unpackedSize":51198,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQC02VJ1XuGzZVby8jVKVEL2PzUb9IbBqoJ1rd2B7BcZOQIgcsmYQPWNEywhnK5UzKlvtK5y1tzJLkJu4q6OHJ45vIk="}]},"_npmUser":{"name":"srinivas1729","email":"srn.npm.mostly.ignored@outlook.com"},"directories":{},"maintainers":[{"name":"srinivas1729","email":"srn.npm.mostly.ignored@outlook.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/appattest-checker-node_1.0.3_1728834087115_0.7427742887791018"},"_hasShrinkwrap":false}},"time":{"created":"2024-01-31T01:34:13.843Z","modified":"2024-10-13T15:41:27.532Z","0.5.0":"2024-01-31T01:34:14.123Z","0.5.1":"2024-01-31T15:58:29.041Z","1.0.0":"2024-02-02T06:52:00.463Z","1.0.1":"2024-02-27T14:06:40.071Z","1.0.2":"2024-03-07T15:37:36.940Z","1.0.3":"2024-10-13T15:41:27.346Z"},"bugs":{"url":"https://github.com/srinivas1729/appattest-checker-node/issues"},"author":{"name":"Srinivas Visvanathan"},"license":"Apache-2.0","homepage":"https://github.com/srinivas1729/appattest-checker-node#readme","keywords":["nodejs","ios","apple-appattest","security"],"repository":{"type":"git","url":"git+https://github.com/srinivas1729/appattest-checker-node.git"},"description":"Node.JS library to check/verify iOS App Attest attestations & assertions","maintainers":[{"name":"srinivas1729","email":"srn.npm.mostly.ignored@outlook.com"}],"readme":"# Apple AppAttest Checker for Node.js\n\n`app-attest-checker` is a [Node.js](https://en.wikipedia.org/wiki/Node.js) library to check\nAttestation and Assertion objects generated on iOS devices. It can be used in your Node.js\nbased server to cryptographically check that requests received in your backend are from\nlegitimate versions of your app, running on actual iOS devices.\n\nBackground:\n\n1. See these [docs](https://developer.apple.com/documentation/devicecheck/establishing_your_app_s_integrity)\n   on how your iOS app needs to generate a public/private key-pair and get them certified by\n   Apple. Certification will produce an _Attestation_ object that should be sent your server for\n   verification. This library includes an API to parse & verify the Attestation and retrieve the\n   public-key for the device from it. Your server should store this public-key indexed by the\n   device-id.\n\n1. Later when your app needs to make normal server requests, it can sign the request contents with\n   with the private-key on the device to produce an _Assertion_. The Assertion should be sent along\n   with the request to the backend (e.g. in a HTTP header). The server can verify that the request\n   came from a a legitimate app/device using another API from this library to check the Assertion.\n\nThis library verifies Attestations and Assertions per steps provided in App Attest [docs](https://developer.apple.com/documentation/devicecheck/validating_apps_that_connect_to_your_server).\n\nRelated repos:\n\n* [`react-native-ios-appattest`](https://github.com/srinivas1729/react-native-ios-appattest):\n  React native library that wraps iOS App Attest API's. It can be used to\n  generate Attestations and Assertions on a device.\n* [`hello-attestation-server-node`](https://github.com/srinivas1729/hello-attestation-server-node):\n  Example API server that uses this library and provides an API that is guarded\n  using Client Attestation.\n* [`RNHelloAttestationClient`](https://github.com/srinivas1729/RNHelloAttestationClient):\n  Example React Native app that makes Attested requests against above server.\n\n## Consuming the library\n\nThe library is avaible on [NPM](www.npmjs.com/package/appattest-checker-node).\n\n```\nnpm install appattest-checker-node\n```\n\n## Library usage\n\n### Verifying Attestation\n\nUse the `verifyAttestation` API to check the Attestation produced by `DCAppAttestService.attestKey`\nAPI on the device ([reference](https://developer.apple.com/documentation/devicecheck/establishing_your_app_s_integrity#3561588)).\nThe `challenge` should be the random value provided by the server to the client to generate the\nAttestation. `keyId` is the identifier of the public key generated on the device.\n\n```typescript\n  const result = await verifyAttestation(\n    {\n      appId: '<team-id>.<bundle-id>',\n      develomentEnv: false,\n    },  // appInfo\n    keyId,\n    challenge,\n    attestation\n  );\n  if ('verifyError' in result) {\n    // Return error to app.\n    // It should not use the generated keys for assertion.\n  } else {\n    // Save publicKey and receipt for this device (sample code).\n    db.save(deviceId, result.publicKeyPem, result.receipt, 0 /* signCount */);\n\n    // Return success to app.\n    // It can use the generated keys for request assertion.\n  }\n\n```\n\n#### Certificate verification\n\nThe Attestation includes X509 certificates (`credCert` and `intermediateCert`) and part of the\nverification involves checking that they were issued by Apple. The library uses a copy of Apple's\nApp Attest Certificate (from [here](https://www.apple.com/certificateauthority/private/)) for this.\nIf you want to specify a custom Root certificate to use (e.g. because the library's copy is stale),\nuse the following API before invoking `verifyAttestation`:\n\n```typescript\n  setAppAttestRootCertificate(CUSTOM_ROOT_CERTIFICATE_IN_PEM_FORMAT);\n```\n\n### Verifying Assertions\n\nUse the `verifyAssertion` API to check Assertions produced by the\n`DCAppAttestService.generateAssertion` on the device ([reference](https://developer.apple.com/documentation/devicecheck/establishing_your_app_s_integrity#3561591)).\nThe app should include Assertions for all important / high value requests (e.g. in a header). If a\nhigh value request is missing an Assertion, the server should fail the request. Also if an\nAssertion is present, the server should verify it as shown below or fail the request.\n\n```typescript\n  const clientDataHash = // SHA-256 of request contents including challenge provided to client.\n\n  // Check that challenge in request matches challenge issued by server\n  // If there is mismatch, fail the request!\n\n  // Lookup public key for the device (sample code).\n  const record = db.load(deviceId);\n\n  const result = await verifyAssertion(\n    clientDataHash,\n    record.publicKeyPem,\n    '<team-id>.<bundle-id>',  // appId\n    assertion\n  );\n  if ('verifyError' in result) {\n    // Request cannot be trusted!\n    // Fail request from app (e.g. return HTTP 401 equivalent)\n  }\n\n  // Check that signCount > persisted value and update.\n  if (result.signCount <= record.signCount) {\n    // Request cannot be trusted!\n    // Fail request from app (e.g. return HTTP 401 equivalent)\n  }\n  db.update(deviceId, result.signCount);\n\n  // Otherwise request can be trusted and continue processing as usual.\n```\n\nEnsure that `clientDataHash` is computed consistently in the app and server. In particular, before\ncomputing SHA256 of the request body, the body needs to be consistent in the client and server.\nAny syntatic differences in the request body (e.g. different ordering of fields) can produce\ndifferent hashes. Use utilities like [`json-stable-stringify`](https://www.npmjs.com/package/json-stable-stringify)\nto produce consistent orderings and hashes.\n","readmeFilename":"README.md"}