{"_id":"fetch-mw-oauth2","_rev":"39-fb3a4e69fcfa9dd23a73db5faa516c0d","name":"fetch-mw-oauth2","dist-tags":{"latest":"1.0.2","alpha":"2.0.11","beta":"2.0.11"},"versions":{"0.1.0":{"name":"fetch-mw-oauth2","version":"0.1.0","description":"Fetch middleware to add OAuth2 support","main":"index.js","scripts":{"test":"make test"},"repository":{"type":"git","url":"git+ssh://git@github.com/evert/fetch-oauth2.git"},"keywords":["fetch","oauth2"],"author":{"name":"Evert Pot","url":"https://evertpot.com"},"license":"MIT","bugs":{"url":"https://github.com/evert/fetch-oauth2/issues"},"homepage":"https://github.com/evert/fetch-oauth2#readme","gitHead":"0666584abec404e7a882ba36b877830676bad0c7","_id":"fetch-mw-oauth2@0.1.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-fh8388vmX2nZRs/OEMm1PkFctrFM25PHO4gvszW1F65hm12jnlggEhMa8CthuXv7OVOk5qEDOFOf4DcMoOKdWw==","shasum":"502ecfb9335d8414dac4cd5405c599e76026ac1a","tarball":"https://registry.npmjs.org/fetch-mw-oauth2/-/fetch-mw-oauth2-0.1.0.tgz","fileCount":1,"unpackedSize":534,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJchsmiCRA9TVsSAnZWagAAVsAP+wZaoFAi6aYUmLZJVlmJ\nWdzq1aZ4ZeVARqmWm/TzDcQJk5OGqsEBCFhFx7ISgGLx03mJCCbao9Ke3RTr\nNHkIQj5dX/pBJOqPIicSjjgWDpMs9eLaitnqvwEssox8ZQtcHHNy4nLOzImf\njnu2MY2zlMs7Lybwis0tTwvmxtWWYmbC9Y3MFthNa6Rrf6n26Vqy2Z3mlzno\nQfYUmLkNGJPXc7V1B2XZfo4qW/P4DNtqxRM7yZcgjz0m0d2g6b47HPI/qc0S\n3NSEqLh/drlBH9lpboasO1/Hw/0APNQHDQpOE9Fh6UNnQbLmh6BDK/cmKkFz\n9oKkxFl2Nn0IXHr/Ym+tkXKE3eBosCVKXmicFkphPXjbWDi1M0VAH3ctPkiV\nizpJnTXKjsZ5HzMXuUMOzm1hjqzGj6jlEUBYrM1Zyq5Xms6A+IsiDiswIWl1\nvxD7tUmWDy3sIpB7JLDhgIEeAc9t5cXquaz4g4kbgm7Ck0ZF7/aazFaPc7r7\nb6zl15fZbuI3Y4/jMCZjsml16q/yf3+8mHvVVKpZBCvYk/ZhYG/8jQlGyOTx\n+qWH0RbXmnanDpdTH9+vswztpY/GWjh61Wyncw4JLn0YucqUD6EY0yqUA613\ncytEe17/brpKd/nBlJitpSBzePIPgRMpIAjDJ0fa1XwxrnwLBZD2IbLYUSdK\nIxRH\r\n=6Bx7\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIDUNoGFXyeeqll89F7P/Ost6oKaUMLd/Ty11suPTuUb5AiBCyGQIdQWHEonLoNIykVYnrWeUTAH1c8cRAPSQoZEsag=="}]},"maintainers":[{"name":"evrt","email":"me@evertpot.com"}],"_npmUser":{"name":"evrt","email":"me@evertpot.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fetch-mw-oauth2_0.1.0_1552337312571_0.29779186110822375"},"_hasShrinkwrap":false,"deprecated":"This package has been deprecated. v2 of this library has been renamed to @badgateway/oauth2-client"},"0.2.0":{"name":"fetch-mw-oauth2","version":"0.2.0","description":"Fetch middleware to add OAuth2 support","main":"index.js","scripts":{"test":"make test"},"repository":{"type":"git","url":"git+ssh://git@github.com/evert/fetch-oauth2.git"},"keywords":["fetch","oauth2"],"author":{"name":"Evert Pot","url":"https://evertpot.com"},"license":"MIT","bugs":{"url":"https://github.com/evert/fetch-oauth2/issues"},"homepage":"https://github.com/evert/fetch-oauth2#readme","devDependencies":{"@types/node":"^11.11.1","node-fetch":"^2.3.0","tslint":"^5.13.1","typescript":"^3.3.3333"},"dependencies":{},"gitHead":"99411b8c6f57367b3b3837c06818b6d45b191bb9","_id":"fetch-mw-oauth2@0.2.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-aSVsbhYNMaTsJp/wDkXyrb3wIvN1YMTimcVVQsOrF27/QVW0vCL452vCXK/kAyozvbEJzghri2IFIOKcdaiCWA==","shasum":"aefbb265692456b6de58ca9e2ecce02b7b6b89f3","tarball":"https://registry.npmjs.org/fetch-mw-oauth2/-/fetch-mw-oauth2-0.2.0.tgz","fileCount":11,"unpackedSize":9285,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJciAziCRA9TVsSAnZWagAADcsQAI9zq8q333hqbRo94vTl\nZakwZ/wuqxPCymPTNWfvLRpYe0GrFACfIKZTkVPtwwW7yohpOZzPw6Fx/hV9\n60xYTt8540/v6kavxI3bEbhrqYKelTRgzITPKYOXVlJcv32dhKzX/JDUIOwH\nZMFdc7rocltpuGu8oKSiANuWix82KHtg+XSHlg+uCUsABHmMPdHEvgU8EEYn\nVAVHs7+j6t9yNf145U1rSXRlwYynDfOZki5YM6Q3cTgS9rgj6JObVpA244Gr\nOAjpjg7dnOqf94XpXz5sALn8BfDjMNtAW9487mr6RNkXMGhaqfvZ4QqfwJfO\nWlSBKSA2KGaOXpTHwJDdyfrjG1mJPZK54L+fxHY2XY7xKHIVRosT81YbGu0H\nwJJj6YwONyXlXvj1aZjGrBgpRtgVNZuGN7E0kgpWA5hPAk3GQoIwtZ4bMLfP\ngQF0fD7todi3/NF6f7TqHPLwqJgzyP8Q6+agW5xOmKt2WZf3m8ggK8FW8L19\ngI5UJhxsxl3GvzOMeq4RHtjxtXmmK8dg0mkIzvFS/s1+b9V3WZjx7B/glkaM\nAelH6RFZQODA3J4Z2ohWb34lQRtzQw6LIjO8kdZ2Ia0J+BMBKo2xU9HLEfG8\nGxWeH+hpWxGLViPoM9DYPGS5eCiL97sf6PiHwKII1ZgF11rH05XqQ9XQTAjn\n4Xd/\r\n=zqcF\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIFYE0XU7McJpeDSDG20I2c8s2fhsnpH4rBZR0EoVI9NIAiB54u87kJogbwGdA+0iev3rTmPclFm9TcYsDjxZXMh+5A=="}]},"maintainers":[{"name":"evrt","email":"me@evertpot.com"}],"_npmUser":{"name":"evrt","email":"me@evertpot.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fetch-mw-oauth2_0.2.0_1552420066203_0.27810106254902345"},"_hasShrinkwrap":false,"deprecated":"This package has been deprecated. v2 of this library has been renamed to @badgateway/oauth2-client"},"0.2.1":{"name":"fetch-mw-oauth2","version":"0.2.1","description":"Fetch middleware to add OAuth2 support","main":"dist/index.js","scripts":{"test":"make test lint"},"repository":{"type":"git","url":"git+ssh://git@github.com/evert/fetch-oauth2.git"},"keywords":["fetch","oauth2"],"author":{"name":"Evert Pot","url":"https://evertpot.com"},"license":"MIT","bugs":{"url":"https://github.com/evert/fetch-oauth2/issues"},"homepage":"https://github.com/evert/fetch-oauth2#readme","devDependencies":{"@types/node":"^11.11.1","awesome-typescript-loader":"^5.2.1","node-fetch":"^2.3.0","tslint":"^5.13.1","typescript":"^3.3.3333","webpack":"^4.29.6","webpack-cli":"^3.2.3"},"dependencies":{},"gitHead":"6a00cd6fd1662a5d0654f5184b5de469f7c619a0","_id":"fetch-mw-oauth2@0.2.1","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-8u1XC3dH4OXe03PjmWWetNPH0WBh5+V5WsPoBxxUW0pkFhgmVU76ZqUoFF/aqzzc4dPO6CVat1V3zsdi6xTghw==","shasum":"8283bc8396ab73096d6d0a8f0ec5eb89382c7413","tarball":"https://registry.npmjs.org/fetch-mw-oauth2/-/fetch-mw-oauth2-0.2.1.tgz","fileCount":27,"unpackedSize":42176,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJciU5WCRA9TVsSAnZWagAAtPMP+gKudhws2e+vnjCOXM0e\nXET9QY9B2CGnudcgBj43+skNZrfP/Csa3+SLnsC4tvQb0HUJtlQudYEdW7JY\nrUIhsiZaRqUGgfpKmmX9CIIbLvOBGyakq1eJkQn2VkelDLr4/+YoDsktHocy\n7FCIpvcJbvfHp4Koe07DKsDqWymCtmg+vn44sukhaufH1yw5Y8gNo3cTX8zX\n/Nz35Ee9nLxFCf9gvEpkS84iUlnjMD4Bj37DIyCeCy3E9Jdikgs1gs98EBV9\nt8ApN50u6hJ50oOYYxCdVM6ejFQF+8YSOVQjcn39iUsEIGDfYw+t5tW47Shg\nV8Xlnl57HfC3sW6CPhAwlaVEZHuzt4dAlsxJhS2xHsXUkmFu26sptJvHh+rk\n0KCeyjjVf1uPrTXeb55Vbife78vIveVhpjxiLUBxSXrYCpYzWYOAWzQd9F+1\nPef5wrnKFJQsfJZkEojBl4ewNl9AZG03YgPAJkwoW9r/r/NJf84hY+Qpfjec\nN8oaQXJ/t0rEZoWzLTFrZGtIXt03ClYL6Uk2HvcjpoWfxs4ytH0/PaqXfnz9\n3DW+6pFbnXmTE17AD3A4Qki3e0twyO5WtZ4H+g/oiOhcJ+vzQKx/xxKWDVCs\nvnw5QOQhPA8nNlOHg0CojacPXVSVKKHSVW75uk28EGJvDLFfOYul7kPovUiz\nz3cu\r\n=TDvp\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCJKyvmbjSkr5+xAUTA8TATDT4HO/sC2f8Rux4G7WAB/gIgOoAimJ8iHlchaHtN3W+emTaNrtNCyYTMArGw7B7+M3E="}]},"maintainers":[{"name":"evrt","email":"me@evertpot.com"}],"_npmUser":{"name":"evrt","email":"me@evertpot.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fetch-mw-oauth2_0.2.1_1552502357482_0.9436615569438875"},"_hasShrinkwrap":false,"deprecated":"This package has been deprecated. v2 of this library has been renamed to @badgateway/oauth2-client"},"0.3.0":{"name":"fetch-mw-oauth2","version":"0.3.0","description":"Fetch middleware to add OAuth2 support","main":"dist/index.js","scripts":{"test":"make test lint"},"repository":{"type":"git","url":"git+ssh://git@github.com/evert/fetch-oauth2.git"},"keywords":["fetch","oauth2"],"author":{"name":"Evert Pot","url":"https://evertpot.com"},"license":"MIT","bugs":{"url":"https://github.com/evert/fetch-oauth2/issues"},"homepage":"https://github.com/evert/fetch-oauth2#readme","devDependencies":{"@types/node":"^11.11.1","awesome-typescript-loader":"^5.2.1","node-fetch":"^2.3.0","tslint":"^5.13.1","typescript":"^3.3.3333","webpack":"^4.29.6","webpack-cli":"^3.2.3"},"dependencies":{},"gitHead":"3f1cfa13a1ed969a8fb1fee9de573b052424fd20","_id":"fetch-mw-oauth2@0.3.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-GPsSFPL2PyQ28JjHUcIk0Kn+kftqLTQRNhqmqSAFNOWLzBM2BXfJn/tj8zgqI3oK6OtEL6OhpE+G3QZsd/o5ow==","shasum":"e6ec76efc355b8e042ef946473dab68102af5b1f","tarball":"https://registry.npmjs.org/fetch-mw-oauth2/-/fetch-mw-oauth2-0.3.0.tgz","fileCount":27,"unpackedSize":52012,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJciWpnCRA9TVsSAnZWagAAfuoQAIH97/PMG3slVrL9uOgq\n+RQsOwcMcFquP9i6KlbDLria3tHnDQmBqTuBAdnqN8l/1X7I/DTtR5U54O1U\nIp4H946cQb6zOz9NdCdWcasPRPjOD6NeDRyxmUfZPCGG7kmbJA5Y77QQjozK\n5kQwurSCgzXmvx8V1msHczF9o0qFPQWZItRPkFa8qEiH/cU66RduJNChe2Ti\ncPojkneGdsQByoMQcLxT7QVil/rG4BsV5FkPtSSiDhJU+te+Nm47BVFvW39v\nFEA5EQBvB/VVf963H/7Vo//zVizcMdRixixs1uTS8s6tZQqOGdu7eS8kgyRL\nzkzr0ohEu9yD8LRJt/qTpGeRLAc1UMqaOkSKUGSVTNy4AyZilPBn2eBkVrqM\nqTjuweOAoukvOtVRSPqjQfhP8y365wuQedawlCH1ExcmueBHHVskW62OnSS9\nbouuz4kolpTxFgUzNaEE9TWl1aABXMkdvOpK2bKfwduscG3jU+xvklJusUah\nXtUD/AQoW9jd12Gs1dxIL5SJlh/Bq0ENOUkiZdCVkPlCv41IMqYWViyZznhn\nnBdq2rp40sYQoL11aIq+Uad5dYGtf/0QnlOpGpIftONc0NlSZCkTEwRj6G7y\nsbm1eFKLu9hlknPL5eY8L/YGTMBJ7qKluh0RME9TlDvIAH1/QLWnophaxZmL\n+9Kb\r\n=eDWo\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIBkC2LFf23+4exu5M1CXFnKalLJvH/VgHhsTBc2GWchtAiEA9lO+elm3gDrBdMW7nGjTC8KGR9RkDgRCiGA4ZDymWCM="}]},"maintainers":[{"name":"evrt","email":"me@evertpot.com"}],"_npmUser":{"name":"evrt","email":"me@evertpot.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fetch-mw-oauth2_0.3.0_1552509543424_0.3470039607739257"},"_hasShrinkwrap":false,"deprecated":"This package has been deprecated. v2 of this library has been renamed to @badgateway/oauth2-client"},"0.3.1":{"name":"fetch-mw-oauth2","version":"0.3.1","description":"Fetch middleware to add OAuth2 support","main":"dist/index.js","scripts":{"test":"make test lint"},"repository":{"type":"git","url":"git+ssh://git@github.com/evert/fetch-oauth2.git"},"keywords":["fetch","oauth2"],"author":{"name":"Evert Pot","url":"https://evertpot.com"},"license":"MIT","bugs":{"url":"https://github.com/evert/fetch-oauth2/issues"},"homepage":"https://github.com/evert/fetch-oauth2#readme","devDependencies":{"@types/node":"^11.11.1","awesome-typescript-loader":"^5.2.1","node-fetch":"^2.3.0","tslint":"^5.13.1","typescript":"^3.3.3333","webpack":"^4.29.6","webpack-cli":"^3.2.3"},"dependencies":{},"gitHead":"0b6bff464896abe0f732b1565dbdeac7b13168fa","_id":"fetch-mw-oauth2@0.3.1","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-EpTtBedVR7GakG5O6wYNoyNopE3RIJEyG5AZZ/BMSnjuhOUrWVsdgrUja+71WcvLyky0TLrU8i6c4H+E5Wr/gQ==","shasum":"87c01b155bd78616d4f09c523062e8429bafadf2","tarball":"https://registry.npmjs.org/fetch-mw-oauth2/-/fetch-mw-oauth2-0.3.1.tgz","fileCount":25,"unpackedSize":38230,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJciYLMCRA9TVsSAnZWagAAP4AP/36mH8GdxYAfp4ZDyPWZ\nSZHxcplfPkNAQM1XdBQB2OpMDdPuXEbOe/+ep39JavF6VD40BfaU7BLRy2om\nNXWx0O/y1otyt18D1lKYrHPea1NqbZp3u8foyqc8CdwFiLuf8i2iXhfNEFtq\n05/WfQ3BfGYvMuekAfYPlMe4HYmZZ4jo1oHLCG0sDnmvjivN1dKSuZyiLeHa\niTHVADCOuYGZdYD3/g8Cqm6h05XMGy1ZEHi69p0NIJ/KKEJQMgeMC5KEAmXk\nWgObqMp2xm+DrtSOEqxOlZd3so1dhhhx0empFQPS2z0/eMsBPWViVu3oAUsq\ncihqkAq5C17zO/dTUhtwuW+/4ngEYdGcxcwZhpSzPULVU10deiHI1th0Zup2\nkjN3YSlRJ+G43MDycI5goeCxz1xlBUYP2N3PEHOU49Nw1inSKykihVYzNUPY\n4XvLgz6i0DYYf9WI7Vlkwiuj2Egbea+Mg0eWYlrx1ObwKHVVLadvzFiadYHL\nHl1NoTYD8xuWTABq5CMBxj5NzDd7NV7DpjchGoIG/9zgNrwQSi7KASFccrFW\nbJCEgGk3vrYY1HBKxVdpYyIxENLspA+6spqYF4eHWxQX4lbptF1r/6eVtvS7\nZuHupKGPEkR0xyOC4H1OfGSnH3tHUiG94nJjT2nUn+QeDhb4CGbUPv70645U\nPJ6y\r\n=lKSh\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIF7uXd/ywGOJxtM9QQiyN7MluNB8D+vyh204dZn/5SCZAiAzmvKyMCK360uL7D0T9eobtdXtufaHioZ1MQywIYtmmg=="}]},"maintainers":[{"name":"evrt","email":"me@evertpot.com"}],"_npmUser":{"name":"evrt","email":"me@evertpot.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fetch-mw-oauth2_0.3.1_1552515787100_0.9874367956657768"},"_hasShrinkwrap":false,"deprecated":"This package has been deprecated. v2 of this library has been renamed to @badgateway/oauth2-client"},"0.3.3":{"name":"fetch-mw-oauth2","version":"0.3.3","description":"Fetch middleware to add OAuth2 support","main":"dist/index.js","scripts":{"test":"make test lint"},"repository":{"type":"git","url":"git+ssh://git@github.com/evert/fetch-oauth2.git"},"keywords":["fetch","oauth2"],"author":{"name":"Evert Pot","url":"https://evertpot.com"},"license":"MIT","bugs":{"url":"https://github.com/evert/fetch-oauth2/issues"},"homepage":"https://github.com/evert/fetch-oauth2#readme","devDependencies":{"@types/node":"^11.11.3","awesome-typescript-loader":"^5.2.1","node-fetch":"^2.3.0","tslint":"^5.14.0","typescript":"^3.3.3333","webpack":"^4.29.6","webpack-cli":"^3.2.3"},"dependencies":{},"gitHead":"0651771dbf3d2938af991c29daabd9d3c8f04cf2","_id":"fetch-mw-oauth2@0.3.3","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-IWHNguzbzIZraDjNuw+C3ldSTq3TR7zEQtzdkv8G5ayg05Ce4B8MfcPrRRTOCJvbQUvAtOJNq8Rt8noW1q0iMw==","shasum":"003bee576e6307e4f1861aacfd14a8511b2e1acc","tarball":"https://registry.npmjs.org/fetch-mw-oauth2/-/fetch-mw-oauth2-0.3.3.tgz","fileCount":25,"unpackedSize":36948,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJcj/peCRA9TVsSAnZWagAAaVwP/i+pk42IYg9Myg1SA6BC\nbETvIWuVyzRemEKRouKCgERGhsB8bDJNUyR40grBZpeGSPzaeWefEMg6Lmht\n/D+BXh8YJz++dODTHwrCEWrTnB0v7YS6VsQgKo6iK+v4xDgGG1Q0OfVPQRHT\nz4stSTb4uWsZ5xDlmsBfHZ38Ir4/UK6c3BEcfFgNUT8nvASyJdryJpZcvGXQ\ntVlagphP/igLD44ogl/HkYNZ6h5v2Ym1PzhlQIAgzOK821tdy21C/IMbzOiy\nbZoDLxBkdOAdD/tW9KwARr+1KTCc4GpFL5wa76OLw1zt6J9dq7WsDJJ1h3Kw\nYQpm1n0gprJDPA5Il2WsUmy/AVzMmSeeWNfT3nBmCplg7f2RLr9N1CDj0hOX\ng0IaG4rxQ9D2PVeLEklbbId6daI4GnTahK1GSrHtQ/8OtNmb4t7O4biSTDn3\n9JcPie5f5g5Y5a1PJ/YjsNbhdrCCDKejjPj6egS4tuD29k2WseEUDMkVakGq\nmvfO57D9N0KIq52hprHoSDpJCPTme1ID1pke3y8cqOuOTVkN3J9fZyraVayC\nZXW5sLvm1FHgF1lUDzdmq+Se7W66SuzS6l21lk+TBt+DkPwbw6Frd9e5MyBG\nDrYD4rvS+YuJKeW4bJacN5X8qwZY78P55spzIlxMSkJO7VGhRsltIZuixC6q\nKH1p\r\n=T+EO\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIHlFBFqzDBE6Ct5A8fIOrW11SAWJMyFXJdLUSRcJ01HfAiEAwys6mpAGznzbDiCHrxMOxFZMLBYxuOBem7LdUXyNIrM="}]},"maintainers":[{"name":"evrt","email":"me@evertpot.com"}],"_npmUser":{"name":"evrt","email":"me@evertpot.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fetch-mw-oauth2_0.3.3_1552939613958_0.9244883841843137"},"_hasShrinkwrap":false,"deprecated":"This package has been deprecated. v2 of this library has been renamed to @badgateway/oauth2-client"},"0.3.4":{"name":"fetch-mw-oauth2","version":"0.3.4","description":"Fetch middleware to add OAuth2 support","main":"dist/index.js","scripts":{"test":"make test lint"},"repository":{"type":"git","url":"git+ssh://git@github.com/evert/fetch-oauth2.git"},"keywords":["fetch","oauth2"],"author":{"name":"Evert Pot","url":"https://evertpot.com"},"license":"MIT","bugs":{"url":"https://github.com/evert/fetch-oauth2/issues"},"homepage":"https://github.com/evert/fetch-oauth2#readme","devDependencies":{"@types/node":"^11.11.3","awesome-typescript-loader":"^5.2.1","node-fetch":"^2.3.0","tslint":"^5.14.0","typescript":"^3.3.3333","webpack":"^4.29.6","webpack-cli":"^3.2.3"},"dependencies":{},"gitHead":"7b3316c49ec09976ab7c67b550ac68087abb29ad","_id":"fetch-mw-oauth2@0.3.4","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-dWorM/fpsuudEjWbZfXoAhZWno6Yws16DUFP6GG9+jfc1Amil9OwQbbCe83Erbcj8IJfN7vfc4bgXI017vX/eg==","shasum":"7018ba6b850844bb1cf1d1b2d7cc8d2c18abc4a7","tarball":"https://registry.npmjs.org/fetch-mw-oauth2/-/fetch-mw-oauth2-0.3.4.tgz","fileCount":29,"unpackedSize":43932,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJckF+5CRA9TVsSAnZWagAAA84P/0FyW0/s/2MH+BH3LjJ/\n2cfHE+GsvPKb+Ch7eN0uq3mVcwqKw0ub622YxyaV1+pRts85Sxg+K1NIUvXB\ni2rBiA7XljhB3y920txFnCDo1sxKLORsuKlwSUYMF4tJ1vr9jqxnyd6f95Fx\n0CXnnib5ap6gb5pCIi1scRjROQwZ+81vl4mtFm+DWGGaEg/f7SBfFOJqTAG4\nqNtYAK5B5y1DSaFBBwczBH7kjmpdNodxu35iVLX75d41bst3yfHPcczNhl4l\nsHoYSGvuT2nMZce7KuObKRk/OmKNpMEfEOAxaaBkd/CBddtfbF89ff7LQ9ev\nM03ioQbcxSNxW6lM4PaxsSIhM5/5n5mbf611sWW6iWO/kCYw2wqkFIqU7esY\nLJdugaC2vQkuWoExOl7oSR1n7kCJ1mMjZcy4gCaxevp9zCdWhnaAXp8Yjwsv\nS83Co0HTTq9AofC4oXlZmgeDFymED6WTJP0MyxXgUgmFC8p4f9a4qHy8FgX9\nFErIyvqeGi9O87tLKI8K8g/2KLbWcbpFWYn31txaRj7k8I59+2CJ7bhppGtR\nI27PixE/rFeQUE2nt3XROXOywfDxjgcPUe8W8yWWQHo3I646qXXbIC+B9Rj+\nV+M07JdeD07E1AuvGVETixVyfQ4lj5AXMA1SOYUGvCLijUsr7Es0TqW6byDk\n6rFQ\r\n=4hN6\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIGUYqOv8BaWCP4yRshJkdhmMzQgoj+LKYAekidrxDDbpAiEAmsj3+ADGrUWSA2B+HXvWMoFETDBhqLN5CkCtxhstt1Q="}]},"maintainers":[{"name":"evrt","email":"me@evertpot.com"}],"_npmUser":{"name":"evrt","email":"me@evertpot.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fetch-mw-oauth2_0.3.4_1552965560210_0.7380166481382344"},"_hasShrinkwrap":false,"deprecated":"This package has been deprecated. v2 of this library has been renamed to @badgateway/oauth2-client"},"0.3.5":{"name":"fetch-mw-oauth2","version":"0.3.5","description":"Fetch middleware to add OAuth2 support","main":"dist/index.js","scripts":{"test":"make test lint"},"repository":{"type":"git","url":"git+ssh://git@github.com/evert/fetch-oauth2.git"},"keywords":["fetch","oauth2"],"author":{"name":"Evert Pot","url":"https://evertpot.com"},"license":"MIT","bugs":{"url":"https://github.com/evert/fetch-oauth2/issues"},"homepage":"https://github.com/evert/fetch-oauth2#readme","devDependencies":{"@types/node":"^12.7.4","awesome-typescript-loader":"^5.2.1","node-fetch":"^2.6.0","tslint":"^5.19.0","typescript":"^3.6.2","webpack":"^4.39.3","webpack-cli":"^3.3.7"},"dependencies":{},"gitHead":"06b498336d019d8b1257fbcc921fc10bb2880853","_id":"fetch-mw-oauth2@0.3.5","_nodeVersion":"10.15.3","_npmVersion":"6.10.2","dist":{"integrity":"sha512-ctlGARDDUY6fsUQFjAfGIRgTRtZGKmFSmnUQAK4xYdwWgXzKe6iQmBAUng0vE3pe8pu+Es84Li5oc1TRwpXdOg==","shasum":"3a4a0ee9e0fe2a72f401a75ea625e1c37fd80935","tarball":"https://registry.npmjs.org/fetch-mw-oauth2/-/fetch-mw-oauth2-0.3.5.tgz","fileCount":36,"unpackedSize":52649,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdcR4FCRA9TVsSAnZWagAA60MP/2z36C8DkWr54gUeBeAp\nMMDJ448P+DanmoCIKbW0GRZq5jebY5YHOCV7U9iW3QMDWkIY4L/gI7gvrTnH\n5E4lmHmlb4+FBjItMfh7m728vwWzWJXVHrml/DIGbgXOZTIWRHkJwPtzLhBZ\nPAqHe7mgT2zzuL87oadiqo2+yO5vVcDZxz9c6JxHrPtsF2ad6kkD6fagdu+3\nr9MUDtmm/fnrcpT7XNKjBY8A6r4o6owvuMn+cuiVQDX0ERs/Y0AHn1XE6w7Y\nFLe+o+hCPa4g/Oe2hlOeWnY43qc1qDPbXDaY2czxEZZzIsJHCh7CZyOlz8wl\nWipZBfG90isbnpmhz5Wey64UMECS0RvLvptKV0ku95+8vObFCOY+NvqySAXj\ndhX8ABzkpzzDb5oluGgD+nfJhtQJQe9Gp1/WhhJ199+d5aQwjEWsycAlJ068\nhC6DW3WhfmDbDyV92vbt0Ex0xoJut28/t/Ry8NbMBFsqZkbIiPgVbclCJaHM\n62SQuqqmZ1OwVmFT7zOWoX42WFUk9EpKuAft8Na/rOd3nQggylWGrDcX7mOu\np6at846yhvLakcDkbQjrGgiwck83MMm3mUi9WTtIh2HWYw8FLwRpNhWgxItF\nDsaYCXHzbsDD9B33xH57pXNO9tAbuKtoK7DZuEy2gV8m78+vHrmKSq4a/sL/\nZf2U\r\n=lwQB\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIDvbcDrIZuQxLFCOseFwxWBR8R7AyrUf4ffMBVbAnXixAiBUXEz7bXNSicfQDxgZPwxVy8cuReapwcw6ZrilEeqklg=="}]},"maintainers":[{"name":"evrt","email":"me@evertpot.com"}],"_npmUser":{"name":"evrt","email":"me@evertpot.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fetch-mw-oauth2_0.3.5_1567694340804_0.36018196170960315"},"_hasShrinkwrap":false,"deprecated":"This package has been deprecated. v2 of this library has been renamed to @badgateway/oauth2-client"},"0.4.0":{"name":"fetch-mw-oauth2","version":"0.4.0","description":"Fetch middleware to add OAuth2 support","main":"dist/index.js","scripts":{"test":"make test lint"},"repository":{"type":"git","url":"git+ssh://git@github.com/evert/fetch-oauth2.git"},"keywords":["fetch","oauth2"],"author":{"name":"Evert Pot","url":"https://evertpot.com"},"license":"MIT","bugs":{"url":"https://github.com/evert/fetch-oauth2/issues"},"homepage":"https://github.com/evert/fetch-oauth2#readme","devDependencies":{"@types/node":"^12.12.6","awesome-typescript-loader":"^5.2.1","node-fetch":"^2.6.0","tslint":"^5.20.1","typescript":"^3.7.2","webpack":"^4.41.2","webpack-cli":"^3.3.10"},"dependencies":{},"browser":"browser/fetch-mw-oauth2.min.js","gitHead":"08809fe36b1e1ba4c05e02fd6fddc26dc8b7405e","_id":"fetch-mw-oauth2@0.4.0","_nodeVersion":"10.15.3","_npmVersion":"6.12.0","dist":{"integrity":"sha512-qn38slnWrMueICoad3i88S4SADDhSEZdsnT3E79wlPYnZqbmXf8bEGOwi3Jya1eR8d9r567JU1DSAQyLx7v/jQ==","shasum":"774a239122c246264aef658bb1f39e41883df375","tarball":"https://registry.npmjs.org/fetch-mw-oauth2/-/fetch-mw-oauth2-0.4.0.tgz","fileCount":36,"unpackedSize":77744,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdwyj7CRA9TVsSAnZWagAA3dgP/22W45wdqLnI0Rb8RMfw\nBFmQabzzOuOo9hHVUxsdFh2/GFlBubV/ecbKki4nJAT2oj+wEWsg+M8i9WQS\nvQe0hLGpsUrWx3zJ/5z+sq9yJAFtiARxIhDzYop0/1DXwaXfYoEwQmhj+kRt\ni288KeLdh4pSV5I6y31iqoDzDKItHKbGS/M4LHKSMzkpBRvAmd/pSmHKe2dO\nmZWeEK05zcbaVQ1gI5ig8NXrxSpNP+XirvODChm6zdJj0E0MVpqn18x87VR3\njvAV4trwrYoewM9toDPsxkuIZZGbnyLtA7Uz3+c7yUNibr/mSJ155xobHIqs\nxq4uFc3gFEwpgXxoeBQYQFt23lAkVo2JCZQ/MHlfrD0cs6vbEoCUdHMf6eaR\nyJyftTXN+DLn4syWFOY10+BM4ix3VZfZic3eAhRzyrn66OREgyha++uRhgjz\nWAij0o7qVttLLdRGHlQIYgA0eiQDdeVLmHEH4KSnC+Uz1GVUF4i61Q8lzOdD\nVy+OuqgY7LMqT+cfpMFiO6NU0YWSD6XclJ1FBALVLrstnBeEl133y61A1ptn\npv/X7Bix89rWtFVKQhQcqScgiqSHOHe0ybo4UH3G8jmApr8HoGzRL2AB0G92\nIra96P65lT62Z8HFtl6HQkwXMdTg1MNIw5l7S1g7RVQXVE5wUmVuydGpXL8N\ngUlY\r\n=Mycs\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIDrtDy3JSUbUr92UE6qJ0FoYzb6u/R7ZV7cN8NDWKm+qAiEAmFmXITNaUEDQajPAHOS1pDwronLu45RBHPbZA+b82xE="}]},"maintainers":[{"name":"evrt","email":"me@evertpot.com"}],"_npmUser":{"name":"evrt","email":"me@evertpot.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fetch-mw-oauth2_0.4.0_1573071099336_0.8969913636974958"},"_hasShrinkwrap":false,"deprecated":"This package has been deprecated. v2 of this library has been renamed to @badgateway/oauth2-client"},"0.4.1":{"name":"fetch-mw-oauth2","version":"0.4.1","description":"Fetch middleware to add OAuth2 support","main":"dist/index.js","scripts":{"test":"make test lint"},"repository":{"type":"git","url":"git+ssh://git@github.com/evert/fetch-oauth2.git"},"keywords":["fetch","oauth2"],"author":{"name":"Evert Pot","url":"https://evertpot.com"},"license":"MIT","bugs":{"url":"https://github.com/evert/fetch-oauth2/issues"},"homepage":"https://github.com/evert/fetch-oauth2#readme","devDependencies":{"@types/node":"^12.12.6","awesome-typescript-loader":"^5.2.1","node-fetch":"^2.6.0","tslint":"^5.20.1","typescript":"^3.7.2","webpack":"^4.41.2","webpack-cli":"^3.3.10"},"dependencies":{},"browser":"browser/fetch-mw-oauth2.min.js","gitHead":"c567e22aebcdaea19de5bba4dcbf72b3be6fa2fd","_id":"fetch-mw-oauth2@0.4.1","_nodeVersion":"10.15.3","_npmVersion":"6.12.0","dist":{"integrity":"sha512-O3RJgcwPXpj8lOfCRtl0V+CEMicaosfjhBHuN3NTx0W3lExkRtlgtMOJf2L4Hf5laBj96LHwtfmdZZrumrkKZA==","shasum":"b9d4685e4887da96b729a2ef6cd19d2e3021d83d","tarball":"https://registry.npmjs.org/fetch-mw-oauth2/-/fetch-mw-oauth2-0.4.1.tgz","fileCount":35,"unpackedSize":57555,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJd7l6jCRA9TVsSAnZWagAAH3sP/Rj0Eb0ezWpzidTOlpkM\n5Nv0scRiSd+r/Hy9T9xXgZUDvMn2UIwOcGN1kUTUAeQTc+0ffMMSvWQDXYTb\n4gS/+of8aPJtVBVIIGxBhoxRxdnTBMIi4otjYIlwyaW9RCloy7IHWje+bkZO\nwttPpegDEeIGb2IbxPZWkzx9VntNqErU6C16UbxFyheR3bZVIate1CuPik/s\nA/VemYzZ3GY+CpyR7z7WgVIBFzxfPIp4KRs9yThbEBiAeY9RAHDDukiqPnqe\npvJwj7tUW2vhppoUZeY7wlM1ZXbbHbAycBisBuZUn1SvjLIoTGLGliyAv3iR\ndBIIqiYH3bzK/Mbg5fQuK2jQE9buYbGORL+DL+ItUkNuzrdDw0y4UTWlZRWm\n3E3n2kLsusS3KxxtIFz9zGkv3VsmOkzjmTrJK1SmD55fG1EVhfY64JSX3U9n\naCcoFSLZBQdmbFy+RUt6/C1Lcusg1c2XA/V3ELZrvNSS9U5yVWSxKQZprYLC\nklxsE2EnFij0xogMGlEz0m/jn0xcdkXoIodaelKB6YLa4hYetTsZx5Y7AD6Z\nVH+hrNtxcxc0JRIUaLvFlbwysNpf4x35BfEW/FXKJNpaJA3VbYKhkYBhBh7n\nNoVJNYNfc9Uom+D3xNKMGw5+RLK92UZAp4ewieQK71zPlV9iDsU55ZNYrnf8\nEAGs\r\n=H7aR\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIF3Rzis2yzJ9jUzAyPDCBVnJsUC7TO0aGwIOSEJMSCI5AiA8vhHP3mJTbSTuzCb4VSWGxWbDRQMFano86VoWwgf7NQ=="}]},"maintainers":[{"name":"evrt","email":"me@evertpot.com"}],"_npmUser":{"name":"evrt","email":"me@evertpot.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fetch-mw-oauth2_0.4.1_1575902882707_0.5174390289822741"},"_hasShrinkwrap":false,"deprecated":"This package has been deprecated. v2 of this library has been renamed to @badgateway/oauth2-client"},"0.4.2":{"name":"fetch-mw-oauth2","version":"0.4.2","description":"Fetch middleware to add OAuth2 support","main":"dist/index.js","scripts":{"test":"make test lint","prepublishOnly":"make build"},"repository":{"type":"git","url":"git+ssh://git@github.com/evert/fetch-oauth2.git"},"keywords":["fetch","oauth2"],"author":{"name":"Evert Pot","url":"https://evertpot.com"},"license":"MIT","bugs":{"url":"https://github.com/evert/fetch-oauth2/issues"},"homepage":"https://github.com/evert/fetch-oauth2#readme","devDependencies":{"@types/node":"^12.12.6","awesome-typescript-loader":"^5.2.1","node-fetch":"^2.6.0","tslint":"^5.20.1","typescript":"^3.7.2","webpack":"^4.41.2","webpack-cli":"^3.3.10"},"dependencies":{},"browser":"browser/fetch-mw-oauth2.min.js","gitHead":"dfd075eb107f48e3545a7ee8e152764cf2d18ac8","_id":"fetch-mw-oauth2@0.4.2","_nodeVersion":"10.15.3","_npmVersion":"6.12.0","dist":{"integrity":"sha512-yzvBLlwn/WxVTN8HBpIM6teXlv6TWXmcCZFz1OGj5AIjgGNXvcdY9OpO5AlBZ9P+XV300eDahWgXKDgcfdhtmg==","shasum":"64d856b90b4766ae565a64513e707f2d5bf51b51","tarball":"https://registry.npmjs.org/fetch-mw-oauth2/-/fetch-mw-oauth2-0.4.2.tgz","fileCount":35,"unpackedSize":57635,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJd7meTCRA9TVsSAnZWagAAg6wQAIu30sk8/mYcNwFrbNDt\nqb88syZ1RQFJ8Y1ti7zzPoXKvIekl+kHBE1YLhyJDmJTZnnI6Gh8tAy16bne\n9qV7uSne3q1i4A4eLBfHSUQVmjIzC0WqNJpYuUEtDySoRAZ3OPX79x52Vx1g\nVNu+mBWRMSRWztMJGDDJVzCTdg6lssxgLinABueOVN6+Ej5q0UlGd/bYI0iA\nGGNvV7k+O9vXZYt60P4lPbatYX5Ht9FfgR724Unn1GSiGvVdegZmOddsQPUA\n47nsEWs+hwh0Eivi43omhHIvd1hHl0CxDGVaHfw6zur7vB1SaDdeb7t0zxVM\n2Iptj+RfvcEdExQPluFJb+28Z4KSQ7yWV1LpzTYqQDqT8VdgqQqf5QNBdnNM\nwlmH4zsZvIv1a3Q/qjrCvXktN397YLX2+TlrxDEf72iHrjmftI0bzpZO0Sm3\ncgyS/4o0/BXzy3UoSP/J9nGZPeiPLTp4moU/tUZGC8S2qrC0XdMUw/mhbIbR\n2asyCFI/k1rYA28n8EAq19ZxQefNUFHzGafybKwKmrsYNP+UDJizpGiQOhfU\n1EEGJqps2AmIgPWB3AXcIq9xrKaHk0xlElPEWjbHJYbHbEkuXAw27QbW3/LG\n8b0wqCfvou9Oqi5BrJ4YMzHAkz11FMCkwbElWHum+XHSXMvCC8adoiD2rsw0\ny7tc\r\n=dB20\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIEbIY8enz2UqXm5ymBsiXJXfWXXIjqJPooOL5QaH1V5mAiEAnvm090ih9OLHKX4wPrEj4PxSvfXXyazDI6pceryHrpo="}]},"maintainers":[{"name":"evrt","email":"me@evertpot.com"}],"_npmUser":{"name":"evrt","email":"me@evertpot.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fetch-mw-oauth2_0.4.2_1575905171606_0.9826778072913076"},"_hasShrinkwrap":false,"deprecated":"This package has been deprecated. v2 of this library has been renamed to @badgateway/oauth2-client"},"0.5.0":{"name":"fetch-mw-oauth2","version":"0.5.0","description":"Fetch middleware to add OAuth2 support","main":"dist/index.js","scripts":{"test":"make test lint","prepublishOnly":"make build"},"repository":{"type":"git","url":"git+ssh://git@github.com/evert/fetch-oauth2.git"},"keywords":["fetch","oauth2"],"author":{"name":"Evert Pot","url":"https://evertpot.com"},"license":"MIT","bugs":{"url":"https://github.com/evert/fetch-oauth2/issues"},"homepage":"https://github.com/evert/fetch-oauth2#readme","devDependencies":{"@types/node":"^12.12.36","awesome-typescript-loader":"^5.2.1","node-fetch":"^2.6.0","tslint":"^6.1.1","typescript":"^3.8.3","webpack":"^4.42.1","webpack-cli":"^3.3.11"},"dependencies":{},"browser":"browser/fetch-mw-oauth2.min.js","gitHead":"dbc7c22c32c651e74e1438c7c492f06542f46eba","_id":"fetch-mw-oauth2@0.5.0","_nodeVersion":"12.16.2","_npmVersion":"6.14.4","dist":{"integrity":"sha512-slYrVF8Oofr5EW0xB9KQBwN5p9YLvoxAr0IVAbns6KFR4AG6yZj/JXOi6Al7ho1hC9aTJYWJebKAJu0St416ag==","shasum":"6f155578127c0004d66b3cb617d513e022abdcf0","tarball":"https://registry.npmjs.org/fetch-mw-oauth2/-/fetch-mw-oauth2-0.5.0.tgz","fileCount":35,"unpackedSize":62539,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJenMawCRA9TVsSAnZWagAAud0P/3mHECyq/GnIliOWz+m5\nlzMSyhZMttTwEUIws/2BDgrsbOJM33Ycbza3hj4lOweWY9+2ib0K9Azd1Dbt\nCq7+L+QHndJl15DOXWx4ee1eNUBNAbPXGRZh9T+dGVOP/iw6DSQMjnRhgOaF\nYkyGRXxYBOyp29HT/+EFs+R9ZFaH4XRihByYCX3X8Jer0mBcnBHIjiIRQSdv\nfqAZhz1uFlMvDkEIjdVQ6jiGuV8sR5Go7ZshVgr8r77WFiOqk7ZHI3Emd9gj\nmtjr9c44XO4S7vItDGtANW7rl9GeUn6nfrXtmiAlCn5BUhIVH6SVzsEK3o4F\nie51eTT4VP/9FmWJpRvG3dkJsJI/ZIsh06MjwUu8OxhVwW8FD/bMoO/ygqWQ\nvfWdHJClxW817Ep9K1VJma3ew2pSS7LLt7yKbpTpuxW8KBi8X99I3B5bv8bT\nWZUfTjhdlcX5ORGVI7rgyYck/vPU5CbbZrbbXl23rgks2CjC7LvxdfgSIKJK\nAL9lGim0WZk+yND0sr6F1eHHikjGWwzf4Xk6U/LxJXuCoWHEDjwvUP92/ptZ\nHJdokL4XsCAqbW0J+XSJogRarDDyvHY1BDpTGMXWPjJ4mC5ur+G1fj0Q6rtx\nHQfaT3pbN5vsqRbgQgdgu03yexUBvjT88RyEtrIuktDkb8czYykZsFOJv1I9\nSXhD\r\n=weOW\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIEwQx6IE9rKrKLxD7PArzOpMYQ6L/A/qAPP+bFxR3nxxAiEA4ojVSvP8jfQePLsspJoLuduE3KjCv1D6MFNoVuQlC+Q="}]},"maintainers":[{"name":"evrt","email":"me@evertpot.com"}],"_npmUser":{"name":"evrt","email":"me@evertpot.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fetch-mw-oauth2_0.5.0_1587332783961_0.04970321241018527"},"_hasShrinkwrap":false,"deprecated":"This package has been deprecated. v2 of this library has been renamed to @badgateway/oauth2-client"},"0.6.0":{"name":"fetch-mw-oauth2","version":"0.6.0","description":"Fetch middleware to add OAuth2 support","main":"dist/index.js","scripts":{"test":"make test lint","prepublishOnly":"make build"},"repository":{"type":"git","url":"git+ssh://git@github.com/badgateway/fetch-oauth2.git"},"keywords":["fetch","oauth2"],"author":{"name":"Evert Pot","url":"https://evertpot.com"},"license":"MIT","bugs":{"url":"https://github.com/badgateway/fetch-oauth2/issues"},"homepage":"https://github.com/badgateway/fetch-oauth2#readme","devDependencies":{"@types/node":"^12.19.4","@typescript-eslint/eslint-plugin":"^4.7.0","@typescript-eslint/parser":"^4.7.0","awesome-typescript-loader":"^5.2.1","eslint":"^7.13.0","node-fetch":"^2.6.1","typescript":"^4.0.5","webpack":"^5.4.0","webpack-cli":"^4.2.0"},"dependencies":{},"browser":"browser/fetch-mw-oauth2.min.js","gitHead":"08ef62864f8e052f6b1b2c2100daa40d40d14658","_id":"fetch-mw-oauth2@0.6.0","_nodeVersion":"14.15.0","_npmVersion":"6.14.8","dist":{"integrity":"sha512-Ey0OEueBhe6nGdCM5MqSDCgzs06t44+MM0xk6kpIOUHaS35hUakRgl08/R1wWDazR+ZFyDJcarL8vUHTsxBURg==","shasum":"1ff04e456180022028f5437490167abec2c9c656","tarball":"https://registry.npmjs.org/fetch-mw-oauth2/-/fetch-mw-oauth2-0.6.0.tgz","fileCount":35,"unpackedSize":68346,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfqa/kCRA9TVsSAnZWagAAo+UQAI4DbeeSv/r7fwtcjv3i\nP0aNZ4m1FIkgYYLSVlAgnORgC/85OdwcHrA8+2x8jY/CVJEZUCZVnpJ+MMFA\n2jBsaBXGcEeXcODwczmbuRobVdZGziDfPUzSM0mwwADpiNtJTI3EVhmCSsEq\nrphhOR5JumvctvCSGp3AC4HZ/Tjf2wTGvj2CvTibNvl/jbUr+zDpkRNlcc7G\nB6ujqNiv/wA7xLtLXNsfGiveRG5LE10055w/3HvQmCbRF9DHUEzT5kcXUo/2\nmeOeEqbFkjsbUDxGpqNjjbaghhLAAClSDCpJ5YmKBjRkywc8v7etqrl4kIrQ\nvSbaIja8GbQmWhBu18xQNWRys8aBQv+ltshPVx+sYCWjKYOnc78AvZ/Gr34W\nwR10O15kVZ8BRtolPI0ItbW25M43A8BZvBAQe/sHbFr+tM/l1rHtaLZwU1xO\nJ4hHFaeJf8tZsErtMFMBWzYJd+gyVDoYIK7eoXpLDaq6swyJ//MGJ3GZKtvA\nV9T1fQFudQvTt8RfY6VWfSMd6zLr+ZJwDEzCNkx3APOkyhhIckmj0/aJIgyl\n3Wh1cmH2/rD3/UzFp5RoMspQNA+i3CGvQOpZR0akCV1t8p4FAxA8/jtKsaXu\n63kr39qfm/flHnFXq0SfQDkxuxiCc7QP5OjpOLkBUS2BjTfyxail9zb/GwzU\nzTh2\r\n=YzFd\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIBTmrIDpkhExNVcKpyRgXc/19LFtr9AzaLGLIA1jvyh+AiBE4pQKmjCfWpfL5U+OyYBvVyuYQw1KnRS3RF8YQ0L2kw=="}]},"_npmUser":{"name":"evrt","email":"me@evertpot.com"},"directories":{},"maintainers":[{"name":"evrt","email":"me@evertpot.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fetch-mw-oauth2_0.6.0_1604956132062_0.9021064480778884"},"_hasShrinkwrap":false,"deprecated":"This package has been deprecated. v2 of this library has been renamed to @badgateway/oauth2-client"},"0.6.1":{"name":"fetch-mw-oauth2","version":"0.6.1","description":"Fetch middleware to add OAuth2 support","main":"dist/index.js","scripts":{"test":"make test lint","prepublishOnly":"make build"},"repository":{"type":"git","url":"git+ssh://git@github.com/badgateway/fetch-oauth2.git"},"keywords":["fetch","oauth2"],"author":{"name":"Evert Pot","url":"https://evertpot.com"},"license":"MIT","bugs":{"url":"https://github.com/badgateway/fetch-oauth2/issues"},"homepage":"https://github.com/badgateway/fetch-oauth2#readme","devDependencies":{"@types/node":"^12.19.6","@typescript-eslint/eslint-plugin":"^4.8.1","@typescript-eslint/parser":"^4.8.1","awesome-typescript-loader":"^5.2.1","eslint":"^7.13.0","node-fetch":"^2.6.1","typescript":"^4.1.2","webpack":"^5.6.0","webpack-cli":"^4.2.0"},"dependencies":{},"browser":"browser/fetch-mw-oauth2.min.js","gitHead":"13715839cc37f3b0e2f9265f7f080e744c9c57b3","_id":"fetch-mw-oauth2@0.6.1","_nodeVersion":"14.15.0","_npmVersion":"6.14.8","dist":{"integrity":"sha512-ADcE+tIKs8/2QXCq4VCSt76F/vB+arsuQX0UCdWLNuk9vameHLNZuNr+WUuFVHVUlULndxTy10LgVWRIjO6NBg==","shasum":"9444fa48ebd40d4313f5285ae9f0d4e276bfce46","tarball":"https://registry.npmjs.org/fetch-mw-oauth2/-/fetch-mw-oauth2-0.6.1.tgz","fileCount":35,"unpackedSize":68454,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJftzH6CRA9TVsSAnZWagAACX8P/1At0pvlMaNZjtAM8G+y\nV54lVGrqLVQc1N2rZ7cp5BBSYokBPlq0xgMCJCtntUhDJXXkvx8cQBq+cSxJ\nJUEDPGR0uMTyCV2QzpqrONmSb5LfR42ClZXrFKWLiymxnsrSUjTIPZeMiP82\nityjzBTnDc4rj5cfhAbfLFjPlg/u6j1ny/NNcNmrL9+5RMRZ8MnMOrhAiPQP\nQHAZEjfLk0PSOFfHAQFHBa5vvpCtwhwaB0egAYhz2eYgJ8JWhWCkXMGa89Vl\nad3Qxp4Iu/kOuSV6XlzIwE7+98iGuaVf08T8qiyTiq+QhSNVveLm9aYH0dqC\nJckPqsHptooDP8QvnLYfN8WwCGf9wM1sbvpysyAFocDYwMHYmXluE0pxOSK/\ntTgVVmE7E8atq98CUkXjKPr3OkxFOqoKMpthBBCgwLimUVqC0GTVi7m4F7+g\nt92bo8L3fMh1RDHkIGntoD1SaCJSXv2ya0gDqNcsQwDM9tpHyTNmB8bg/ZdB\nT9kySXkMnuaYhZwl3FY0oJuACvtll/GyEl7e9VFgqtnahSHlEj7G3iZ2qey7\nTwFJ1wlR4H4CnNxV8clhecL4kxSX/HxjAJw5rIfqxXGSrgQPXzAn3iuJlJPq\na09oQ19XuX3liGBfYh4rwJHWkH1PqCQwYxtt1EfmiUbBW3drMeT1NcZIHs+C\n/L3w\r\n=5lDC\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDS/lg6+z3Gbgnzb1iY2pm4qTfXs9msXyFDc1fNf1inqgIgOiskDckBtivsGLZH2LtAQ+aTpjdIznFIAVSMa4Sm3ZY="}]},"_npmUser":{"name":"evrt","email":"me@evertpot.com"},"directories":{},"maintainers":[{"name":"evrt","email":"me@evertpot.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fetch-mw-oauth2_0.6.1_1605841402124_0.35538008234298224"},"_hasShrinkwrap":false,"deprecated":"This package has been deprecated. v2 of this library has been renamed to @badgateway/oauth2-client"},"0.7.0":{"name":"fetch-mw-oauth2","version":"0.7.0","description":"Fetch middleware to add OAuth2 support","main":"dist/index.js","scripts":{"test":"make test lint","prepublishOnly":"make build"},"repository":{"type":"git","url":"git+ssh://git@github.com/badgateway/fetch-oauth2.git"},"keywords":["fetch","oauth2"],"author":{"name":"Evert Pot","url":"https://evertpot.com"},"license":"MIT","bugs":{"url":"https://github.com/badgateway/fetch-oauth2/issues"},"homepage":"https://github.com/badgateway/fetch-oauth2#readme","devDependencies":{"@types/node":"^12.19.8","@typescript-eslint/eslint-plugin":"^4.9.0","@typescript-eslint/parser":"^4.9.0","awesome-typescript-loader":"^5.2.1","eslint":"^7.14.0","node-fetch":"^2.6.1","typescript":"^4.1.2","webpack":"^5.9.0","webpack-cli":"^4.2.0"},"dependencies":{},"browser":"browser/fetch-mw-oauth2.min.js","gitHead":"456b873011daed0d275b3189d76a08847ac383b3","_id":"fetch-mw-oauth2@0.7.0","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-tN9uuCXx/FYDlHGukXcVhOvZzouawJZUJ4ni7bx3ayTcxcPaCyENIRmChNgzVRjLK6mYTC/8DfWPXC6OjCdpsQ==","shasum":"315943f51b9a6faeda4ed0640dca691cc4f54f70","tarball":"https://registry.npmjs.org/fetch-mw-oauth2/-/fetch-mw-oauth2-0.7.0.tgz","fileCount":35,"unpackedSize":71308,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfxb2eCRA9TVsSAnZWagAARZYQAKTartG0klQ60j2orjjb\ne8IB5/LdEo2W74YVoyg4RzSe7CGJVGVPsnZToszdDyopndxsL3xomjfeu7yV\nXJDa3gbVbH4/grPlHgnuOOnaK+rhyWz9iMUYz0jpe7foKymp52GPbQ5sX04H\nN2sZTH/Jh8zDLb7em7tuHgZIUsoPjr6HdaYvSeR0sm61b9xt7xO7GcnQz0XB\n83CROHsHYfbYPYHBTI6RsiuYdSj7lyYZ8T8oiWkolaO0Ecaphr+atzVWd54B\n/sWBxtKiPC4MmLZBruSCT2EOB6iEBkquQrkWX8X/YKEhbFQqmZ75GTvkvw3e\nc3YYfmXmtcKU4eo7pa0xXky2DkP+MQEBvZl/tmW7nQpAtGS7C6JTDYBEc3x7\n0i+oOKVFYgEXiy50EC6O2frjdvFHAnTmOOImGHCOORIsZf6pReS27GXlTVZw\nfpopkxp2ikBru2CgLVnWPQ1GjppCb+I2eBPoZL7ae9qtpxNCNAJXlXArPNfF\ne4hMYPUpFn5x1O784C6zloF3jdSfZZGDflfXdV7TlAHqCCQNAg+ONT5LnioS\ndsqwqCcmkXncpRFJV4ZTbop2v98T+8E80laYxfCHcP81ycIXzoMrc1OkX8Ae\n239mP6839Vmvr/NA/tJMyBQW7qmnc5B5gkDKAgTPrIDryZPY8lJXWWAJ6434\nGNTx\r\n=Y0ON\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIEDYjaeDq+m2iFebImL5zgrD8brmaIRoh07TJlyiKsyDAiEA4XpZNxMK+UbdO5dCLoWU09WloIZgVGG4czhVi4YSMeQ="}]},"_npmUser":{"name":"evrt","email":"me@evertpot.com"},"directories":{},"maintainers":[{"name":"evrt","email":"me@evertpot.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fetch-mw-oauth2_0.7.0_1606794653685_0.06579955586106179"},"_hasShrinkwrap":false,"deprecated":"This package has been deprecated. v2 of this library has been renamed to @badgateway/oauth2-client"},"0.7.1":{"name":"fetch-mw-oauth2","version":"0.7.1","description":"Fetch middleware to add OAuth2 support","main":"dist/index.js","scripts":{"test":"make test lint","prepublishOnly":"make build"},"repository":{"type":"git","url":"git+ssh://git@github.com/badgateway/fetch-oauth2.git"},"keywords":["fetch","oauth2"],"author":{"name":"Evert Pot","url":"https://evertpot.com"},"license":"MIT","bugs":{"url":"https://github.com/badgateway/fetch-oauth2/issues"},"homepage":"https://github.com/badgateway/fetch-oauth2#readme","devDependencies":{"@types/node":"^12.19.8","@typescript-eslint/eslint-plugin":"^4.9.0","@typescript-eslint/parser":"^4.9.0","awesome-typescript-loader":"^5.2.1","eslint":"^7.14.0","node-fetch":"^2.6.1","typescript":"^4.1.2","webpack":"^5.9.0","webpack-cli":"^4.2.0"},"dependencies":{},"browser":"browser/fetch-mw-oauth2.min.js","gitHead":"fecff3eb34da22b6783d48a4513b585581631adc","_id":"fetch-mw-oauth2@0.7.1","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-DfUucdbNB8KkT+AhzJoOS8QHF02q5dBZyoMGEHxCvNp1D5WTRFJ4iEpmO2jq9EzwQcukMLlZ6YMY6+zbWfE7Ig==","shasum":"7e58951b96e0e3695a8eaabc8c85e41bc6974de2","tarball":"https://registry.npmjs.org/fetch-mw-oauth2/-/fetch-mw-oauth2-0.7.1.tgz","fileCount":35,"unpackedSize":71541,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfxb8MCRA9TVsSAnZWagAAu3oQAJfRX3Ko6YqH6u4d/VOg\nikZ7vUv6vvoMzJxL/ATiIuf7x6M8BnpgJ0egnt0IkkId7OzBUGWvTsfcq8q6\n8Z1nINUvDFwj5FKxxtFzn6MCdRRlg4kgB6dp881aerO6yTfxBXLuZzFngSd8\n2y/M9dyi/jSKmUWQJe0fRO9Gr082sQyznBQDHHqxJ8iZbTNw649Amk71SuME\njkDikaGYqwLjYvu4cbnTm/8KOjut0gXRoAuoOgIyPd8Pd9yqli6MvVEi7Rzn\neSHDiMsa+5c3Y3J3avOuRAjJFxbmf2Oiui0UzNJ/y5FYNfdjKcCud8xM6gac\nX61jqBGqxD5lqBHyDs7EnFzmLL4gPxTAndMmRVwGDyutJipDH6tGecuTHfkr\nsl8Cv5DmL7y4DGHRqnNR0wOM4Bxub6HXlhKeguPPtRixgFbwRV/fF749SILM\nKp/fEVPaoTDdoPb6ljj7ujhDkp2cKqQkO+PlqLO1bcuZNQRwr7ZmtE3iqtPU\n0NHXXFJGlROjvKuKE1S7uUCxP/4syhy7j9oc4iegEpdE9nzi4EORcoRl3akE\nCD9qGZrBzy6F1Ezqlg5yr7xb1RVA2UF+AgTUdn2jnEZeLLWtEXrp97O/VjSl\nkHD9G0/e4IfM3Ycvtg3nwMcyvb82IOZRhkfxTEkVl32DHb4QGc9agRh9ZpQ8\ndF2e\r\n=jWHG\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCYWBJtyutk7z2yC7Pu7XURS0cbB0hxTOBaNt+kjOoJZQIhAItsWT4LWggOPdOXYB4X4lkH3+tM1Ab3k+gEWesil3PI"}]},"_npmUser":{"name":"evrt","email":"me@evertpot.com"},"directories":{},"maintainers":[{"name":"evrt","email":"me@evertpot.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fetch-mw-oauth2_0.7.1_1606795017326_0.4437575171658248"},"_hasShrinkwrap":false,"deprecated":"This package has been deprecated. v2 of this library has been renamed to @badgateway/oauth2-client"},"0.7.2":{"name":"fetch-mw-oauth2","version":"0.7.2","description":"Fetch middleware to add OAuth2 support","main":"dist/index.js","scripts":{"test":"make test lint","prepublishOnly":"make build"},"repository":{"type":"git","url":"git+ssh://git@github.com/badgateway/fetch-oauth2.git"},"keywords":["fetch","oauth2"],"author":{"name":"Evert Pot","url":"https://evertpot.com"},"license":"MIT","bugs":{"url":"https://github.com/badgateway/fetch-oauth2/issues"},"homepage":"https://github.com/badgateway/fetch-oauth2#readme","devDependencies":{"@types/node":"^12.19.8","@typescript-eslint/eslint-plugin":"^4.9.0","@typescript-eslint/parser":"^4.9.0","awesome-typescript-loader":"^5.2.1","eslint":"^7.14.0","node-fetch":"^2.6.1","typescript":"^4.1.2","webpack":"^5.9.0","webpack-cli":"^4.2.0"},"dependencies":{},"browser":"browser/fetch-mw-oauth2.min.js","gitHead":"77b0a59b66fb2e50474478d42d2a7fdf86b6f81c","_id":"fetch-mw-oauth2@0.7.2","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-v8V9Mu2GneV3OYd/jvPtYdrRZglV7+1mc7HwPVARNNJkAPq2z9P+oSmAtkKNdxT+YnFqeEVVFTepSzZNmU//jw==","shasum":"fc725a91c9994388f234a8dda6e46adfecb9eb51","tarball":"https://registry.npmjs.org/fetch-mw-oauth2/-/fetch-mw-oauth2-0.7.2.tgz","fileCount":36,"unpackedSize":91792,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfxc8sCRA9TVsSAnZWagAA+8cP/RURhcLUgACJ2HR3tdwm\n5lzsAQynSEA1Ud1XjIagDv6kNGjC9aLLKxpGXIpRqEltIFQDqmY/zUpxX9gw\nGwojlxVFlMNulGUiEbTZRLBfX8nGLTh4pmhrwPaWTjioW1dzFElAwgVQk8Xj\nb4swgeWkju6FMB/lTkGpXTkLGGGpVfDWT88Ban9IslICJVZlnVJNcWB6Mig4\nN0KDjQVCSZTnM7uAdtWBbREq3EeCWZf18WQy/geDAUvwD23rOgtF++F0Px9E\n/EJsWnoKZpPtGX3Cb3+UljrgttEnUM4T0zRaDslDNTmcQFJ5TFug+XqCzQwp\nVq4imToTWnUgnr+0wsAknZUVM8zn0kkLxP26imPJuTIzPQDyqO5+7jKNrLyZ\n0UJQp83pQI8fyqIiNqDyTHrLlsCzRnpjffvm82Ie5pwOhMCeak+qukHibLV5\ntuui9zBNuW4sxiGe7NX0ZYmR5HmR06lKnAXi3MWZ5pmm3SAkBTHHS+0l7Qlk\n4ut/glDgBY0Hl1pkgcHPWLRaRxoP2/K+LweI1iDf8QPKlpOC72va/rFd7sEQ\nF4qJNDGKr87njO9EF0ibXBRh27wYZxdSwFL2n0Fun4IAyRgl5uj1zznB7olz\nTEREo51mYGYCcBglnmlbZ8CjcP1z6eRX6AZg6/W3K0HOB5oKlRMbBnTHn6F1\nZaja\r\n=H13S\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIGOC9ZHqKeS1MSIbiC0haAt3KgqBGdmgAFTKUS6yC9pZAiEAhSGtpFITD4j6zZMzCgAgDy5jBvRA+PZhCArOWpULKUo="}]},"_npmUser":{"name":"evrt","email":"me@evertpot.com"},"directories":{},"maintainers":[{"name":"evrt","email":"me@evertpot.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fetch-mw-oauth2_0.7.2_1606799148273_0.2819408590234811"},"_hasShrinkwrap":false,"deprecated":"This package has been deprecated. v2 of this library has been renamed to @badgateway/oauth2-client"},"0.7.3":{"name":"fetch-mw-oauth2","version":"0.7.3","description":"Fetch middleware to add OAuth2 support","main":"dist/index.js","scripts":{"test":"make test lint","prepublishOnly":"make build"},"repository":{"type":"git","url":"git+ssh://git@github.com/badgateway/fetch-oauth2.git"},"keywords":["fetch","oauth2"],"author":{"name":"Evert Pot","url":"https://evertpot.com"},"license":"MIT","bugs":{"url":"https://github.com/badgateway/fetch-oauth2/issues"},"homepage":"https://github.com/badgateway/fetch-oauth2#readme","devDependencies":{"@types/node":"^12.19.8","@typescript-eslint/eslint-plugin":"^4.9.0","@typescript-eslint/parser":"^4.9.0","awesome-typescript-loader":"^5.2.1","eslint":"^7.14.0","node-fetch":"^2.6.1","typescript":"^4.1.2","webpack":"^5.9.0","webpack-cli":"^4.2.0"},"dependencies":{},"browser":"browser/fetch-mw-oauth2.min.js","gitHead":"c467d64b550262ee898862460d59bb983a296fbd","_id":"fetch-mw-oauth2@0.7.3","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-mQ9s9Fb/U3C4t+agxAxYV1IhWD9bGM+50qmDq3VMiYThElzbBDem/R7SnSwx2FSIWN1EdS+Zb56LrX7NaSxrbQ==","shasum":"9674ca6beabe7f56040de72084953d7a28216998","tarball":"https://registry.npmjs.org/fetch-mw-oauth2/-/fetch-mw-oauth2-0.7.3.tgz","fileCount":35,"unpackedSize":71122,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfxdFaCRA9TVsSAnZWagAA1RQP/j3s7KwfZ9ZRB0xdSre0\nlEU/RXcpt9gYaSstY65qbbVo33aYp8pcQQupO0Dp4TxuVfB0GEi+IK++g8Gl\n/1mbwzh0i6FG+PT/dic6OFniDUhWn79Etu154W93AukA7TskvynMVZNoCx4U\nNhOBX0SC2ALyJon0CLYaK0pZdobUnvqcHcW+fBcA3jJ6HgYBl6RIKElJqxC5\nxP9sNtMcKhRTbjoRjZoVImcUxFThTyqw7XktS9Bp4dZyMJ14XjCmqODFRLcz\nwDK6GXzhBM06UIcQ40AhjbFWIWAVzRm+BjJwDmo/L3ZeoLqyESKt+rKa/WFY\ngRsQ3fJ3sTAoIgmRb4cvr6wVHIQJNJNDgG0hFtc9t1BhvYWFkpwowVi1sEpV\nTBIDENfgwAomWCFeHIwpm+WR//fnq4ezdVFqUsM0Dtqw9T6f1eOS2V4JhKB7\n4q8Pnt8Ggd5z4tH1HpGJort9TRaNGTab1WVS/za2i8jbvzS+5ZpUz8aRFHuB\nBannrmJGJr+TgLs9micZz+zOrKQHY/YtWGfbP8Jmx6Twj37wp06T14y3xI6u\nd2sXzXdyWhvjFB6RT0sKp0uUMLNFNgDGUqAzmW2GvvJoW6PyA5gTX/BJi4qq\nbB3UwfB51Qkt3c+vUZKrUQZNyWWKGss8WbzYzv3Yss7aHMDwwiesCjZg8kxc\nbogs\r\n=j3Y9\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIF8acl1rm+xk+sjGbzRdMNAZxoNU9f7l49fnQxnwpUrgAiB6Ul9ir56NuvzCyYePAqOhJJ9lh0zwQWUyWi8n9S0ZOg=="}]},"_npmUser":{"name":"evrt","email":"me@evertpot.com"},"directories":{},"maintainers":[{"name":"evrt","email":"me@evertpot.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fetch-mw-oauth2_0.7.3_1606799705569_0.5179786560599438"},"_hasShrinkwrap":false,"deprecated":"This package has been deprecated. v2 of this library has been renamed to @badgateway/oauth2-client"},"0.7.5":{"name":"fetch-mw-oauth2","version":"0.7.5","description":"Fetch middleware to add OAuth2 support","main":"dist/index.js","scripts":{"test":"make test lint","prepublishOnly":"make build"},"repository":{"type":"git","url":"git+ssh://git@github.com/badgateway/fetch-mw-oauth2.git"},"keywords":["fetch","oauth2"],"author":{"name":"Evert Pot","url":"https://evertpot.com"},"license":"MIT","bugs":{"url":"https://github.com/badgateway/fetch-mw-oauth2/issues"},"homepage":"https://github.com/badgateway/fetch-mw-oauth2#readme","devDependencies":{"@types/node":"^12.19.8","@typescript-eslint/eslint-plugin":"^4.9.0","@typescript-eslint/parser":"^4.9.0","awesome-typescript-loader":"^5.2.1","eslint":"^7.14.0","node-fetch":"^2.6.1","typescript":"^4.1.2","webpack":"^5.9.0","webpack-cli":"^4.2.0"},"dependencies":{},"browser":"browser/fetch-mw-oauth2.min.js","gitHead":"674b1de98679c746a757b1cbbd58554e50479a04","_id":"fetch-mw-oauth2@0.7.5","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-V+hOEJ6dcT6GvaAgoluudiFxYy3EGtkSAQRBXNIIlhn1t3sOdEFAFWzehYtZfyh2IA7ANVhzheQjDZhPwz3VnA==","shasum":"902eb5cae5cda77cf2d39f8567f15024db53967e","tarball":"https://registry.npmjs.org/fetch-mw-oauth2/-/fetch-mw-oauth2-0.7.5.tgz","fileCount":35,"unpackedSize":71356,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfyWUFCRA9TVsSAnZWagAAo7oQAJtX3Nu7iS+bL5+PRkNq\nDS0ufqYcR65JDK24X+xGGU1zTptxcpjz8wNpPPLr3YDHIFhhIsmziGcjTzJr\nC7/bnJRMADozSfItuxEHLcqu+xEnVMKFJG4XIDubRPsbCb5tzwWN03fOUvKS\n0DKs5avSS4WYHTswNJPvImtPVd7Gbnc8ekGlOrtdXe6oeKgNLIHQInoV6ZUE\nFinYZp130Cwz3OctOvr4tCUEjVSCcuDFQbISOJaN+QIdDD2lD1T1oZZ39XMC\nuUnVYcUKk+zqEdeyUXwX7BUIfWNh4WS6xRXDr6NHWcimMetVOUTATdh1Qa7G\nbORGG/w9PGT4nPn+uQuuEQ7k4Cg3a1D8T39ea7qApt0gB/GC1SXxfTDrVwNv\nrt7RAKq5bSG2Zl0ANt53vYFILFX8hARqfCnSt2ZDLJd5LZN/ef1bCcTxD/VE\nK/LeBkfD/DFZPkiBR2rIYehGxPFkLW+dovaZAWi0bP0VKA0eh/JSvoTziGM/\nvbA9/reaXf4gAJh4nBG6tWqUeZKgBIwZd9g8RNx/nPIdwQI5dlqIA6dNFOKy\nSpPx2DWr49Nec64J2rsH3QuhLm9H9sJEu2Oh08Or+tdNL+a4FIGxgIgAsZyb\nx4xEBVC87ZP4UzqeJy+2y2f4acefHIJdOsHuzS0TIiwmWYHX8Bt+iG2O+iPW\n3PKZ\r\n=njvB\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIE7ifhEiSyNDD72niRPucsUin8CxfRenjO9yN8trS0beAiBTueaKZMhItfHFluuDDjb/7eGdFsaWWG47upmmBbqAig=="}]},"_npmUser":{"name":"evrt","email":"me@evertpot.com"},"directories":{},"maintainers":[{"name":"evrt","email":"me@evertpot.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fetch-mw-oauth2_0.7.5_1607034116486_0.6934151279876759"},"_hasShrinkwrap":false,"deprecated":"This package has been deprecated. v2 of this library has been renamed to @badgateway/oauth2-client"},"0.7.6":{"name":"fetch-mw-oauth2","version":"0.7.6","description":"Fetch middleware to add OAuth2 support","main":"dist/index.js","scripts":{"test":"make test lint","prepublishOnly":"make build"},"repository":{"type":"git","url":"git+ssh://git@github.com/badgateway/fetch-mw-oauth2.git"},"keywords":["fetch","oauth2"],"author":{"name":"Evert Pot","url":"https://evertpot.com"},"license":"MIT","bugs":{"url":"https://github.com/badgateway/fetch-mw-oauth2/issues"},"homepage":"https://github.com/badgateway/fetch-mw-oauth2#readme","devDependencies":{"@types/node":"^12.20.4","@typescript-eslint/eslint-plugin":"^4.15.2","@typescript-eslint/parser":"^4.15.2","awesome-typescript-loader":"^5.2.1","eslint":"^7.20.0","node-fetch":"^2.6.1","typescript":"^4.1.5","webpack":"^5.24.0","webpack-cli":"^4.5.0"},"dependencies":{},"browser":"browser/fetch-mw-oauth2.min.js","gitHead":"a36fcda53beac56b6a549e1e167964a4990ae33d","_id":"fetch-mw-oauth2@0.7.6","_nodeVersion":"14.15.5","_npmVersion":"6.14.11","dist":{"integrity":"sha512-LN2dPB1omRya+Vd7wz3TYoAvSGu6/A3Pnd8PTBDuAuUF+cNSjpiHcQkkInLEZoQhQif5MOg9yY/MFNvpnPkjuw==","shasum":"fb4bf3c66d04ed0593e11744d5ea91ea2ada0f16","tarball":"https://registry.npmjs.org/fetch-mw-oauth2/-/fetch-mw-oauth2-0.7.6.tgz","fileCount":35,"unpackedSize":73097,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJgNFSlCRA9TVsSAnZWagAARCwP/2LUTtiY6+pyR2Q7FhlF\nRhK+ZKFf731StIukF64jMRD9zt1E5OsjfEBm97iB20iLmNLEY2WCjXuzYQNH\nwIsLYBucNCXdmuTw8v/cRnYC2qVe9inGuIKLHDJkoP6wuL4AGTHN/hcmGjFM\nT0nPQro5QwAhnRcANcQjWE6lulxv0OrWMc390Hmps++v7yJRq0B68XeFCId9\n8tU4zB793UQdtMbsB4T1LwJ3bqjMBiW6Q2tDHRA8Ouft1iKR0viq3eNjnkFT\ncCefQwHq4IdnXfElxsBWgMy5fxbNY6KmxnXW5HgKWhd4DaFDvIrGpmV3Hlcq\nosbVvwyzwsLsazdOxsGteBexV/K1Nfqainq+H4t1/wDrJazqdyBS77P82zp0\nXoi4FIK59MEQQxNZ5Z+R7OdOwFH3wimVKm3FfgISqlTdHmpuYQA1E+nTVbPV\n92iU/1w1MqJOiHBUWWlZc/UFSDSzlBnPfYXN3eZFMxjBetbv0Uukm7H5rKQh\n3lcsZUxbQJW3dHdktdB11G0UMszyCkaF2B9g6LcYeRkLO8ytZ+M1iVermn4B\njLMZtq18Bwh39oZCdgK+pB2ZaE9rkErWQiKjHQG/heRZW5H8GArV5mTPPmQW\nPDS9luSVzvdQQYFQK0XkGsCWuxi+dn+MKOXZLSA0Ny20E3aBPBUQlO3b+Iva\nSyyo\r\n=/07e\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCD8QZfDzECab1eBdjrqKQgNKcjpKLClVpyGQl5uzI0kgIhAOiYvvvL+ljPIC3nxYJn9x5s+2hmNuyO7zq8J8wXfMN6"}]},"_npmUser":{"name":"evrt","email":"me@evertpot.com"},"directories":{},"maintainers":[{"name":"evrt","email":"me@evertpot.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fetch-mw-oauth2_0.7.6_1614042277192_0.30810379837446233"},"_hasShrinkwrap":false,"deprecated":"This package has been deprecated. v2 of this library has been renamed to @badgateway/oauth2-client"},"0.7.7":{"name":"fetch-mw-oauth2","version":"0.7.7","description":"Fetch middleware to add OAuth2 support","main":"dist/index.js","scripts":{"test":"make test lint","prepublishOnly":"make build"},"repository":{"type":"git","url":"git+ssh://git@github.com/badgateway/fetch-mw-oauth2.git"},"keywords":["fetch","oauth2"],"author":{"name":"Evert Pot","url":"https://evertpot.com"},"license":"MIT","bugs":{"url":"https://github.com/badgateway/fetch-mw-oauth2/issues"},"homepage":"https://github.com/badgateway/fetch-mw-oauth2#readme","devDependencies":{"@types/node":"^12.20.4","@typescript-eslint/eslint-plugin":"^4.15.2","@typescript-eslint/parser":"^4.15.2","awesome-typescript-loader":"^5.2.1","eslint":"^7.20.0","node-fetch":"^2.6.1","typescript":"^4.1.5","webpack":"^5.24.0","webpack-cli":"^4.5.0"},"dependencies":{},"browser":"browser/fetch-mw-oauth2.min.js","gitHead":"d92fd23a82ee33e57c9565bc07fe6667b99465fb","_id":"fetch-mw-oauth2@0.7.7","_nodeVersion":"14.15.5","_npmVersion":"6.14.11","dist":{"integrity":"sha512-HcV/0FqDEDouzNy/p2uo+jbsC2wX3cqaF1rcfwfyiN8uEAQNcgbKxAvuRz4egATxjvUa273ugyAO17gpU3exkg==","shasum":"e92cef2004f29ced50569d0952ff9835338df7da","tarball":"https://registry.npmjs.org/fetch-mw-oauth2/-/fetch-mw-oauth2-0.7.7.tgz","fileCount":35,"unpackedSize":74162,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJgNFWpCRA9TVsSAnZWagAAdNwP/3rGuYdx5RG/SSdAzm0B\nF6xkB0hWvoDoDpweMgHGW10Ij9YLUFMsmT2w8FE0fFsaxel/9MyD+3MO1L9P\nOaj/OC4NPi2evZuxXUb50sRzdPl3X0uhfTjX0VzRrkaFb9w6aaahjHkjKT+V\nBdMC9pGLhwYRLQQc+IEC35pM/s6RET3TcORFZpbB5pNDU3HzxotRbIMvB/48\nn457iflXysTCldsyGNGuSx2knNwEz7hjiIXz/OanviEkz9txccjTMNXXnrNb\nKS2Gun/F52As/cXAUgSlllb203xvQO0TbN/oagoNcoxknq/aSE0CdLfMEzxZ\n8Cz37W4/+yiOwvYjctoAS8KCojaL4zqJ22fKba9+XZLFbeFo+NczB1qoQmB4\nstkwtKoF+HedRKE0JTKoIEHcFZlHxKubq5xpZ6Fkzy10fzw1sh+2NZItyKlz\nBca4gCFkAbakUjEOBhaEzX0g0qTQpR17pjYgzExfrEKqcmlj/4ugcX3e7WH+\ngSvPQOWwd1DpO1jFmsjBxASy2V/mNzK8nOR4CIluxcVuYqFIJtRh2GXO1sCz\nOpBfiupeCW+zW40tMTBDbPV065sWza2znzGRM9hxiqokJxRReNzlEEljgqfS\ndJFFkiaN4wBdBKNlyWFr8LjMtRB5ctIaaPtXGOwvHOFm1uebKcMLxiMQ5m1Z\nBxyR\r\n=sR1O\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCRDFQV7rMJ7Krk5w1HxLjqhs6+34mgqF6p8ptuT6SBGAIgUrimCK04rYTjaBsW+IfWR4ld6EWloZ3QDU09nXXYzMg="}]},"_npmUser":{"name":"evrt","email":"me@evertpot.com"},"directories":{},"maintainers":[{"name":"evrt","email":"me@evertpot.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fetch-mw-oauth2_0.7.7_1614042537072_0.26765437205065346"},"_hasShrinkwrap":false,"deprecated":"This package has been deprecated. v2 of this library has been renamed to @badgateway/oauth2-client"},"1.0.0":{"name":"fetch-mw-oauth2","version":"1.0.0","description":"Fetch middleware to add OAuth2 support","main":"dist/index.js","scripts":{"test":"make test lint","prepublishOnly":"make build"},"repository":{"type":"git","url":"git+ssh://git@github.com/badgateway/fetch-mw-oauth2.git"},"keywords":["fetch","oauth2"],"author":{"name":"Evert Pot","url":"https://evertpot.com"},"license":"MIT","bugs":{"url":"https://github.com/badgateway/fetch-mw-oauth2/issues"},"homepage":"https://github.com/badgateway/fetch-mw-oauth2#readme","devDependencies":{"@types/node":"^12.20.36","@typescript-eslint/eslint-plugin":"^5.2.0","@typescript-eslint/parser":"^5.2.0","eslint":"^8.1.0","node-fetch":"^3.0.0","ts-loader":"^9.2.6","typescript":"^4.4.4","webpack":"^5.60.0","webpack-cli":"^4.9.1"},"browser":"browser/fetch-mw-oauth2.min.js","types":"./dist/index.d.ts","gitHead":"84a5d1fbf6e2606d60ac1bf0a1cf89158c97cef7","_id":"fetch-mw-oauth2@1.0.0","_nodeVersion":"16.13.0","_npmVersion":"8.1.0","dist":{"integrity":"sha512-Go1epFchfJye/EKWYEpihDJF2p+U9lzeqyZl0hJHkKzNFQk2ffrw5y8mEjYNZjHYJjf31aJDQRVodWkJFiv0oA==","shasum":"f6086e7bc46a24c9a74570ecc1dfb94d9307d365","tarball":"https://registry.npmjs.org/fetch-mw-oauth2/-/fetch-mw-oauth2-1.0.0.tgz","fileCount":34,"unpackedSize":70346,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJh2q8nCRA9TVsSAnZWagAAI84P/35WDiIZWVBD7uRT8OKj\nqj/ntufyUsKpgBx6WFUfBLWNXAwQT/A5MCpD190+d5aUBUX0WIkA2QKsR8iZ\nj3UFoVmz4gYdKEQuDYYrTq5FLVUqVftsetxo3WM+tJu2FTEBNu5dy99vrK2f\nrYaPXuTO8A/JVMIxRgPnTzhLZyMZfpui9gvx00eOiRFGYZ4lM/eDmV4qS3ox\nYl2Xv3JhW6Hze9H7prlm5Rjrb16o4uSpIdLGfBSBx5wnXU3TFwj+s1+WmiMs\nhBzh1kY83iqLRo/XIib26YS0MPP5Y5kRdc4nMq9xVM0VGalettPRwzxd7abN\nP8FMekyXTv8wrFCxfpllMJxLUe/9Tl/fV5zrXlleEhDRmn2yltttRvJhm6Y4\n12LWfBIsTDZCI2CZlc4/AkHMFb/58JhLDct4sdmAjHUV2VNuvkMd3LZnO3+q\nuk+hc8jzcjcGHx3bjoY/amOLKOWtUVk9uqjIO7d4u4x9nqGudcfJ9HsMtU0N\nTqbvpf/8E7r7fnFLk7AWOSnztm+W6OONpE/fhh77gAFD/bDjgbyAn7wJx4Bs\nZ0QCFkxjSiV8qSw6TeNw2M9+/OiEm2jSwnHcaZzoxVir0kafdDHsqdQvAWHJ\nKNkMaHF6qVsnaIX0/sRuX9Dy2P6eRxlZoLJ9xr0Y91GcIUKKJAGiU6iNNdup\n2LAA\r\n=BZfn\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIB3b1RDKGdz6hcWpRBR7G5ZbU9at1yKZjeixBccPHBy6AiEA1unuxacwcrZ1KxAFyT6Fb0DwGPBp0l8nIJs1h6ntv6c="}]},"_npmUser":{"name":"evrt","email":"me@evertpot.com"},"directories":{},"maintainers":[{"name":"evrt","email":"me@evertpot.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fetch-mw-oauth2_1.0.0_1635455717939_0.5225989681122363"},"_hasShrinkwrap":false,"deprecated":"This package has been deprecated. v2 of this library has been renamed to @badgateway/oauth2-client"},"2.0.0":{"name":"fetch-mw-oauth2","version":"2.0.0","description":"Fetch middleware to add OAuth2 support","main":"dist/index.js","scripts":{"test":"make test lint","prepublishOnly":"make build"},"repository":{"type":"git","url":"git+ssh://git@github.com/badgateway/fetch-mw-oauth2.git"},"keywords":["fetch","oauth2"],"author":{"name":"Evert Pot","url":"https://evertpot.com"},"license":"MIT","bugs":{"url":"https://github.com/badgateway/fetch-mw-oauth2/issues"},"homepage":"https://github.com/badgateway/fetch-mw-oauth2#readme","devDependencies":{"@types/node":"^17.0.25","@typescript-eslint/eslint-plugin":"^5.2.0","@typescript-eslint/parser":"^5.2.0","eslint":"^8.1.0","node-fetch":"^3.0.0","ts-loader":"^9.2.6","typescript":"^4.4.4","webpack":"^5.60.0","webpack-cli":"^4.9.1"},"browser":"browser/fetch-mw-oauth2.min.js","types":"./dist/index.d.ts","readme":"# fetch-mw-oauth2\n\nThis package contains an OAuth2 client. It aims to be a fully-featured OAuth2\nutility library, for Node.js, Browsers and written in Typescript.\n\nThis library supports the following features:\n\n* `authorization_code` grant with optional [PKCE][1] support.\n* `password` and `client_credentials` grant.\n* a `fetch()` wrapper that automatically adds Bearer tokens and refreshes them.\n* OAuth2 endpoint discovery via the Server metadata document ([RFC8414][2]).\n* OAuth2 Token Introspection ([RFC7662][3]).\n\n\n## Installation\n\n```sh\nnpm i fetch-mw-oauth2\n```\n\n## Usage\n\nTo get started, set up the Client class.\n\n\n```typescript\nimport { OAuth2Client } from 'fetch-mw-oauth2';\n\nconst client = new Client({\n\n  // The base URI of your OAuth2 server\n  server: 'https://my-auth-server/',\n\n  // OAuth2 client id\n  clientId: '...',\n\n  // OAuth2 client secret. Only required for 'client_credentials', 'password'\n  // flows. You should not specify this for authorization_code.\n  clientSecret: '...',\n\n\n  // The following URIs are all optional. If they are not specified, we will\n  // attempt to discover them using the oauth2 discovery document.\n  // If your server doesn't have support this, you may need to specify these.\n  // you may use relative URIs for any of these.\n\n\n  // Token endpoint. Most flows need this.\n  // If not specified we'll use the information for the discovery document\n  // first, and otherwise default to /token\n  tokenEndpoint: '/token',\n\n  // Authorization endpoint.\n  //\n  // You only need this to generate URLs for authorization_code flows.\n  // If not specified we'll use the information for the discovery document\n  // first, and otherwise default to /authorize\n  authorizationEndpoint: '/authorize',\n\n  // OAuth2 Metadata discovery endpoint.\n  //\n  // This document is used to determine various server features.\n  // If not specified, we assume it's on /.well-known/oauth2-authorization-server\n  discoveryEndpoint: '/.well-known/oauth2-authorization-server',\n\n});\n```\n\n### Tokens\n\nMany functions use or return a 'OAuth2Token' type. This type has the following\nshape:\n\n```typescript\nexport type OAuth2Token = {\n  accessToken: string;\n  refreshToken: string | null;\n\n  /**\n   * When the Access Token expires.\n   *\n   * This is expressed as a unix timestamp in milliseconds.\n   */\n  expiresAt: number | null;\n\n};\n```\n\n\n### client_credentials grant.\n\n```typescript\nconst token = await client.clientCredentials();\n```\n\n### Refreshing tokens\n\n```typescript\nconst newToken = await client.refresh(oldToken);\n```\n\n\n### password grant:\n\n```typescript\nconst token = await client.password({\n  username: '..',\n  password: '..',\n});\n```\n\n### authorization_code\n\nThe `authorization_code` flow is the flow for browser-based applications,\nand roughly consists of 3 major steps:\n\n1. Redirect the user to an authorization endpoint, where they log in.\n2. Authorization endpoint redirects back to app with a 'code' query\n   parameter.\n3. The `code` is exchanged for a access and refresh token.\n\nThis library provides support for all 3 steps, but there's no requirement\nto use its functionality as the system is mostly stateless.\n\n```typescript\nimport { OAuth2Client } from 'client';\n\nconst client = new OAuth2Client({\n  server: 'https://authserver.example/',\n  clientId: '...',\n\n  // Note, if urls cannot be auto-detected, also specify these:\n  tokenEndpoint: '/token',\n  authorizationEndpoint: '/authorize',\n});\n\nconst authorizationCode = client.authorizationCode({\n\n  // URL in the app that the user should get redirected to after authenticating\n  redirectUri: 'https://my-app.example/',\n\n  // Optional string that can be sent along to the auth server. This value will\n  // be sent along with the redirect back to the app verbatim.\n  state: 'some-string',\n});\n```\n\n**Redirecting the user to the authorization server**\n\n```typescript\n// In a browser this might work as follows:\ndocument.location = await authorizationCode.getAuthorizeUri();\n```\n\n**Handling the redirect back to the app and obtain token**\n\n```typescript\nconst codeResponse = await authorizationCode.validateResponse(\n  document.location\n);\n\nconst oauth2Token = await authorizationCode.getToken(codeResponse);\n```\n\n\n### Fetch Wrapper\n\nWhen using an OAuth2-protected API, typically you will need to obtain an Access\ntoken, and then add this token to each request using an `Authorization: Bearer`\nheader.\n\nBecause access tokens have a limited lifetime, and occasionally needs to be\nrefreshed this is a bunch of potential plumbing.\n\nTo make this easier, this library has a 'fetch wrapper'. This is effectively\njust like a regular fetch function, except it automatically adds the header\nand will automatically refresh tokens when needed.\n\nUsage:\n\n```typescript\nimport { OAuth2Client, OAuth2Fetch } from 'fetch-mw-oauth2';\n\nconst client = new OAuth2Client({\n  server: 'https://my-auth-server',\n  clientId: 'my-client-id'\n});\n\n\nconst fetchWrapper = new OAuth2Fetch({\n  client: client,\n\n  /**\n   * You are responsible for implementing this function.\n   * it's purpose is to supply the 'intitial' oauth2 token.\n   */\n  getNewToken: async () => {\n\n    // Example\n    return client.clientCredentials();     \n\n    // Another example\n    return client.authorizationCode({\n      code: '..',\n      redirectUri: '..',\n    });\n\n    // You can return null to fail the process. You may want to do this\n    // when a user needs to be redirected back to the authorization_code\n    // endpoints.\n    return null;\n\n  },\n\n  /**\n   * Optional. This will be called for any fatal authentication errors.\n   */\n  onError: (err) => {\n    // err is of type Error\n  }\n\n});\n```\n\nAfter set up, you can just call `fetch` on the new object ot call your API, and\nthe library will ensure there's always a `Bearer` header.\n\n```typescript\nconst response = fetchWrapper.fetch('https://my-api', {\n  method: 'POST',\n  body: 'Hello world'\n});\n```\n\n### Storing tokens for later use with FetchWrapper\n\nTo keep a user logged in between sessions, you may want to avoid full\nreauthentication. To do this, you'll need to store authentication token.\n\nThe fetch wrapper has 2 functions to help with this:\n\n```typescript\n\nconst fetchWrapper = new OAuth2Fetch({\n  client: client,\n\n  getNewToken: async () => {\n\n    // See above!\n\n  },\n\n  /**\n   * This function is called whenever the active token changes. Using this is\n   * optional, but it may be used to (for example) put the token in off-line\n   * storage for later usage.\n   */\n  storeToken: (token) => {\n    document.localStorage.setItem('token-store', JSON.stringify(token));\n  }\n\n  /**\n   * Also an optional feature. Implement this if you want the wrapper to try a\n   * stored token before attempting a full reauthentication.\n   *\n   * This function may be async. Return null if there was no token.\n   */\n  getStoredToken: () => {\n    const token = document.localStorage.getItem('token-store');\n    if (token) return JSON.parse(token);\n    return null;\n  }\n\n});\n```\n\n\n### fetchMw function\n\nIt might be preferable to use this library as a more traditional 'middleware'.\n\nThe OAuth2Fetch object also exposes a `fetchMw` function that takes 2 arguments:\n\n1. `request`\n2. `next`\n\nThe next argument is a function that also takes a request and returns a\nresponse.\n\nUsually you will want to use this with some kind of fetch middleware container,\nas such:\n\n```typescript\nmyFetchMiddleware(oauth2.fetchMw);\n```\n\nBut it's also possible to use it directly. For example:\n\n```typescript\noauth2.fetchMw(myRequest, innerRequest => fetch(innerRequest));\n```\n\n### Introspection\n\nIntrospection ([RFC7662][3]) lets you find more information about a token,\nsuch as whether it's valid, which user it belongs to, which oauth2 client\nwas used to generate it, etc.\n\nTo be able to use it, your authorization server must have support for the\nintrospection endpoint. It's location will be automatically detected using\nthe Metadata discovery document.\n\n```typescript\nimport { OAuth2Client } from 'fetch-mw-oauth2';\n\nconst client = new Client({\n  server: 'https://auth-server.example/',\n\n  clientId: '...',\n\n  /**\n   * Some servers require OAuth2 clientId/clientSecret to be passed.\n   * If they require it, specify it. If not it's fine to omit.\n   */\n  clientSecret: '...',\n\n});\n\n// Get a token\nconst token = client.clientCredentials();\n\n// Introspect!\nconsole.log(client.introspect(token));\n```\n\n[1]: https://datatracker.ietf.org/doc/html/rfc7636 \"Proof Key for Code Exchange by OAuth Public Clients\"\n[2]: https://datatracker.ietf.org/doc/html/rfc8414 \"OAuth 2.0 Authorization Server Metadata\"\n[3]: https://datatracker.ietf.org/doc/html/rfc7662 \"OAuth 2.0 Token Introspection\"\n","readmeFilename":"README.md","gitHead":"072a9d485743e990def896130c14dfedb1c27e6f","_id":"fetch-mw-oauth2@2.0.0","_nodeVersion":"17.9.0","_npmVersion":"8.5.5","dist":{"integrity":"sha512-Qduejmnwu0XL5f/M8lvXtaX5EOcQ4wfq1kzOJcCGB5trRZTwhIR4b2DxDV/D6UvwdSwZMpMG+5v3hLkNMh0iNQ==","shasum":"a3df8c5320dc2c21ded61fc4e316a5a0a61f21a0","tarball":"https://registry.npmjs.org/fetch-mw-oauth2/-/fetch-mw-oauth2-2.0.0.tgz","fileCount":46,"unpackedSize":131863,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIEiit1QZY88K98tG2dLEwnJsStcDjb01xLA22z7+JgS2AiB8TD4SWO5bVvrnpWrEBQo3VDW3RQPV1rV9wQilS6NiRQ=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiXzzkACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrUnxAAkcgeWXm9TXE3cgnv/1QUJZpkxLJCjnE2rf1VYLYRUS7+iJbt\r\nFdIN/gmaEDuXrvrpUx5809/qdF8Ys0hIIjj5q85grQkyiS7kexW3jetROeAi\r\n3xB86d9hBRlgIYx+fnGQhP8b0JC68+UW3SbATiohTir/viz45sxuCotlgN7W\r\nHXoW76MOFgNKfFn0f5mBnVIuUrB+3LEB7XywVWdethdFBgveWKKktuVVTzeM\r\n9yVvxea8zyf0UfXLNd9a8pghnJcIZNPNIq0f+z+22KMalGubEi7UCiZ0iWjv\r\nMKAsypwtgpLF8KWwnmTrgFhXbXbjPSgm0Fr62mUvDdXqNIbt3lkvsmSQsTCz\r\nS4wIxF6nxNUACZ5dbvdu7sLk32sfjRj1XOC9MjyQRReNuNNsCmSxTrgWCByO\r\nHzHl7UQlUtSkNkDDM17VY4zrNvkZrgh2OqFGzNqTPprA3sJQyHbxO4lRiQ60\r\nIkuc0Ra9cnXP5A2F81aT2t+rowiiovE6FH3WBjXpfMt7+8Q7kP4jPJz2bE+o\r\nc15rfRjKKEma3ki3qM6sqpVVkaohRqKsEeUGcSM6OojOzMq3oScxqZNMdpkb\r\nbsy608KRV8BXgv8+05n2OIVtgvPTSoWm12Qw+AsPzkrVVZE5kbdnxybfc1w7\r\nCHRoZSuy/1ISG8mZ8LC6cUoA9Tv189OcQRQ=\r\n=xuSS\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"evrt","email":"me@evertpot.com"},"directories":{},"maintainers":[{"name":"evrt","email":"me@evertpot.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fetch-mw-oauth2_2.0.0_1650408676065_0.4353421730596785"},"_hasShrinkwrap":false,"deprecated":"This package has been deprecated. v2 of this library has been renamed to @badgateway/oauth2-client"},"2.0.1":{"name":"fetch-mw-oauth2","version":"2.0.1","description":"Fetch middleware to add OAuth2 support","main":"dist/index.js","scripts":{"test":"make test lint","prepublishOnly":"make build"},"repository":{"type":"git","url":"git+ssh://git@github.com/badgateway/fetch-mw-oauth2.git"},"keywords":["fetch","oauth2"],"author":{"name":"Evert Pot","url":"https://evertpot.com"},"license":"MIT","bugs":{"url":"https://github.com/badgateway/fetch-mw-oauth2/issues"},"homepage":"https://github.com/badgateway/fetch-mw-oauth2#readme","devDependencies":{"@types/node":"^17.0.25","@typescript-eslint/eslint-plugin":"^5.2.0","@typescript-eslint/parser":"^5.2.0","eslint":"^8.1.0","node-fetch":"^3.0.0","ts-loader":"^9.2.6","typescript":"^4.4.4","webpack":"^5.60.0","webpack-cli":"^4.9.1"},"browser":"browser/fetch-mw-oauth2.min.js","types":"./dist/index.d.ts","readme":"# fetch-mw-oauth2\n\nThis package contains an OAuth2 client. It aims to be a fully-featured OAuth2\nutility library, for Node.js, Browsers and written in Typescript.\n\nThis library supports the following features:\n\n* `authorization_code` grant with optional [PKCE][1] support.\n* `password` and `client_credentials` grant.\n* a `fetch()` wrapper that automatically adds Bearer tokens and refreshes them.\n* OAuth2 endpoint discovery via the Server metadata document ([RFC8414][2]).\n* OAuth2 Token Introspection ([RFC7662][3]).\n\n\n## Installation\n\n```sh\nnpm i fetch-mw-oauth2\n```\n\n## Usage\n\nTo get started, set up the Client class.\n\n\n```typescript\nimport { OAuth2Client } from 'fetch-mw-oauth2';\n\nconst client = new Client({\n\n  // The base URI of your OAuth2 server\n  server: 'https://my-auth-server/',\n\n  // OAuth2 client id\n  clientId: '...',\n\n  // OAuth2 client secret. Only required for 'client_credentials', 'password'\n  // flows. You should not specify this for authorization_code.\n  clientSecret: '...',\n\n\n  // The following URIs are all optional. If they are not specified, we will\n  // attempt to discover them using the oauth2 discovery document.\n  // If your server doesn't have support this, you may need to specify these.\n  // you may use relative URIs for any of these.\n\n\n  // Token endpoint. Most flows need this.\n  // If not specified we'll use the information for the discovery document\n  // first, and otherwise default to /token\n  tokenEndpoint: '/token',\n\n  // Authorization endpoint.\n  //\n  // You only need this to generate URLs for authorization_code flows.\n  // If not specified we'll use the information for the discovery document\n  // first, and otherwise default to /authorize\n  authorizationEndpoint: '/authorize',\n\n  // OAuth2 Metadata discovery endpoint.\n  //\n  // This document is used to determine various server features.\n  // If not specified, we assume it's on /.well-known/oauth2-authorization-server\n  discoveryEndpoint: '/.well-known/oauth2-authorization-server',\n\n});\n```\n\n### Tokens\n\nMany functions use or return a 'OAuth2Token' type. This type has the following\nshape:\n\n```typescript\nexport type OAuth2Token = {\n  accessToken: string;\n  refreshToken: string | null;\n\n  /**\n   * When the Access Token expires.\n   *\n   * This is expressed as a unix timestamp in milliseconds.\n   */\n  expiresAt: number | null;\n\n};\n```\n\n\n### client_credentials grant.\n\n```typescript\nconst token = await client.clientCredentials();\n```\n\n### Refreshing tokens\n\n```typescript\nconst newToken = await client.refresh(oldToken);\n```\n\n\n### password grant:\n\n```typescript\nconst token = await client.password({\n  username: '..',\n  password: '..',\n});\n```\n\n### authorization_code\n\nThe `authorization_code` flow is the flow for browser-based applications,\nand roughly consists of 3 major steps:\n\n1. Redirect the user to an authorization endpoint, where they log in.\n2. Authorization endpoint redirects back to app with a 'code' query\n   parameter.\n3. The `code` is exchanged for a access and refresh token.\n\nThis library provides support for all 3 steps, but there's no requirement\nto use its functionality as the system is mostly stateless.\n\n```typescript\nimport { OAuth2Client } from 'client';\n\nconst client = new OAuth2Client({\n  server: 'https://authserver.example/',\n  clientId: '...',\n\n  // Note, if urls cannot be auto-detected, also specify these:\n  tokenEndpoint: '/token',\n  authorizationEndpoint: '/authorize',\n});\n\nconst authorizationCode = client.authorizationCode({\n\n  // URL in the app that the user should get redirected to after authenticating\n  redirectUri: 'https://my-app.example/',\n\n  // Optional string that can be sent along to the auth server. This value will\n  // be sent along with the redirect back to the app verbatim.\n  state: 'some-string',\n});\n```\n\n**Redirecting the user to the authorization server**\n\n```typescript\n// In a browser this might work as follows:\ndocument.location = await authorizationCode.getAuthorizeUri();\n```\n\n**Handling the redirect back to the app and obtain token**\n\n```typescript\nconst codeResponse = await authorizationCode.validateResponse(\n  document.location\n);\n\nconst oauth2Token = await authorizationCode.getToken(codeResponse);\n```\n\n\n### Fetch Wrapper\n\nWhen using an OAuth2-protected API, typically you will need to obtain an Access\ntoken, and then add this token to each request using an `Authorization: Bearer`\nheader.\n\nBecause access tokens have a limited lifetime, and occasionally needs to be\nrefreshed this is a bunch of potential plumbing.\n\nTo make this easier, this library has a 'fetch wrapper'. This is effectively\njust like a regular fetch function, except it automatically adds the header\nand will automatically refresh tokens when needed.\n\nUsage:\n\n```typescript\nimport { OAuth2Client, OAuth2Fetch } from 'fetch-mw-oauth2';\n\nconst client = new OAuth2Client({\n  server: 'https://my-auth-server',\n  clientId: 'my-client-id'\n});\n\n\nconst fetchWrapper = new OAuth2Fetch({\n  client: client,\n\n  /**\n   * You are responsible for implementing this function.\n   * it's purpose is to supply the 'intitial' oauth2 token.\n   */\n  getNewToken: async () => {\n\n    // Example\n    return client.clientCredentials();     \n\n    // Another example\n    return client.authorizationCode({\n      code: '..',\n      redirectUri: '..',\n    });\n\n    // You can return null to fail the process. You may want to do this\n    // when a user needs to be redirected back to the authorization_code\n    // endpoints.\n    return null;\n\n  },\n\n  /**\n   * Optional. This will be called for any fatal authentication errors.\n   */\n  onError: (err) => {\n    // err is of type Error\n  }\n\n});\n```\n\nAfter set up, you can just call `fetch` on the new object ot call your API, and\nthe library will ensure there's always a `Bearer` header.\n\n```typescript\nconst response = fetchWrapper.fetch('https://my-api', {\n  method: 'POST',\n  body: 'Hello world'\n});\n```\n\n### Storing tokens for later use with FetchWrapper\n\nTo keep a user logged in between sessions, you may want to avoid full\nreauthentication. To do this, you'll need to store authentication token.\n\nThe fetch wrapper has 2 functions to help with this:\n\n```typescript\n\nconst fetchWrapper = new OAuth2Fetch({\n  client: client,\n\n  getNewToken: async () => {\n\n    // See above!\n\n  },\n\n  /**\n   * This function is called whenever the active token changes. Using this is\n   * optional, but it may be used to (for example) put the token in off-line\n   * storage for later usage.\n   */\n  storeToken: (token) => {\n    document.localStorage.setItem('token-store', JSON.stringify(token));\n  }\n\n  /**\n   * Also an optional feature. Implement this if you want the wrapper to try a\n   * stored token before attempting a full reauthentication.\n   *\n   * This function may be async. Return null if there was no token.\n   */\n  getStoredToken: () => {\n    const token = document.localStorage.getItem('token-store');\n    if (token) return JSON.parse(token);\n    return null;\n  }\n\n});\n```\n\n\n### fetchMw function\n\nIt might be preferable to use this library as a more traditional 'middleware'.\n\nThe OAuth2Fetch object also exposes a `fetchMw` function that takes 2 arguments:\n\n1. `request`\n2. `next`\n\nThe next argument is a function that also takes a request and returns a\nresponse.\n\nUsually you will want to use this with some kind of fetch middleware container,\nas such:\n\n```typescript\nmyFetchMiddleware(oauth2.fetchMw);\n```\n\nBut it's also possible to use it directly. For example:\n\n```typescript\noauth2.fetchMw(myRequest, innerRequest => fetch(innerRequest));\n```\n\n### Introspection\n\nIntrospection ([RFC7662][3]) lets you find more information about a token,\nsuch as whether it's valid, which user it belongs to, which oauth2 client\nwas used to generate it, etc.\n\nTo be able to use it, your authorization server must have support for the\nintrospection endpoint. It's location will be automatically detected using\nthe Metadata discovery document.\n\n```typescript\nimport { OAuth2Client } from 'fetch-mw-oauth2';\n\nconst client = new Client({\n  server: 'https://auth-server.example/',\n\n  clientId: '...',\n\n  /**\n   * Some servers require OAuth2 clientId/clientSecret to be passed.\n   * If they require it, specify it. If not it's fine to omit.\n   */\n  clientSecret: '...',\n\n});\n\n// Get a token\nconst token = client.clientCredentials();\n\n// Introspect!\nconsole.log(client.introspect(token));\n```\n\n[1]: https://datatracker.ietf.org/doc/html/rfc7636 \"Proof Key for Code Exchange by OAuth Public Clients\"\n[2]: https://datatracker.ietf.org/doc/html/rfc8414 \"OAuth 2.0 Authorization Server Metadata\"\n[3]: https://datatracker.ietf.org/doc/html/rfc7662 \"OAuth 2.0 Token Introspection\"\n","readmeFilename":"README.md","gitHead":"2813873573c49d0fba87dcb00c8df0c196b36edb","_id":"fetch-mw-oauth2@2.0.1","_nodeVersion":"17.9.0","_npmVersion":"8.5.5","dist":{"integrity":"sha512-Bq8+HTXJ/3qnUwfd2dsbWG4aWBQSl+pWYeD9h/yCKBVZXUBDyodmlj2lgSj4bM18nuzgoyrH0Pkk57jQAhZ+Vw==","shasum":"fb2615d0ddea8d7e4c3941ba628fc2476801877a","tarball":"https://registry.npmjs.org/fetch-mw-oauth2/-/fetch-mw-oauth2-2.0.1.tgz","fileCount":46,"unpackedSize":131861,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIEvxhWX/BhSQ4Sa4lnVPT+44bLJi/pUWWur4+RzAguUIAiEApr4KZ4gfix6moPI4bit7D9EF6bPLTyAF0ncu9hjBeNQ="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiX0NSACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmonWg/5AdKDXcdkKdey6jF+QFNExdwLMXGoPifCrk13CSZ3+SlwVqPf\r\njk/ajAiF2KMJNwA2LQSTMiBaOZT9hkxLm4azWn+Hot1OPosLoz1wFyCEVdZs\r\niVomx4nxZbMsO8KBp/9BrBIZoM8Iszo5/+txviY6UNhjgZPNA8eiMErU5KKJ\r\nLNq70WjHcSpOEFKdQY4sFBMOuu3Sscfqrm6tmCCtIhZFKt+eNMYICV12inif\r\nBk6F1UgQuM56/+o9gNX3GWeGE87wqT8F/LtnC9+J3/ExMd9NJCoRH+QKIMyS\r\n+y+2KdL6zR6tQeTHLo4S5nWXvev8jEyDJ5DXTHqq5Qth/Cbcke7rQt67OU+r\r\n49L90aZbwuAjiwCco21GpwDGjfRTMndN4waeO2ek2/tMxAM1c+LV5zZiAwnK\r\n3LztP+FoMWUIBWtaueuIMuaKd01TzTglCdLgLpjJUnziaBH1ykQullhKSr0+\r\njje8Hymrv5m6QGKFGbPwl03W8eJBl2Pi3z6ZjobNR3gSnB+jcjBvH0f53M+V\r\nEl6kS9SeSuQ+Htjgt4+rTbgZ66ZxaP6J4zmA4lh1UzlY9l5k9fgvorREoGZQ\r\nyGj9NvKD7cJvkS9qHZwa4HZzwgMr2WZh8iWGiWTQAY6IiT1lbgMuLLUK3Aga\r\n0A7mN2HQHlwppj1rTkLuHuguN27+cRlcy7E=\r\n=g4XJ\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"evrt","email":"me@evertpot.com"},"directories":{},"maintainers":[{"name":"evrt","email":"me@evertpot.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fetch-mw-oauth2_2.0.1_1650410322200_0.40091301902089893"},"_hasShrinkwrap":false,"deprecated":"This package has been deprecated. v2 of this library has been renamed to @badgateway/oauth2-client"},"2.0.2":{"name":"fetch-mw-oauth2","version":"2.0.2","description":"Fetch middleware to add OAuth2 support","main":"dist/index.js","scripts":{"test":"make test lint","prepublishOnly":"make build"},"repository":{"type":"git","url":"git+ssh://git@github.com/badgateway/fetch-mw-oauth2.git"},"keywords":["fetch","oauth2"],"author":{"name":"Evert Pot","url":"https://evertpot.com"},"license":"MIT","bugs":{"url":"https://github.com/badgateway/fetch-mw-oauth2/issues"},"homepage":"https://github.com/badgateway/fetch-mw-oauth2#readme","devDependencies":{"@types/node":"^17.0.25","@typescript-eslint/eslint-plugin":"^5.2.0","@typescript-eslint/parser":"^5.2.0","eslint":"^8.1.0","node-fetch":"^3.0.0","ts-loader":"^9.2.6","typescript":"^4.4.4","webpack":"^5.60.0","webpack-cli":"^4.9.1"},"browser":"browser/fetch-mw-oauth2.min.js","types":"./dist/index.d.ts","readme":"# fetch-mw-oauth2\n\nThis package contains an OAuth2 client. It aims to be a fully-featured OAuth2\nutility library, for Node.js, Browsers and written in Typescript.\n\nThis library supports the following features:\n\n* `authorization_code` grant with optional [PKCE][1] support.\n* `password` and `client_credentials` grant.\n* a `fetch()` wrapper that automatically adds Bearer tokens and refreshes them.\n* OAuth2 endpoint discovery via the Server metadata document ([RFC8414][2]).\n* OAuth2 Token Introspection ([RFC7662][3]).\n\n\n## Installation\n\n```sh\nnpm i fetch-mw-oauth2\n```\n\n## Usage\n\nTo get started, set up the Client class.\n\n\n```typescript\nimport { OAuth2Client } from 'fetch-mw-oauth2';\n\nconst client = new Client({\n\n  // The base URI of your OAuth2 server\n  server: 'https://my-auth-server/',\n\n  // OAuth2 client id\n  clientId: '...',\n\n  // OAuth2 client secret. Only required for 'client_credentials', 'password'\n  // flows. You should not specify this for authorization_code.\n  clientSecret: '...',\n\n\n  // The following URIs are all optional. If they are not specified, we will\n  // attempt to discover them using the oauth2 discovery document.\n  // If your server doesn't have support this, you may need to specify these.\n  // you may use relative URIs for any of these.\n\n\n  // Token endpoint. Most flows need this.\n  // If not specified we'll use the information for the discovery document\n  // first, and otherwise default to /token\n  tokenEndpoint: '/token',\n\n  // Authorization endpoint.\n  //\n  // You only need this to generate URLs for authorization_code flows.\n  // If not specified we'll use the information for the discovery document\n  // first, and otherwise default to /authorize\n  authorizationEndpoint: '/authorize',\n\n  // OAuth2 Metadata discovery endpoint.\n  //\n  // This document is used to determine various server features.\n  // If not specified, we assume it's on /.well-known/oauth2-authorization-server\n  discoveryEndpoint: '/.well-known/oauth2-authorization-server',\n\n});\n```\n\n### Tokens\n\nMany functions use or return a 'OAuth2Token' type. This type has the following\nshape:\n\n```typescript\nexport type OAuth2Token = {\n  accessToken: string;\n  refreshToken: string | null;\n\n  /**\n   * When the Access Token expires.\n   *\n   * This is expressed as a unix timestamp in milliseconds.\n   */\n  expiresAt: number | null;\n\n};\n```\n\n\n### client_credentials grant.\n\n```typescript\nconst token = await client.clientCredentials();\n```\n\n### Refreshing tokens\n\n```typescript\nconst newToken = await client.refresh(oldToken);\n```\n\n\n### password grant:\n\n```typescript\nconst token = await client.password({\n  username: '..',\n  password: '..',\n});\n```\n\n### authorization_code\n\nThe `authorization_code` flow is the flow for browser-based applications,\nand roughly consists of 3 major steps:\n\n1. Redirect the user to an authorization endpoint, where they log in.\n2. Authorization endpoint redirects back to app with a 'code' query\n   parameter.\n3. The `code` is exchanged for a access and refresh token.\n\nThis library provides support for all 3 steps, but there's no requirement\nto use its functionality as the system is mostly stateless.\n\n```typescript\nimport { OAuth2Client } from 'client';\n\nconst client = new OAuth2Client({\n  server: 'https://authserver.example/',\n  clientId: '...',\n\n  // Note, if urls cannot be auto-detected, also specify these:\n  tokenEndpoint: '/token',\n  authorizationEndpoint: '/authorize',\n});\n\nconst authorizationCode = client.authorizationCode({\n\n  // URL in the app that the user should get redirected to after authenticating\n  redirectUri: 'https://my-app.example/',\n\n  // Optional string that can be sent along to the auth server. This value will\n  // be sent along with the redirect back to the app verbatim.\n  state: 'some-string',\n});\n```\n\n**Redirecting the user to the authorization server**\n\n```typescript\n// In a browser this might work as follows:\ndocument.location = await authorizationCode.getAuthorizeUri();\n```\n\n**Handling the redirect back to the app and obtain token**\n\n```typescript\nconst codeResponse = await authorizationCode.validateResponse(\n  document.location\n);\n\nconst oauth2Token = await authorizationCode.getToken(codeResponse);\n```\n\n\n### Fetch Wrapper\n\nWhen using an OAuth2-protected API, typically you will need to obtain an Access\ntoken, and then add this token to each request using an `Authorization: Bearer`\nheader.\n\nBecause access tokens have a limited lifetime, and occasionally needs to be\nrefreshed this is a bunch of potential plumbing.\n\nTo make this easier, this library has a 'fetch wrapper'. This is effectively\njust like a regular fetch function, except it automatically adds the header\nand will automatically refresh tokens when needed.\n\nUsage:\n\n```typescript\nimport { OAuth2Client, OAuth2Fetch } from 'fetch-mw-oauth2';\n\nconst client = new OAuth2Client({\n  server: 'https://my-auth-server',\n  clientId: 'my-client-id'\n});\n\n\nconst fetchWrapper = new OAuth2Fetch({\n  client: client,\n\n  /**\n   * You are responsible for implementing this function.\n   * it's purpose is to supply the 'intitial' oauth2 token.\n   */\n  getNewToken: async () => {\n\n    // Example\n    return client.clientCredentials();     \n\n    // Another example\n    return client.authorizationCode({\n      code: '..',\n      redirectUri: '..',\n    });\n\n    // You can return null to fail the process. You may want to do this\n    // when a user needs to be redirected back to the authorization_code\n    // endpoints.\n    return null;\n\n  },\n\n  /**\n   * Optional. This will be called for any fatal authentication errors.\n   */\n  onError: (err) => {\n    // err is of type Error\n  }\n\n});\n```\n\nAfter set up, you can just call `fetch` on the new object ot call your API, and\nthe library will ensure there's always a `Bearer` header.\n\n```typescript\nconst response = fetchWrapper.fetch('https://my-api', {\n  method: 'POST',\n  body: 'Hello world'\n});\n```\n\n### Storing tokens for later use with FetchWrapper\n\nTo keep a user logged in between sessions, you may want to avoid full\nreauthentication. To do this, you'll need to store authentication token.\n\nThe fetch wrapper has 2 functions to help with this:\n\n```typescript\n\nconst fetchWrapper = new OAuth2Fetch({\n  client: client,\n\n  getNewToken: async () => {\n\n    // See above!\n\n  },\n\n  /**\n   * This function is called whenever the active token changes. Using this is\n   * optional, but it may be used to (for example) put the token in off-line\n   * storage for later usage.\n   */\n  storeToken: (token) => {\n    document.localStorage.setItem('token-store', JSON.stringify(token));\n  }\n\n  /**\n   * Also an optional feature. Implement this if you want the wrapper to try a\n   * stored token before attempting a full reauthentication.\n   *\n   * This function may be async. Return null if there was no token.\n   */\n  getStoredToken: () => {\n    const token = document.localStorage.getItem('token-store');\n    if (token) return JSON.parse(token);\n    return null;\n  }\n\n});\n```\n\n\n### fetchMw function\n\nIt might be preferable to use this library as a more traditional 'middleware'.\n\nThe OAuth2Fetch object also exposes a `fetchMw` function that takes 2 arguments:\n\n1. `request`\n2. `next`\n\nThe next argument is a function that also takes a request and returns a\nresponse.\n\nUsually you will want to use this with some kind of fetch middleware container,\nas such:\n\n```typescript\nmyFetchMiddleware(oauth2.fetchMw);\n```\n\nBut it's also possible to use it directly. For example:\n\n```typescript\noauth2.fetchMw(myRequest, innerRequest => fetch(innerRequest));\n```\n\n### Introspection\n\nIntrospection ([RFC7662][3]) lets you find more information about a token,\nsuch as whether it's valid, which user it belongs to, which oauth2 client\nwas used to generate it, etc.\n\nTo be able to use it, your authorization server must have support for the\nintrospection endpoint. It's location will be automatically detected using\nthe Metadata discovery document.\n\n```typescript\nimport { OAuth2Client } from 'fetch-mw-oauth2';\n\nconst client = new Client({\n  server: 'https://auth-server.example/',\n\n  clientId: '...',\n\n  /**\n   * Some servers require OAuth2 clientId/clientSecret to be passed.\n   * If they require it, specify it. If not it's fine to omit.\n   */\n  clientSecret: '...',\n\n});\n\n// Get a token\nconst token = client.clientCredentials();\n\n// Introspect!\nconsole.log(client.introspect(token));\n```\n\n[1]: https://datatracker.ietf.org/doc/html/rfc7636 \"Proof Key for Code Exchange by OAuth Public Clients\"\n[2]: https://datatracker.ietf.org/doc/html/rfc8414 \"OAuth 2.0 Authorization Server Metadata\"\n[3]: https://datatracker.ietf.org/doc/html/rfc7662 \"OAuth 2.0 Token Introspection\"\n","readmeFilename":"README.md","gitHead":"42e8d7f323fb08c4895d8f3a6d2d58bf0e0b1b7e","_id":"fetch-mw-oauth2@2.0.2","_nodeVersion":"17.9.0","_npmVersion":"8.5.5","dist":{"integrity":"sha512-Sx7rZLIplZlUPSHgO4EtBFDPLx4+lUibiFDA11w+nWE+tUa7O3JryQUMkwtU8JzG2EJtevjkezi2bwTkqqE3xw==","shasum":"a0bfdd5ad73b977746b4ddf2aed6d0cff3df925a","tarball":"https://registry.npmjs.org/fetch-mw-oauth2/-/fetch-mw-oauth2-2.0.2.tgz","fileCount":46,"unpackedSize":133186,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQChNDacxX5ujCeIR+4barUXr2R138znttA7mdz4WyHL7AIhAN1WKvWk1rojx8jhAe5jU24cveibj2X2j9pc97xCNHp+"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiX1pkACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmr+hw/8C45l8x0vrhcRkSZUO1PRsmEtlZ8P10cIFLiKxdmAj2bg7eEp\r\nyw50hlXTN6rCCcWhBLmv6R+FSDBRCiSyk33um33g+5XpaHRHbRIro/q+GPpl\r\nrhgMynKRSTwcI/ShOPTkMc36CySPaGFe7rzt/Qw5Y/aUtdjXnG5Fmiu7dNgV\r\nL2BKMuUTyKI0+mKRwXMeToVRHkccNHrt+VKal9NCDFoXuj70B3y/PH9DUGXj\r\nAOP3nXw0nKBrJeEHdaBgMKYKo2FkvhOuaKEF9labscAo45fMNTNLOf+F76DV\r\nL1YqaYw+rEpolVpsl6qbZbyoEyiXKJK/LLi8/3Yh95u3Y4MynKysxVK912tk\r\n9VO+2yAVg8H4SA6ZdTt8xBiAUWQqyrflWxZkTUBRWkhHKjZI5cPjqPIoCm01\r\nwYCRZ1NQI+bFMMHTSPhOwUbczuZl+7jBw2QXgW8CjqG/1L1jEvrM5Z4bwwZ9\r\nCrVrgEI0RkzgymEZ6eKjd8JkhFu+TBtsLPgESuBxfCRVerUNlq7B6qwSDKT/\r\nkGrQdOs+jSFWFHV7ncJ+AHafjGLU61OtB19hup7LGIPwhHT1kQ39Cu7OUmKt\r\nO3GVOTvIZUCxGoxGIlC7/rY1+i5LB3QUxdN/gmPHfLig6GI3hIEsSmoPSQH6\r\nL9smXW08ctigFf4DaXe+H39cbuVDOAnXHVc=\r\n=vp46\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"evrt","email":"me@evertpot.com"},"directories":{},"maintainers":[{"name":"evrt","email":"me@evertpot.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fetch-mw-oauth2_2.0.2_1650416228032_0.5288624673129974"},"_hasShrinkwrap":false,"deprecated":"This package has been deprecated. v2 of this library has been renamed to @badgateway/oauth2-client"},"2.0.3":{"name":"fetch-mw-oauth2","version":"2.0.3","description":"Fetch middleware to add OAuth2 support","main":"dist/index.js","scripts":{"test":"make test lint","prepublishOnly":"make build"},"repository":{"type":"git","url":"git+ssh://git@github.com/badgateway/fetch-mw-oauth2.git"},"keywords":["fetch","oauth2"],"author":{"name":"Evert Pot","url":"https://evertpot.com"},"license":"MIT","bugs":{"url":"https://github.com/badgateway/fetch-mw-oauth2/issues"},"homepage":"https://github.com/badgateway/fetch-mw-oauth2#readme","devDependencies":{"@types/node":"^17.0.25","@typescript-eslint/eslint-plugin":"^5.2.0","@typescript-eslint/parser":"^5.2.0","eslint":"^8.1.0","node-fetch":"^3.0.0","ts-loader":"^9.2.6","typescript":"^4.4.4","webpack":"^5.60.0","webpack-cli":"^4.9.1"},"browser":"browser/fetch-mw-oauth2.min.js","types":"./dist/index.d.ts","readme":"# fetch-mw-oauth2\n\nThis package contains an OAuth2 client. It aims to be a fully-featured OAuth2\nutility library, for Node.js, Browsers and written in Typescript.\n\nThis library supports the following features:\n\n* `authorization_code` grant with optional [PKCE][1] support.\n* `password` and `client_credentials` grant.\n* a `fetch()` wrapper that automatically adds Bearer tokens and refreshes them.\n* OAuth2 endpoint discovery via the Server metadata document ([RFC8414][2]).\n* OAuth2 Token Introspection ([RFC7662][3]).\n\n\n## Installation\n\n```sh\nnpm i fetch-mw-oauth2\n```\n\n## Usage\n\nTo get started, set up the Client class.\n\n\n```typescript\nimport { OAuth2Client } from 'fetch-mw-oauth2';\n\nconst client = new Client({\n\n  // The base URI of your OAuth2 server\n  server: 'https://my-auth-server/',\n\n  // OAuth2 client id\n  clientId: '...',\n\n  // OAuth2 client secret. Only required for 'client_credentials', 'password'\n  // flows. You should not specify this for authorization_code.\n  clientSecret: '...',\n\n\n  // The following URIs are all optional. If they are not specified, we will\n  // attempt to discover them using the oauth2 discovery document.\n  // If your server doesn't have support this, you may need to specify these.\n  // you may use relative URIs for any of these.\n\n\n  // Token endpoint. Most flows need this.\n  // If not specified we'll use the information for the discovery document\n  // first, and otherwise default to /token\n  tokenEndpoint: '/token',\n\n  // Authorization endpoint.\n  //\n  // You only need this to generate URLs for authorization_code flows.\n  // If not specified we'll use the information for the discovery document\n  // first, and otherwise default to /authorize\n  authorizationEndpoint: '/authorize',\n\n  // OAuth2 Metadata discovery endpoint.\n  //\n  // This document is used to determine various server features.\n  // If not specified, we assume it's on /.well-known/oauth2-authorization-server\n  discoveryEndpoint: '/.well-known/oauth2-authorization-server',\n\n});\n```\n\n### Tokens\n\nMany functions use or return a 'OAuth2Token' type. This type has the following\nshape:\n\n```typescript\nexport type OAuth2Token = {\n  accessToken: string;\n  refreshToken: string | null;\n\n  /**\n   * When the Access Token expires.\n   *\n   * This is expressed as a unix timestamp in milliseconds.\n   */\n  expiresAt: number | null;\n\n};\n```\n\n\n### client_credentials grant.\n\n```typescript\nconst token = await client.clientCredentials();\n```\n\n### Refreshing tokens\n\n```typescript\nconst newToken = await client.refresh(oldToken);\n```\n\n\n### password grant:\n\n```typescript\nconst token = await client.password({\n  username: '..',\n  password: '..',\n});\n```\n\n### authorization_code\n\nThe `authorization_code` flow is the flow for browser-based applications,\nand roughly consists of 3 major steps:\n\n1. Redirect the user to an authorization endpoint, where they log in.\n2. Authorization endpoint redirects back to app with a 'code' query\n   parameter.\n3. The `code` is exchanged for a access and refresh token.\n\nThis library provides support for all 3 steps, but there's no requirement\nto use its functionality as the system is mostly stateless.\n\n```typescript\nimport { OAuth2Client } from 'client';\n\nconst client = new OAuth2Client({\n  server: 'https://authserver.example/',\n  clientId: '...',\n\n  // Note, if urls cannot be auto-detected, also specify these:\n  tokenEndpoint: '/token',\n  authorizationEndpoint: '/authorize',\n});\n\nconst authorizationCode = client.authorizationCode({\n\n  // URL in the app that the user should get redirected to after authenticating\n  redirectUri: 'https://my-app.example/',\n\n  // Optional string that can be sent along to the auth server. This value will\n  // be sent along with the redirect back to the app verbatim.\n  state: 'some-string',\n});\n```\n\n**Redirecting the user to the authorization server**\n\n```typescript\n// In a browser this might work as follows:\ndocument.location = await authorizationCode.getAuthorizeUri();\n```\n\n**Handling the redirect back to the app and obtain token**\n\n```typescript\nconst codeResponse = await authorizationCode.validateResponse(\n  document.location\n);\n\nconst oauth2Token = await authorizationCode.getToken(codeResponse);\n```\n\n\n### Fetch Wrapper\n\nWhen using an OAuth2-protected API, typically you will need to obtain an Access\ntoken, and then add this token to each request using an `Authorization: Bearer`\nheader.\n\nBecause access tokens have a limited lifetime, and occasionally needs to be\nrefreshed this is a bunch of potential plumbing.\n\nTo make this easier, this library has a 'fetch wrapper'. This is effectively\njust like a regular fetch function, except it automatically adds the header\nand will automatically refresh tokens when needed.\n\nUsage:\n\n```typescript\nimport { OAuth2Client, OAuth2Fetch } from 'fetch-mw-oauth2';\n\nconst client = new OAuth2Client({\n  server: 'https://my-auth-server',\n  clientId: 'my-client-id'\n});\n\n\nconst fetchWrapper = new OAuth2Fetch({\n  client: client,\n\n  /**\n   * You are responsible for implementing this function.\n   * it's purpose is to supply the 'intitial' oauth2 token.\n   */\n  getNewToken: async () => {\n\n    // Example\n    return client.clientCredentials();     \n\n    // Another example\n    return client.authorizationCode({\n      code: '..',\n      redirectUri: '..',\n    });\n\n    // You can return null to fail the process. You may want to do this\n    // when a user needs to be redirected back to the authorization_code\n    // endpoints.\n    return null;\n\n  },\n\n  /**\n   * Optional. This will be called for any fatal authentication errors.\n   */\n  onError: (err) => {\n    // err is of type Error\n  }\n\n});\n```\n\nAfter set up, you can just call `fetch` on the new object ot call your API, and\nthe library will ensure there's always a `Bearer` header.\n\n```typescript\nconst response = fetchWrapper.fetch('https://my-api', {\n  method: 'POST',\n  body: 'Hello world'\n});\n```\n\n### Storing tokens for later use with FetchWrapper\n\nTo keep a user logged in between sessions, you may want to avoid full\nreauthentication. To do this, you'll need to store authentication token.\n\nThe fetch wrapper has 2 functions to help with this:\n\n```typescript\n\nconst fetchWrapper = new OAuth2Fetch({\n  client: client,\n\n  getNewToken: async () => {\n\n    // See above!\n\n  },\n\n  /**\n   * This function is called whenever the active token changes. Using this is\n   * optional, but it may be used to (for example) put the token in off-line\n   * storage for later usage.\n   */\n  storeToken: (token) => {\n    document.localStorage.setItem('token-store', JSON.stringify(token));\n  }\n\n  /**\n   * Also an optional feature. Implement this if you want the wrapper to try a\n   * stored token before attempting a full reauthentication.\n   *\n   * This function may be async. Return null if there was no token.\n   */\n  getStoredToken: () => {\n    const token = document.localStorage.getItem('token-store');\n    if (token) return JSON.parse(token);\n    return null;\n  }\n\n});\n```\n\n\n### fetchMw function\n\nIt might be preferable to use this library as a more traditional 'middleware'.\n\nThe OAuth2Fetch object also exposes a `fetchMw` function that takes 2 arguments:\n\n1. `request`\n2. `next`\n\nThe next argument is a function that also takes a request and returns a\nresponse.\n\nUsually you will want to use this with some kind of fetch middleware container,\nas such:\n\n```typescript\nmyFetchMiddleware(oauth2.fetchMw);\n```\n\nBut it's also possible to use it directly. For example:\n\n```typescript\noauth2.fetchMw(myRequest, innerRequest => fetch(innerRequest));\n```\n\n### Introspection\n\nIntrospection ([RFC7662][3]) lets you find more information about a token,\nsuch as whether it's valid, which user it belongs to, which oauth2 client\nwas used to generate it, etc.\n\nTo be able to use it, your authorization server must have support for the\nintrospection endpoint. It's location will be automatically detected using\nthe Metadata discovery document.\n\n```typescript\nimport { OAuth2Client } from 'fetch-mw-oauth2';\n\nconst client = new Client({\n  server: 'https://auth-server.example/',\n\n  clientId: '...',\n\n  /**\n   * Some servers require OAuth2 clientId/clientSecret to be passed.\n   * If they require it, specify it. If not it's fine to omit.\n   */\n  clientSecret: '...',\n\n});\n\n// Get a token\nconst token = client.clientCredentials();\n\n// Introspect!\nconsole.log(client.introspect(token));\n```\n\n[1]: https://datatracker.ietf.org/doc/html/rfc7636 \"Proof Key for Code Exchange by OAuth Public Clients\"\n[2]: https://datatracker.ietf.org/doc/html/rfc8414 \"OAuth 2.0 Authorization Server Metadata\"\n[3]: https://datatracker.ietf.org/doc/html/rfc7662 \"OAuth 2.0 Token Introspection\"\n","readmeFilename":"README.md","gitHead":"7f968776e47a3a8d94fd0f68c02bcb9453bd8d0a","_id":"fetch-mw-oauth2@2.0.3","_nodeVersion":"17.9.0","_npmVersion":"8.5.5","dist":{"integrity":"sha512-RYGmbgOCTXNCE2YYv8OvfvDefd8x+VKH/0p3WgceF4Iyx2D6QS2waA/qcwGpDEQADww/mDMINV9w2PBDPQft0Q==","shasum":"5320191819ebfb3eb541ec5e8e9aa87dd756087e","tarball":"https://registry.npmjs.org/fetch-mw-oauth2/-/fetch-mw-oauth2-2.0.3.tgz","fileCount":46,"unpackedSize":134081,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIF30bOZA4RWV1VFdMuaVqExZTencHcRdKBsslTdOl2YXAiEAiFwPK1zAdoGlYxRi17Jq1bqxzVcP3BwmEMcQGIe48Zk="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiX2TkACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmphyBAAjuqTvojs6D6lXV99+ZeCw8dKGq4bY7648BXzzYhElnnfts7S\r\nBhc9nqiccusg4hF+cTnmcrm4gt1OWreOt2W4H4pVwdapF4c5bDit4ElqgLiQ\r\naHEIeiafnmN4eo4w4AzOXEU2+H96v8B5udUdcLPqcqWv+LcAPLnEGuNInwfy\r\nGdPCizcIHKpNHDiRAOkwUSdg4qk2EneEuPJKYkHHiIvEPFyYZ11UNE5hsT1z\r\nsUw0p8UTk/jPx4ozyQ/aoDQn1Iv9pw5DAE7W+RcWT8gkAVxsK6Yi1F0f6aCm\r\nLO8DHVEsLQyCddd8SwpeDJCuNSmEFDV+82agm4QYbW/W7NpGRUoot4TM1sWI\r\nK0p1WOQTXV6bjRMQw+475Pc6KslXGpicyPIrb1tcueuFQ9aA57lQsEbhIbfi\r\ntSy12xVxGDZWrYPJ2qzOYdliwr/LnbTUlfoT0Dmn/lu3+FLEVdbI5U03Aafy\r\nVQPgFyidZBB/gyLucuBE3exEcW/iz0sbD0VgFT2eiAR+fV8A5hWfzh+wobCm\r\n/1Fy+Yvp4dojCJJYTMmrs079B1bGxeSIcyrwmBuoOhBoh5YTtT7sJC0/93Ez\r\ni7AE+d5GAGW+uK9Y/o5BWcpIycKSn5a0IFbzxrmzTp8LZpqnWEcpL0BYuS/G\r\nBd1oJCGf83UUuA13Zs4hffmQh+taKiMzxIw=\r\n=pKkk\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"evrt","email":"me@evertpot.com"},"directories":{},"maintainers":[{"name":"evrt","email":"me@evertpot.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fetch-mw-oauth2_2.0.3_1650418916303_0.8747029808927147"},"_hasShrinkwrap":false,"deprecated":"This package has been deprecated. v2 of this library has been renamed to @badgateway/oauth2-client"},"2.0.4":{"name":"fetch-mw-oauth2","version":"2.0.4","description":"Fetch middleware to add OAuth2 support","main":"dist/index.js","scripts":{"test":"make test lint","prepublishOnly":"make build"},"repository":{"type":"git","url":"git+ssh://git@github.com/badgateway/fetch-mw-oauth2.git"},"keywords":["fetch","oauth2"],"author":{"name":"Evert Pot","url":"https://evertpot.com"},"license":"MIT","bugs":{"url":"https://github.com/badgateway/fetch-mw-oauth2/issues"},"homepage":"https://github.com/badgateway/fetch-mw-oauth2#readme","devDependencies":{"@types/node":"^17.0.25","@typescript-eslint/eslint-plugin":"^5.2.0","@typescript-eslint/parser":"^5.2.0","eslint":"^8.1.0","node-fetch":"^3.0.0","ts-loader":"^9.2.6","typescript":"^4.4.4","webpack":"^5.60.0","webpack-cli":"^4.9.1"},"browser":"browser/fetch-mw-oauth2.min.js","types":"./dist/index.d.ts","readme":"# fetch-mw-oauth2\n\nThis package contains an OAuth2 client. It aims to be a fully-featured OAuth2\nutility library, for Node.js, Browsers and written in Typescript.\n\nThis library supports the following features:\n\n* `authorization_code` grant with optional [PKCE][1] support.\n* `password` and `client_credentials` grant.\n* a `fetch()` wrapper that automatically adds Bearer tokens and refreshes them.\n* OAuth2 endpoint discovery via the Server metadata document ([RFC8414][2]).\n* OAuth2 Token Introspection ([RFC7662][3]).\n\n\n## Installation\n\n```sh\nnpm i fetch-mw-oauth2\n```\n\n## Usage\n\nTo get started, set up the Client class.\n\n\n```typescript\nimport { OAuth2Client } from 'fetch-mw-oauth2';\n\nconst client = new Client({\n\n  // The base URI of your OAuth2 server\n  server: 'https://my-auth-server/',\n\n  // OAuth2 client id\n  clientId: '...',\n\n  // OAuth2 client secret. Only required for 'client_credentials', 'password'\n  // flows. You should not specify this for authorization_code.\n  clientSecret: '...',\n\n\n  // The following URIs are all optional. If they are not specified, we will\n  // attempt to discover them using the oauth2 discovery document.\n  // If your server doesn't have support this, you may need to specify these.\n  // you may use relative URIs for any of these.\n\n\n  // Token endpoint. Most flows need this.\n  // If not specified we'll use the information for the discovery document\n  // first, and otherwise default to /token\n  tokenEndpoint: '/token',\n\n  // Authorization endpoint.\n  //\n  // You only need this to generate URLs for authorization_code flows.\n  // If not specified we'll use the information for the discovery document\n  // first, and otherwise default to /authorize\n  authorizationEndpoint: '/authorize',\n\n  // OAuth2 Metadata discovery endpoint.\n  //\n  // This document is used to determine various server features.\n  // If not specified, we assume it's on /.well-known/oauth2-authorization-server\n  discoveryEndpoint: '/.well-known/oauth2-authorization-server',\n\n});\n```\n\n### Tokens\n\nMany functions use or return a 'OAuth2Token' type. This type has the following\nshape:\n\n```typescript\nexport type OAuth2Token = {\n  accessToken: string;\n  refreshToken: string | null;\n\n  /**\n   * When the Access Token expires.\n   *\n   * This is expressed as a unix timestamp in milliseconds.\n   */\n  expiresAt: number | null;\n\n};\n```\n\n\n### client_credentials grant.\n\n```typescript\nconst token = await client.clientCredentials();\n```\n\n### Refreshing tokens\n\n```typescript\nconst newToken = await client.refresh(oldToken);\n```\n\n\n### password grant:\n\n```typescript\nconst token = await client.password({\n  username: '..',\n  password: '..',\n});\n```\n\n### authorization_code\n\nThe `authorization_code` flow is the flow for browser-based applications,\nand roughly consists of 3 major steps:\n\n1. Redirect the user to an authorization endpoint, where they log in.\n2. Authorization endpoint redirects back to app with a 'code' query\n   parameter.\n3. The `code` is exchanged for a access and refresh token.\n\nThis library provides support for all 3 steps, but there's no requirement\nto use its functionality as the system is mostly stateless.\n\n```typescript\nimport { OAuth2Client } from 'client';\n\nconst client = new OAuth2Client({\n  server: 'https://authserver.example/',\n  clientId: '...',\n\n  // Note, if urls cannot be auto-detected, also specify these:\n  tokenEndpoint: '/token',\n  authorizationEndpoint: '/authorize',\n});\n\nconst authorizationCode = client.authorizationCode({\n\n  // URL in the app that the user should get redirected to after authenticating\n  redirectUri: 'https://my-app.example/',\n\n  // Optional string that can be sent along to the auth server. This value will\n  // be sent along with the redirect back to the app verbatim.\n  state: 'some-string',\n});\n```\n\n**Redirecting the user to the authorization server**\n\n```typescript\n// In a browser this might work as follows:\ndocument.location = await authorizationCode.getAuthorizeUri();\n```\n\n**Handling the redirect back to the app and obtain token**\n\n```typescript\nconst codeResponse = await authorizationCode.validateResponse(\n  document.location\n);\n\nconst oauth2Token = await authorizationCode.getToken(codeResponse);\n```\n\n\n### Fetch Wrapper\n\nWhen using an OAuth2-protected API, typically you will need to obtain an Access\ntoken, and then add this token to each request using an `Authorization: Bearer`\nheader.\n\nBecause access tokens have a limited lifetime, and occasionally needs to be\nrefreshed this is a bunch of potential plumbing.\n\nTo make this easier, this library has a 'fetch wrapper'. This is effectively\njust like a regular fetch function, except it automatically adds the header\nand will automatically refresh tokens when needed.\n\nUsage:\n\n```typescript\nimport { OAuth2Client, OAuth2Fetch } from 'fetch-mw-oauth2';\n\nconst client = new OAuth2Client({\n  server: 'https://my-auth-server',\n  clientId: 'my-client-id'\n});\n\n\nconst fetchWrapper = new OAuth2Fetch({\n  client: client,\n\n  /**\n   * You are responsible for implementing this function.\n   * it's purpose is to supply the 'intitial' oauth2 token.\n   */\n  getNewToken: async () => {\n\n    // Example\n    return client.clientCredentials();     \n\n    // Another example\n    return client.authorizationCode({\n      code: '..',\n      redirectUri: '..',\n    });\n\n    // You can return null to fail the process. You may want to do this\n    // when a user needs to be redirected back to the authorization_code\n    // endpoints.\n    return null;\n\n  },\n\n  /**\n   * Optional. This will be called for any fatal authentication errors.\n   */\n  onError: (err) => {\n    // err is of type Error\n  }\n\n});\n```\n\nAfter set up, you can just call `fetch` on the new object ot call your API, and\nthe library will ensure there's always a `Bearer` header.\n\n```typescript\nconst response = fetchWrapper.fetch('https://my-api', {\n  method: 'POST',\n  body: 'Hello world'\n});\n```\n\n### Storing tokens for later use with FetchWrapper\n\nTo keep a user logged in between sessions, you may want to avoid full\nreauthentication. To do this, you'll need to store authentication token.\n\nThe fetch wrapper has 2 functions to help with this:\n\n```typescript\n\nconst fetchWrapper = new OAuth2Fetch({\n  client: client,\n\n  getNewToken: async () => {\n\n    // See above!\n\n  },\n\n  /**\n   * This function is called whenever the active token changes. Using this is\n   * optional, but it may be used to (for example) put the token in off-line\n   * storage for later usage.\n   */\n  storeToken: (token) => {\n    document.localStorage.setItem('token-store', JSON.stringify(token));\n  }\n\n  /**\n   * Also an optional feature. Implement this if you want the wrapper to try a\n   * stored token before attempting a full reauthentication.\n   *\n   * This function may be async. Return null if there was no token.\n   */\n  getStoredToken: () => {\n    const token = document.localStorage.getItem('token-store');\n    if (token) return JSON.parse(token);\n    return null;\n  }\n\n});\n```\n\n\n### Fetch Middleware function\n\nIt might be preferable to use this library as a more traditional 'middleware'.\n\nThe OAuth2Fetch object also exposes a `mw` function that returns a middleware\nfor fetch.\n\n```typescript\nconst mw = oauth2.mw();\nconst response = mw(\n  myRequest,\n  req => fetch(req)\n);\n```\n\nThis syntax looks a bit wild if you're not used to building middlewares, but\nthis effectively allows you to 'decorate' existing request libraries with\nfunctionality from this oauth2 library.\n\nA real example using the [Ketting](https://github.com/badgateway/ketting)\nlibrary:\n\n```typescript\nimport { Client } from 'ketting';\nimport { OAuth2Client, OAuth2Fetch } from 'fetch-mw-oauth2';\n\n/**\n * Create the oauth2 client\n */\nconst oauth2Client = new OAuth2Client({\n  server: 'https://my-auth.example',\n  clientId: 'foo',\n});\n\n/**\n * Create the 'fetch helper'\n */\nconst oauth2Fetch = new OAuth2Fetch({\n  client: oauth2Client,\n});\n\n/**\n * Add the middleware to Ketting\n */\nconst ketting = new Client('http://api-root');\nketting.use(oauth2Fetch.mw());\n```\n\n### Introspection\n\nIntrospection ([RFC7662][3]) lets you find more information about a token,\nsuch as whether it's valid, which user it belongs to, which oauth2 client\nwas used to generate it, etc.\n\nTo be able to use it, your authorization server must have support for the\nintrospection endpoint. It's location will be automatically detected using\nthe Metadata discovery document.\n\n```typescript\nimport { OAuth2Client } from 'fetch-mw-oauth2';\n\nconst client = new Client({\n  server: 'https://auth-server.example/',\n\n  clientId: '...',\n\n  /**\n   * Some servers require OAuth2 clientId/clientSecret to be passed.\n   * If they require it, specify it. If not it's fine to omit.\n   */\n  clientSecret: '...',\n\n});\n\n// Get a token\nconst token = client.clientCredentials();\n\n// Introspect!\nconsole.log(client.introspect(token));\n```\n\n[1]: https://datatracker.ietf.org/doc/html/rfc7636 \"Proof Key for Code Exchange by OAuth Public Clients\"\n[2]: https://datatracker.ietf.org/doc/html/rfc8414 \"OAuth 2.0 Authorization Server Metadata\"\n[3]: https://datatracker.ietf.org/doc/html/rfc7662 \"OAuth 2.0 Token Introspection\"\n","readmeFilename":"README.md","gitHead":"9284db18031bfb1783c1e47a06403669ad3bcd35","_id":"fetch-mw-oauth2@2.0.4","_nodeVersion":"17.9.0","_npmVersion":"8.5.5","dist":{"integrity":"sha512-8n/cLAThNOEzUpbSuM0rsQ9aGB8BegGbDhtT0DMa7qv3OvAN2FOQ4CkoyQwNFj6pRobC+xC/HoTh0/+p4BeQDQ==","shasum":"0470335a9e5408dcf412e95eba89136ec0919d73","tarball":"https://registry.npmjs.org/fetch-mw-oauth2/-/fetch-mw-oauth2-2.0.4.tgz","fileCount":46,"unpackedSize":134856,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCymG87A477Md5EY/DcPv6hV4YvWAxpItoqI7tVwyPzmwIhAP5SrINV6XvIS0cDWChCu4LtN1ocW2ADC+yxYR6+KWB+"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiX25UACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqVIQ/+JfKd4gBLmI6FCpSXJLUqY0WDB6LGcz1llqNVCKdvcOOPjaf8\r\n6DVphJqf0xRWRgrCEwWc18lohxEvgYCBDqtvfieJbTUMcOCoDMg0UlKbXVir\r\nlG+bDXFGVZ87QQ6vDSTfsoslGN/OR85TnKKTLMVQHDVp2tDGfSF+GRbVmw1B\r\nBexh0iRTNhGDVIe36QVGqYItjDoxjDCqFJF6bhjY3fiuXRFATCgHDD9rqwqx\r\nTx/76tkavlJk6+ickYTWalKH/WGjauO26CWhO9ZwLabtJtMQfL9kcCuqwZoN\r\nzNzgBckt8s5PPtTZ2U8+/bxvUg4wn1yqCVabNuTGbLaWywhbPhru0Cd51yN4\r\nchRMEiQzGCaI9pjWV1c1lA77d86gMFmnJlLA/2BX78JJ1h5wOaHP6cLOwpTx\r\nEpYY5E2tDWlE+rw5e0HtWMsH74vJTEkZiCmBLldh+qQMS768yHnknB6y9tL0\r\nHEyRRm34YRp9acy9zlWEXR8QUjcxLj1eVGW6qj7vR1S5/NMp7+oqrPg0qA97\r\nxbNtiRnFlHEG1tgcIDwpsC8AN8RDf0RgDIzQlwn7lOCB1CrqT98JvceL+H95\r\nsD4Sq5FJEHlh8toLPJwzXrEFLa6C5XyZ3c+6uTAtCqXrqUuEHWya34oFTUI7\r\nZ0SuCFbKsVrCe6S0RMajo+Z0RCM82eUQ7Zc=\r\n=Sncj\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"evrt","email":"me@evertpot.com"},"directories":{},"maintainers":[{"name":"evrt","email":"me@evertpot.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fetch-mw-oauth2_2.0.4_1650421332014_0.4399130962558393"},"_hasShrinkwrap":false,"deprecated":"This package has been deprecated. v2 of this library has been renamed to @badgateway/oauth2-client"},"2.0.5":{"name":"fetch-mw-oauth2","version":"2.0.5","description":"Fetch middleware to add OAuth2 support","main":"dist/index.js","scripts":{"test":"make test lint","prepublishOnly":"make build"},"repository":{"type":"git","url":"git+ssh://git@github.com/badgateway/fetch-mw-oauth2.git"},"keywords":["fetch","oauth2"],"author":{"name":"Evert Pot","url":"https://evertpot.com"},"license":"MIT","bugs":{"url":"https://github.com/badgateway/fetch-mw-oauth2/issues"},"homepage":"https://github.com/badgateway/fetch-mw-oauth2#readme","devDependencies":{"@types/node":"^17.0.25","@typescript-eslint/eslint-plugin":"^5.2.0","@typescript-eslint/parser":"^5.2.0","eslint":"^8.1.0","node-fetch":"^3.0.0","ts-loader":"^9.2.6","typescript":"^4.4.4","webpack":"^5.60.0","webpack-cli":"^4.9.1"},"browser":"browser/fetch-mw-oauth2.min.js","types":"./dist/index.d.ts","readme":"# fetch-mw-oauth2\n\nThis package contains an OAuth2 client. It aims to be a fully-featured OAuth2\nutility library, for Node.js, Browsers and written in Typescript.\n\nThis library supports the following features:\n\n* `authorization_code` grant with optional [PKCE][1] support.\n* `password` and `client_credentials` grant.\n* a `fetch()` wrapper that automatically adds Bearer tokens and refreshes them.\n* OAuth2 endpoint discovery via the Server metadata document ([RFC8414][2]).\n* OAuth2 Token Introspection ([RFC7662][3]).\n\n\n## Installation\n\n```sh\nnpm i fetch-mw-oauth2\n```\n\n## Usage\n\nTo get started, set up the Client class.\n\n\n```typescript\nimport { OAuth2Client } from 'fetch-mw-oauth2';\n\nconst client = new Client({\n\n  // The base URI of your OAuth2 server\n  server: 'https://my-auth-server/',\n\n  // OAuth2 client id\n  clientId: '...',\n\n  // OAuth2 client secret. Only required for 'client_credentials', 'password'\n  // flows. You should not specify this for authorization_code.\n  clientSecret: '...',\n\n\n  // The following URIs are all optional. If they are not specified, we will\n  // attempt to discover them using the oauth2 discovery document.\n  // If your server doesn't have support this, you may need to specify these.\n  // you may use relative URIs for any of these.\n\n\n  // Token endpoint. Most flows need this.\n  // If not specified we'll use the information for the discovery document\n  // first, and otherwise default to /token\n  tokenEndpoint: '/token',\n\n  // Authorization endpoint.\n  //\n  // You only need this to generate URLs for authorization_code flows.\n  // If not specified we'll use the information for the discovery document\n  // first, and otherwise default to /authorize\n  authorizationEndpoint: '/authorize',\n\n  // OAuth2 Metadata discovery endpoint.\n  //\n  // This document is used to determine various server features.\n  // If not specified, we assume it's on /.well-known/oauth2-authorization-server\n  discoveryEndpoint: '/.well-known/oauth2-authorization-server',\n\n});\n```\n\n### Tokens\n\nMany functions use or return a 'OAuth2Token' type. This type has the following\nshape:\n\n```typescript\nexport type OAuth2Token = {\n  accessToken: string;\n  refreshToken: string | null;\n\n  /**\n   * When the Access Token expires.\n   *\n   * This is expressed as a unix timestamp in milliseconds.\n   */\n  expiresAt: number | null;\n\n};\n```\n\n\n### client_credentials grant.\n\n```typescript\nconst token = await client.clientCredentials();\n```\n\n### Refreshing tokens\n\n```typescript\nconst newToken = await client.refresh(oldToken);\n```\n\n\n### password grant:\n\n```typescript\nconst token = await client.password({\n  username: '..',\n  password: '..',\n});\n```\n\n### authorization_code\n\nThe `authorization_code` flow is the flow for browser-based applications,\nand roughly consists of 3 major steps:\n\n1. Redirect the user to an authorization endpoint, where they log in.\n2. Authorization endpoint redirects back to app with a 'code' query\n   parameter.\n3. The `code` is exchanged for a access and refresh token.\n\nThis library provides support for all 3 steps, but there's no requirement\nto use its functionality as the system is mostly stateless.\n\n```typescript\nimport { OAuth2Client } from 'client';\n\nconst client = new OAuth2Client({\n  server: 'https://authserver.example/',\n  clientId: '...',\n\n  // Note, if urls cannot be auto-detected, also specify these:\n  tokenEndpoint: '/token',\n  authorizationEndpoint: '/authorize',\n});\n\nconst authorizationCode = client.authorizationCode({\n\n  // URL in the app that the user should get redirected to after authenticating\n  redirectUri: 'https://my-app.example/',\n\n  // Optional string that can be sent along to the auth server. This value will\n  // be sent along with the redirect back to the app verbatim.\n  state: 'some-string',\n});\n```\n\n**Redirecting the user to the authorization server**\n\n```typescript\n// In a browser this might work as follows:\ndocument.location = await authorizationCode.getAuthorizeUri();\n```\n\n**Handling the redirect back to the app and obtain token**\n\n```typescript\nconst codeResponse = await authorizationCode.validateResponse(\n  document.location\n);\n\nconst oauth2Token = await authorizationCode.getToken(codeResponse);\n```\n\n### PKCE support\n\nModern OAuth2 server should support PKCE, which improves security.\nThis library supports PKCE. Luckily you don't need to know in advance whether\nyour authorization server supports it. If they do, you get the additional\nbenefit. If not, nothing should break.\n\nTo use PKCE, you need to make one extra step when calling `authorizationCode`:\n\n```typescript\nimport { OAuth2Client, getCodeVerifier } from 'client';\n\nconst client = new OAuth2Client({\n  server: 'https://authserver.example/',\n  clientId: '...',\n\n  // Note, if urls cannot be auto-detected, also specify these:\n  tokenEndpoint: '/token',\n  authorizationEndpoint: '/authorize',\n});\n\n/**\n * IMPORTANT! This returns a random value every time it's called\n *\n * Because the authorization_code is a multi-step process that likely results\n * in the user leaving your website and coming back later, you must store the\n * result of this somewhere.\n *\n * The codeVerifier gets used in the first step 'getAuthorizeUrl()` and the\n * last step 'getToken()`.\n */\nconst codeVerifier = getCodeVerifier();\nconst authorizationCode = client.authorizationCode({\n\n  // URL in the app that the user should get redirected to after authenticating\n  redirectUri: 'https://my-app.example/',\n\n  // Optional string that can be sent along to the auth server. This value will\n  // be sent along with the redirect back to the app verbatim.\n  state: 'some-string',\n\n  // Pass the code verifier\n  codeVerifier,\n});\n```\n\n### Fetch Wrapper\n\nWhen using an OAuth2-protected API, typically you will need to obtain an Access\ntoken, and then add this token to each request using an `Authorization: Bearer`\nheader.\n\nBecause access tokens have a limited lifetime, and occasionally needs to be\nrefreshed this is a bunch of potential plumbing.\n\nTo make this easier, this library has a 'fetch wrapper'. This is effectively\njust like a regular fetch function, except it automatically adds the header\nand will automatically refresh tokens when needed.\n\nUsage:\n\n```typescript\nimport { OAuth2Client, OAuth2Fetch } from 'fetch-mw-oauth2';\n\nconst client = new OAuth2Client({\n  server: 'https://my-auth-server',\n  clientId: 'my-client-id'\n});\n\n\nconst fetchWrapper = new OAuth2Fetch({\n  client: client,\n\n  /**\n   * You are responsible for implementing this function.\n   * it's purpose is to supply the 'intitial' oauth2 token.\n   */\n  getNewToken: async () => {\n\n    // Example\n    return client.clientCredentials();     \n\n    // Another example\n    return client.authorizationCode({\n      code: '..',\n      redirectUri: '..',\n    });\n\n    // You can return null to fail the process. You may want to do this\n    // when a user needs to be redirected back to the authorization_code\n    // endpoints.\n    return null;\n\n  },\n\n  /**\n   * Optional. This will be called for any fatal authentication errors.\n   */\n  onError: (err) => {\n    // err is of type Error\n  }\n\n});\n```\n\nAfter set up, you can just call `fetch` on the new object ot call your API, and\nthe library will ensure there's always a `Bearer` header.\n\n```typescript\nconst response = fetchWrapper.fetch('https://my-api', {\n  method: 'POST',\n  body: 'Hello world'\n});\n```\n\n### Storing tokens for later use with FetchWrapper\n\nTo keep a user logged in between sessions, you may want to avoid full\nreauthentication. To do this, you'll need to store authentication token.\n\nThe fetch wrapper has 2 functions to help with this:\n\n```typescript\n\nconst fetchWrapper = new OAuth2Fetch({\n  client: client,\n\n  getNewToken: async () => {\n\n    // See above!\n\n  },\n\n  /**\n   * This function is called whenever the active token changes. Using this is\n   * optional, but it may be used to (for example) put the token in off-line\n   * storage for later usage.\n   */\n  storeToken: (token) => {\n    document.localStorage.setItem('token-store', JSON.stringify(token));\n  }\n\n  /**\n   * Also an optional feature. Implement this if you want the wrapper to try a\n   * stored token before attempting a full reauthentication.\n   *\n   * This function may be async. Return null if there was no token.\n   */\n  getStoredToken: () => {\n    const token = document.localStorage.getItem('token-store');\n    if (token) return JSON.parse(token);\n    return null;\n  }\n\n});\n```\n\n\n### Fetch Middleware function\n\nIt might be preferable to use this library as a more traditional 'middleware'.\n\nThe OAuth2Fetch object also exposes a `mw` function that returns a middleware\nfor fetch.\n\n```typescript\nconst mw = oauth2.mw();\nconst response = mw(\n  myRequest,\n  req => fetch(req)\n);\n```\n\nThis syntax looks a bit wild if you're not used to building middlewares, but\nthis effectively allows you to 'decorate' existing request libraries with\nfunctionality from this oauth2 library.\n\nA real example using the [Ketting](https://github.com/badgateway/ketting)\nlibrary:\n\n```typescript\nimport { Client } from 'ketting';\nimport { OAuth2Client, OAuth2Fetch } from 'fetch-mw-oauth2';\n\n/**\n * Create the oauth2 client\n */\nconst oauth2Client = new OAuth2Client({\n  server: 'https://my-auth.example',\n  clientId: 'foo',\n});\n\n/**\n * Create the 'fetch helper'\n */\nconst oauth2Fetch = new OAuth2Fetch({\n  client: oauth2Client,\n});\n\n/**\n * Add the middleware to Ketting\n */\nconst ketting = new Client('http://api-root');\nketting.use(oauth2Fetch.mw());\n```\n\n### Introspection\n\nIntrospection ([RFC7662][3]) lets you find more information about a token,\nsuch as whether it's valid, which user it belongs to, which oauth2 client\nwas used to generate it, etc.\n\nTo be able to use it, your authorization server must have support for the\nintrospection endpoint. It's location will be automatically detected using\nthe Metadata discovery document.\n\n```typescript\nimport { OAuth2Client } from 'fetch-mw-oauth2';\n\nconst client = new Client({\n  server: 'https://auth-server.example/',\n\n  clientId: '...',\n\n  /**\n   * Some servers require OAuth2 clientId/clientSecret to be passed.\n   * If they require it, specify it. If not it's fine to omit.\n   */\n  clientSecret: '...',\n\n});\n\n// Get a token\nconst token = client.clientCredentials();\n\n// Introspect!\nconsole.log(client.introspect(token));\n```\n\n[1]: https://datatracker.ietf.org/doc/html/rfc7636 \"Proof Key for Code Exchange by OAuth Public Clients\"\n[2]: https://datatracker.ietf.org/doc/html/rfc8414 \"OAuth 2.0 Authorization Server Metadata\"\n[3]: https://datatracker.ietf.org/doc/html/rfc7662 \"OAuth 2.0 Token Introspection\"\n","readmeFilename":"README.md","gitHead":"61596e5382e06832ddab9b7d82c0aa564faa0532","_id":"fetch-mw-oauth2@2.0.5","_nodeVersion":"18.0.0","_npmVersion":"8.6.0","dist":{"integrity":"sha512-BI6ZM7O0F5Yrl8raDNMSZSrwiZPkbfDbX5hMK7uXa+TrBioK77Rxd5nvNO4Hui+zbApED52Vdh/ub9SBMErsIg==","shasum":"fe58a9c74f82fd404ec45708da76fa92e696d0ff","tarball":"https://registry.npmjs.org/fetch-mw-oauth2/-/fetch-mw-oauth2-2.0.5.tgz","fileCount":46,"unpackedSize":144504,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIGa8svmQLbuLta30nSJPQGJ3kJC/MUftnm5CG0TFoIkyAiBgY/AcUekKPA1LFD6TPwIv+Dxw8rJm26E3xacGkcbmMg=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiZj2iACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqDoRAAgG2Wfo9WJog+euKXwLa1acYjKF7MdL5eTqO8brkr0Q31DEMG\r\n+V4tmYEKrFTpA27XWgsdO46KepiKauSepK3mDmQuhwafGAYtxv8Q3vWeZCqG\r\nXBza3umq0EDVL5YkIio2gfNJUXbsNd73GqawjFmu2WHMPEQg2NjJePsH9Q4E\r\nJRqmYzyJbBciNFgjQMeYs0lAMnw+T71c3mPSnhcc9hCGfswiHktYpK4lwSNE\r\nSwubpOU4BZOFyADSg8WLU8DmzPzBhvApofQfkMO6B8xwUQw14Nj4oHcmynkc\r\nPnbHa4P70l3vXShwFipzvXHvFwqH1KE4M3QEUD5NaawVxbKyt0XwibP0OCMo\r\n/bh0HQvHmHFLqhAC3mmGAFCf5q0EdY+H1i6Y3iT4VkjrT8kOsdwohhvOs2s/\r\n3Q4IdYvBQYN2PpxYPblSu0w07reOF2+w1XVSvD3I+X/sWT2AykDwA7C35lTU\r\n8c1fCy6UF/BzmQ9dRY1otLjSrebETB5NI6Q7cOoA9CDCM0EaE1onK1uN55kY\r\n/k5rE53poQLD4dWgoHaOzFqUZZ7oJDZi0sN1Q750o5/JsPFiWOg7o/JzwCoG\r\n/IKBsPamVDHXRpWRuHCRZsNQLpf4FVr2bXeEt4bQODCOqhOan2jujLRvQktR\r\nLEF1G2EC1nIoUzR3dPx3PsN657cYXIo+WN4=\r\n=eymP\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"evrt","email":"me@evertpot.com"},"directories":{},"maintainers":[{"name":"evrt","email":"me@evertpot.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fetch-mw-oauth2_2.0.5_1650867617998_0.34405229104218904"},"_hasShrinkwrap":false,"deprecated":"This package has been deprecated. v2 of this library has been renamed to @badgateway/oauth2-client"},"2.0.6":{"name":"fetch-mw-oauth2","version":"2.0.6","description":"Fetch middleware to add OAuth2 support","main":"dist/index.js","scripts":{"test":"make test lint","prepublishOnly":"make build"},"repository":{"type":"git","url":"git+ssh://git@github.com/badgateway/fetch-mw-oauth2.git"},"keywords":["fetch","oauth2"],"author":{"name":"Evert Pot","url":"https://evertpot.com"},"license":"MIT","bugs":{"url":"https://github.com/badgateway/fetch-mw-oauth2/issues"},"homepage":"https://github.com/badgateway/fetch-mw-oauth2#readme","devDependencies":{"@types/node":"^17.0.25","@typescript-eslint/eslint-plugin":"^5.2.0","@typescript-eslint/parser":"^5.2.0","eslint":"^8.1.0","node-fetch":"^3.0.0","ts-loader":"^9.2.6","typescript":"^4.4.4","webpack":"^5.60.0","webpack-cli":"^4.9.1"},"browser":"browser/fetch-mw-oauth2.min.js","types":"./dist/index.d.ts","readme":"# fetch-mw-oauth2\n\nThis package contains an OAuth2 client. It aims to be a fully-featured OAuth2\nutility library, for Node.js, Browsers and written in Typescript.\n\nThis library supports the following features:\n\n* `authorization_code` grant with optional [PKCE][1] support.\n* `password` and `client_credentials` grant.\n* a `fetch()` wrapper that automatically adds Bearer tokens and refreshes them.\n* OAuth2 endpoint discovery via the Server metadata document ([RFC8414][2]).\n* OAuth2 Token Introspection ([RFC7662][3]).\n\n\n## Installation\n\n```sh\nnpm i fetch-mw-oauth2\n```\n\n## Usage\n\nTo get started, set up the Client class.\n\n\n```typescript\nimport { OAuth2Client } from 'fetch-mw-oauth2';\n\nconst client = new Client({\n\n  // The base URI of your OAuth2 server\n  server: 'https://my-auth-server/',\n\n  // OAuth2 client id\n  clientId: '...',\n\n  // OAuth2 client secret. Only required for 'client_credentials', 'password'\n  // flows. You should not specify this for authorization_code.\n  clientSecret: '...',\n\n\n  // The following URIs are all optional. If they are not specified, we will\n  // attempt to discover them using the oauth2 discovery document.\n  // If your server doesn't have support this, you may need to specify these.\n  // you may use relative URIs for any of these.\n\n\n  // Token endpoint. Most flows need this.\n  // If not specified we'll use the information for the discovery document\n  // first, and otherwise default to /token\n  tokenEndpoint: '/token',\n\n  // Authorization endpoint.\n  //\n  // You only need this to generate URLs for authorization_code flows.\n  // If not specified we'll use the information for the discovery document\n  // first, and otherwise default to /authorize\n  authorizationEndpoint: '/authorize',\n\n  // OAuth2 Metadata discovery endpoint.\n  //\n  // This document is used to determine various server features.\n  // If not specified, we assume it's on /.well-known/oauth2-authorization-server\n  discoveryEndpoint: '/.well-known/oauth2-authorization-server',\n\n});\n```\n\n### Tokens\n\nMany functions use or return a 'OAuth2Token' type. This type has the following\nshape:\n\n```typescript\nexport type OAuth2Token = {\n  accessToken: string;\n  refreshToken: string | null;\n\n  /**\n   * When the Access Token expires.\n   *\n   * This is expressed as a unix timestamp in milliseconds.\n   */\n  expiresAt: number | null;\n\n};\n```\n\n\n### client_credentials grant.\n\n```typescript\nconst token = await client.clientCredentials();\n```\n\n### Refreshing tokens\n\n```typescript\nconst newToken = await client.refresh(oldToken);\n```\n\n\n### password grant:\n\n```typescript\nconst token = await client.password({\n  username: '..',\n  password: '..',\n});\n```\n\n### authorization_code\n\nThe `authorization_code` flow is the flow for browser-based applications,\nand roughly consists of 3 major steps:\n\n1. Redirect the user to an authorization endpoint, where they log in.\n2. Authorization endpoint redirects back to app with a 'code' query\n   parameter.\n3. The `code` is exchanged for a access and refresh token.\n\nThis library provides support for all 3 steps, but there's no requirement\nto use its functionality as the system is mostly stateless.\n\n```typescript\nimport { OAuth2Client } from 'client';\n\nconst client = new OAuth2Client({\n  server: 'https://authserver.example/',\n  clientId: '...',\n\n  // Note, if urls cannot be auto-detected, also specify these:\n  tokenEndpoint: '/token',\n  authorizationEndpoint: '/authorize',\n});\n\nconst authorizationCode = client.authorizationCode({\n\n  // URL in the app that the user should get redirected to after authenticating\n  redirectUri: 'https://my-app.example/',\n\n  // Optional string that can be sent along to the auth server. This value will\n  // be sent along with the redirect back to the app verbatim.\n  state: 'some-string',\n});\n```\n\n**Redirecting the user to the authorization server**\n\n```typescript\n// In a browser this might work as follows:\ndocument.location = await authorizationCode.getAuthorizeUri();\n```\n\n**Handling the redirect back to the app and obtain token**\n\n```typescript\nconst codeResponse = await authorizationCode.validateResponse(\n  document.location\n);\n\nconst oauth2Token = await authorizationCode.getToken(codeResponse);\n```\n\n### PKCE support\n\nModern OAuth2 server should support PKCE, which improves security.\nThis library supports PKCE. Luckily you don't need to know in advance whether\nyour authorization server supports it. If they do, you get the additional\nbenefit. If not, nothing should break.\n\nTo use PKCE, you need to make one extra step when calling `authorizationCode`:\n\n```typescript\nimport { OAuth2Client, getCodeVerifier } from 'client';\n\nconst client = new OAuth2Client({\n  server: 'https://authserver.example/',\n  clientId: '...',\n\n  // Note, if urls cannot be auto-detected, also specify these:\n  tokenEndpoint: '/token',\n  authorizationEndpoint: '/authorize',\n});\n\n/**\n * IMPORTANT! This returns a random value every time it's called\n *\n * Because the authorization_code is a multi-step process that likely results\n * in the user leaving your website and coming back later, you must store the\n * result of this somewhere.\n *\n * The codeVerifier gets used in the first step 'getAuthorizeUrl()` and the\n * last step 'getToken()`.\n */\nconst codeVerifier = getCodeVerifier();\nconst authorizationCode = client.authorizationCode({\n\n  // URL in the app that the user should get redirected to after authenticating\n  redirectUri: 'https://my-app.example/',\n\n  // Optional string that can be sent along to the auth server. This value will\n  // be sent along with the redirect back to the app verbatim.\n  state: 'some-string',\n\n  // Pass the code verifier\n  codeVerifier,\n});\n```\n\n### Fetch Wrapper\n\nWhen using an OAuth2-protected API, typically you will need to obtain an Access\ntoken, and then add this token to each request using an `Authorization: Bearer`\nheader.\n\nBecause access tokens have a limited lifetime, and occasionally needs to be\nrefreshed this is a bunch of potential plumbing.\n\nTo make this easier, this library has a 'fetch wrapper'. This is effectively\njust like a regular fetch function, except it automatically adds the header\nand will automatically refresh tokens when needed.\n\nUsage:\n\n```typescript\nimport { OAuth2Client, OAuth2Fetch } from 'fetch-mw-oauth2';\n\nconst client = new OAuth2Client({\n  server: 'https://my-auth-server',\n  clientId: 'my-client-id'\n});\n\n\nconst fetchWrapper = new OAuth2Fetch({\n  client: client,\n\n  /**\n   * You are responsible for implementing this function.\n   * it's purpose is to supply the 'intitial' oauth2 token.\n   */\n  getNewToken: async () => {\n\n    // Example\n    return client.clientCredentials();     \n\n    // Another example\n    return client.authorizationCode({\n      code: '..',\n      redirectUri: '..',\n    });\n\n    // You can return null to fail the process. You may want to do this\n    // when a user needs to be redirected back to the authorization_code\n    // endpoints.\n    return null;\n\n  },\n\n  /**\n   * Optional. This will be called for any fatal authentication errors.\n   */\n  onError: (err) => {\n    // err is of type Error\n  }\n\n});\n```\n\nAfter set up, you can just call `fetch` on the new object ot call your API, and\nthe library will ensure there's always a `Bearer` header.\n\n```typescript\nconst response = fetchWrapper.fetch('https://my-api', {\n  method: 'POST',\n  body: 'Hello world'\n});\n```\n\n### Storing tokens for later use with FetchWrapper\n\nTo keep a user logged in between sessions, you may want to avoid full\nreauthentication. To do this, you'll need to store authentication token.\n\nThe fetch wrapper has 2 functions to help with this:\n\n```typescript\n\nconst fetchWrapper = new OAuth2Fetch({\n  client: client,\n\n  getNewToken: async () => {\n\n    // See above!\n\n  },\n\n  /**\n   * This function is called whenever the active token changes. Using this is\n   * optional, but it may be used to (for example) put the token in off-line\n   * storage for later usage.\n   */\n  storeToken: (token) => {\n    document.localStorage.setItem('token-store', JSON.stringify(token));\n  }\n\n  /**\n   * Also an optional feature. Implement this if you want the wrapper to try a\n   * stored token before attempting a full reauthentication.\n   *\n   * This function may be async. Return null if there was no token.\n   */\n  getStoredToken: () => {\n    const token = document.localStorage.getItem('token-store');\n    if (token) return JSON.parse(token);\n    return null;\n  }\n\n});\n```\n\n\n### Fetch Middleware function\n\nIt might be preferable to use this library as a more traditional 'middleware'.\n\nThe OAuth2Fetch object also exposes a `mw` function that returns a middleware\nfor fetch.\n\n```typescript\nconst mw = oauth2.mw();\nconst response = mw(\n  myRequest,\n  req => fetch(req)\n);\n```\n\nThis syntax looks a bit wild if you're not used to building middlewares, but\nthis effectively allows you to 'decorate' existing request libraries with\nfunctionality from this oauth2 library.\n\nA real example using the [Ketting](https://github.com/badgateway/ketting)\nlibrary:\n\n```typescript\nimport { Client } from 'ketting';\nimport { OAuth2Client, OAuth2Fetch } from 'fetch-mw-oauth2';\n\n/**\n * Create the oauth2 client\n */\nconst oauth2Client = new OAuth2Client({\n  server: 'https://my-auth.example',\n  clientId: 'foo',\n});\n\n/**\n * Create the 'fetch helper'\n */\nconst oauth2Fetch = new OAuth2Fetch({\n  client: oauth2Client,\n});\n\n/**\n * Add the middleware to Ketting\n */\nconst ketting = new Client('http://api-root');\nketting.use(oauth2Fetch.mw());\n```\n\n### Introspection\n\nIntrospection ([RFC7662][3]) lets you find more information about a token,\nsuch as whether it's valid, which user it belongs to, which oauth2 client\nwas used to generate it, etc.\n\nTo be able to use it, your authorization server must have support for the\nintrospection endpoint. It's location will be automatically detected using\nthe Metadata discovery document.\n\n```typescript\nimport { OAuth2Client } from 'fetch-mw-oauth2';\n\nconst client = new Client({\n  server: 'https://auth-server.example/',\n\n  clientId: '...',\n\n  /**\n   * Some servers require OAuth2 clientId/clientSecret to be passed.\n   * If they require it, specify it. If not it's fine to omit.\n   */\n  clientSecret: '...',\n\n});\n\n// Get a token\nconst token = client.clientCredentials();\n\n// Introspect!\nconsole.log(client.introspect(token));\n```\n\n[1]: https://datatracker.ietf.org/doc/html/rfc7636 \"Proof Key for Code Exchange by OAuth Public Clients\"\n[2]: https://datatracker.ietf.org/doc/html/rfc8414 \"OAuth 2.0 Authorization Server Metadata\"\n[3]: https://datatracker.ietf.org/doc/html/rfc7662 \"OAuth 2.0 Token Introspection\"\n","readmeFilename":"README.md","gitHead":"28c4b8d884f3f6bfc410ff62bd4659aabc308404","_id":"fetch-mw-oauth2@2.0.6","_nodeVersion":"18.0.0","_npmVersion":"8.6.0","dist":{"integrity":"sha512-iYg68Wh9w36ryZ+dgTs1ElrY50ODeYyYdYVIILMJCfVy9QB90QBibuXx5FF4Oz6/7mBBPViRh5Dt/pFGYNcT8g==","shasum":"a5ce8193352ea38980218510a1a3ee5bdd971d1a","tarball":"https://registry.npmjs.org/fetch-mw-oauth2/-/fetch-mw-oauth2-2.0.6.tgz","fileCount":46,"unpackedSize":144671,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIDHt1RJb+YzNVNkx6RnB9uvRGdGoXnccFmSkvn1fjhhqAiEA1SDEUcRx738ApogkPaEWwe7s6wcC7NcsUEwJzOZ4AU0="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiZkFKACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqFYA/+M8i4ZTLYRfvrUK0mQfeN+QxqAGhaX4JEQDPrNTTY+w4YlngI\r\n/0xrdzdYVP4uchxXFkTrhLUqb+IM/6RRE++ugh1dpRKW0FeKYRSQf+uRH1+j\r\n02uezSK0/OdQdWkoX0/DPZPoX8M54kOX73Jwd5TD621hTZq55pUX9cxvu0JT\r\nhBNi0LRVR9pE8C23rzfkp/iN4mnme95R0Qz0Xx0tpA1unnWWN1xnFJzgbOwv\r\nnqulRVwT6V4J1Ig7FYueRvMm5sV2ATFqks/TMC9kcdz9YAuY28VnL7e9ZYkh\r\nb5bKQwa85dT2oJ3ZudyPZ0FIfrQ4fsSZ03FFMdOpMdl4LfVl8xmjRD/PFeCt\r\nsoXFc4mlIrkAlYZdFZczUoaOVre54aJC0M4Za9RRffrmy05oMFbvbDOwPQPc\r\n8PBJIatB8ES2T2b1RVE0h4xVEYufgKWTbeXF/7+xFHGCLfK6V1+aFzhL+Q6a\r\n77zj8jmWv8sfmsyY4SMuZSyP2eh02++0N1c1gkGxS+yyV2T7OBBs1gqZ3YS3\r\nN0sIgBBCwbI0eX23yJHjvOGMq6/qTp9lD0Cyz66UHJ7+6zeYfrzmrmzZSj/d\r\nh+hPmfkFaEuSPH6EQbhOIaJVnumMJxEB2aIq8X2EavpVmdALG7Rqxb3RPNwv\r\ni/c8+2TISrEK1ZuT3jazaEtJkLFI9vRsSAk=\r\n=weQ4\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"evrt","email":"me@evertpot.com"},"directories":{},"maintainers":[{"name":"evrt","email":"me@evertpot.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fetch-mw-oauth2_2.0.6_1650868554606_0.5789714771421008"},"_hasShrinkwrap":false,"deprecated":"This package has been deprecated. v2 of this library has been renamed to @badgateway/oauth2-client"},"2.0.7":{"name":"fetch-mw-oauth2","version":"2.0.7","description":"Fetch middleware to add OAuth2 support","main":"dist/index.js","scripts":{"test":"make test lint","prepublishOnly":"make build"},"repository":{"type":"git","url":"git+ssh://git@github.com/badgateway/fetch-mw-oauth2.git"},"keywords":["fetch","oauth2"],"author":{"name":"Evert Pot","url":"https://evertpot.com"},"license":"MIT","bugs":{"url":"https://github.com/badgateway/fetch-mw-oauth2/issues"},"homepage":"https://github.com/badgateway/fetch-mw-oauth2#readme","devDependencies":{"@types/node":"^17.0.25","@typescript-eslint/eslint-plugin":"^5.2.0","@typescript-eslint/parser":"^5.2.0","eslint":"^8.1.0","node-fetch":"^3.0.0","ts-loader":"^9.2.6","typescript":"^4.4.4","webpack":"^5.60.0","webpack-cli":"^4.9.1"},"browser":"browser/fetch-mw-oauth2.min.js","types":"./dist/index.d.ts","readme":"# fetch-mw-oauth2\n\nThis package contains an OAuth2 client. It aims to be a fully-featured OAuth2\nutility library, for Node.js, Browsers and written in Typescript.\n\nThis library supports the following features:\n\n* `authorization_code` grant with optional [PKCE][1] support.\n* `password` and `client_credentials` grant.\n* a `fetch()` wrapper that automatically adds Bearer tokens and refreshes them.\n* OAuth2 endpoint discovery via the Server metadata document ([RFC8414][2]).\n* OAuth2 Token Introspection ([RFC7662][3]).\n\n\n## Installation\n\n```sh\nnpm i fetch-mw-oauth2\n```\n\n## Usage\n\nTo get started, set up the Client class.\n\n\n```typescript\nimport { OAuth2Client } from 'fetch-mw-oauth2';\n\nconst client = new Client({\n\n  // The base URI of your OAuth2 server\n  server: 'https://my-auth-server/',\n\n  // OAuth2 client id\n  clientId: '...',\n\n  // OAuth2 client secret. Only required for 'client_credentials', 'password'\n  // flows. You should not specify this for authorization_code.\n  clientSecret: '...',\n\n\n  // The following URIs are all optional. If they are not specified, we will\n  // attempt to discover them using the oauth2 discovery document.\n  // If your server doesn't have support this, you may need to specify these.\n  // you may use relative URIs for any of these.\n\n\n  // Token endpoint. Most flows need this.\n  // If not specified we'll use the information for the discovery document\n  // first, and otherwise default to /token\n  tokenEndpoint: '/token',\n\n  // Authorization endpoint.\n  //\n  // You only need this to generate URLs for authorization_code flows.\n  // If not specified we'll use the information for the discovery document\n  // first, and otherwise default to /authorize\n  authorizationEndpoint: '/authorize',\n\n  // OAuth2 Metadata discovery endpoint.\n  //\n  // This document is used to determine various server features.\n  // If not specified, we assume it's on /.well-known/oauth2-authorization-server\n  discoveryEndpoint: '/.well-known/oauth2-authorization-server',\n\n});\n```\n\n### Tokens\n\nMany functions use or return a 'OAuth2Token' type. This type has the following\nshape:\n\n```typescript\nexport type OAuth2Token = {\n  accessToken: string;\n  refreshToken: string | null;\n\n  /**\n   * When the Access Token expires.\n   *\n   * This is expressed as a unix timestamp in milliseconds.\n   */\n  expiresAt: number | null;\n\n};\n```\n\n\n### client_credentials grant.\n\n```typescript\nconst token = await client.clientCredentials();\n```\n\n### Refreshing tokens\n\n```typescript\nconst newToken = await client.refresh(oldToken);\n```\n\n\n### password grant:\n\n```typescript\nconst token = await client.password({\n  username: '..',\n  password: '..',\n});\n```\n\n### authorization_code\n\nThe `authorization_code` flow is the flow for browser-based applications,\nand roughly consists of 3 major steps:\n\n1. Redirect the user to an authorization endpoint, where they log in.\n2. Authorization endpoint redirects back to app with a 'code' query\n   parameter.\n3. The `code` is exchanged for a access and refresh token.\n\nThis library provides support for all 3 steps, but there's no requirement\nto use its functionality as the system is mostly stateless.\n\n```typescript\nimport { OAuth2Client } from 'client';\n\nconst client = new OAuth2Client({\n  server: 'https://authserver.example/',\n  clientId: '...',\n\n  // Note, if urls cannot be auto-detected, also specify these:\n  tokenEndpoint: '/token',\n  authorizationEndpoint: '/authorize',\n});\n\nconst authorizationCode = client.authorizationCode({\n\n  // URL in the app that the user should get redirected to after authenticating\n  redirectUri: 'https://my-app.example/',\n\n  // Optional string that can be sent along to the auth server. This value will\n  // be sent along with the redirect back to the app verbatim.\n  state: 'some-string',\n});\n```\n\n**Redirecting the user to the authorization server**\n\n```typescript\n// In a browser this might work as follows:\ndocument.location = await authorizationCode.getAuthorizeUri();\n```\n\n**Handling the redirect back to the app and obtain token**\n\n```typescript\nconst codeResponse = await authorizationCode.validateResponse(\n  document.location\n);\n\nconst oauth2Token = await authorizationCode.getToken(codeResponse);\n```\n\n### PKCE support\n\nModern OAuth2 server should support PKCE, which improves security.\nThis library supports PKCE. Luckily you don't need to know in advance whether\nyour authorization server supports it. If they do, you get the additional\nbenefit. If not, nothing should break.\n\nTo use PKCE, you need to make one extra step when calling `authorizationCode`:\n\n```typescript\nimport { OAuth2Client, getCodeVerifier } from 'client';\n\nconst client = new OAuth2Client({\n  server: 'https://authserver.example/',\n  clientId: '...',\n\n  // Note, if urls cannot be auto-detected, also specify these:\n  tokenEndpoint: '/token',\n  authorizationEndpoint: '/authorize',\n});\n\n/**\n * IMPORTANT! This returns a random value every time it's called\n *\n * Because the authorization_code is a multi-step process that likely results\n * in the user leaving your website and coming back later, you must store the\n * result of this somewhere.\n *\n * The codeVerifier gets used in the first step 'getAuthorizeUrl()` and the\n * last step 'getToken()`.\n */\nconst codeVerifier = getCodeVerifier();\nconst authorizationCode = client.authorizationCode({\n\n  // URL in the app that the user should get redirected to after authenticating\n  redirectUri: 'https://my-app.example/',\n\n  // Optional string that can be sent along to the auth server. This value will\n  // be sent along with the redirect back to the app verbatim.\n  state: 'some-string',\n\n  // Pass the code verifier\n  codeVerifier,\n});\n```\n\n### Fetch Wrapper\n\nWhen using an OAuth2-protected API, typically you will need to obtain an Access\ntoken, and then add this token to each request using an `Authorization: Bearer`\nheader.\n\nBecause access tokens have a limited lifetime, and occasionally needs to be\nrefreshed this is a bunch of potential plumbing.\n\nTo make this easier, this library has a 'fetch wrapper'. This is effectively\njust like a regular fetch function, except it automatically adds the header\nand will automatically refresh tokens when needed.\n\nUsage:\n\n```typescript\nimport { OAuth2Client, OAuth2Fetch } from 'fetch-mw-oauth2';\n\nconst client = new OAuth2Client({\n  server: 'https://my-auth-server',\n  clientId: 'my-client-id'\n});\n\n\nconst fetchWrapper = new OAuth2Fetch({\n  client: client,\n\n  /**\n   * You are responsible for implementing this function.\n   * it's purpose is to supply the 'intitial' oauth2 token.\n   */\n  getNewToken: async () => {\n\n    // Example\n    return client.clientCredentials();     \n\n    // Another example\n    return client.authorizationCode({\n      code: '..',\n      redirectUri: '..',\n    });\n\n    // You can return null to fail the process. You may want to do this\n    // when a user needs to be redirected back to the authorization_code\n    // endpoints.\n    return null;\n\n  },\n\n  /**\n   * Optional. This will be called for any fatal authentication errors.\n   */\n  onError: (err) => {\n    // err is of type Error\n  }\n\n});\n```\n\nAfter set up, you can just call `fetch` on the new object ot call your API, and\nthe library will ensure there's always a `Bearer` header.\n\n```typescript\nconst response = fetchWrapper.fetch('https://my-api', {\n  method: 'POST',\n  body: 'Hello world'\n});\n```\n\n### Storing tokens for later use with FetchWrapper\n\nTo keep a user logged in between sessions, you may want to avoid full\nreauthentication. To do this, you'll need to store authentication token.\n\nThe fetch wrapper has 2 functions to help with this:\n\n```typescript\n\nconst fetchWrapper = new OAuth2Fetch({\n  client: client,\n\n  getNewToken: async () => {\n\n    // See above!\n\n  },\n\n  /**\n   * This function is called whenever the active token changes. Using this is\n   * optional, but it may be used to (for example) put the token in off-line\n   * storage for later usage.\n   */\n  storeToken: (token) => {\n    document.localStorage.setItem('token-store', JSON.stringify(token));\n  }\n\n  /**\n   * Also an optional feature. Implement this if you want the wrapper to try a\n   * stored token before attempting a full reauthentication.\n   *\n   * This function may be async. Return null if there was no token.\n   */\n  getStoredToken: () => {\n    const token = document.localStorage.getItem('token-store');\n    if (token) return JSON.parse(token);\n    return null;\n  }\n\n});\n```\n\n\n### Fetch Middleware function\n\nIt might be preferable to use this library as a more traditional 'middleware'.\n\nThe OAuth2Fetch object also exposes a `mw` function that returns a middleware\nfor fetch.\n\n```typescript\nconst mw = oauth2.mw();\nconst response = mw(\n  myRequest,\n  req => fetch(req)\n);\n```\n\nThis syntax looks a bit wild if you're not used to building middlewares, but\nthis effectively allows you to 'decorate' existing request libraries with\nfunctionality from this oauth2 library.\n\nA real example using the [Ketting](https://github.com/badgateway/ketting)\nlibrary:\n\n```typescript\nimport { Client } from 'ketting';\nimport { OAuth2Client, OAuth2Fetch } from 'fetch-mw-oauth2';\n\n/**\n * Create the oauth2 client\n */\nconst oauth2Client = new OAuth2Client({\n  server: 'https://my-auth.example',\n  clientId: 'foo',\n});\n\n/**\n * Create the 'fetch helper'\n */\nconst oauth2Fetch = new OAuth2Fetch({\n  client: oauth2Client,\n});\n\n/**\n * Add the middleware to Ketting\n */\nconst ketting = new Client('http://api-root');\nketting.use(oauth2Fetch.mw());\n```\n\n### Introspection\n\nIntrospection ([RFC7662][3]) lets you find more information about a token,\nsuch as whether it's valid, which user it belongs to, which oauth2 client\nwas used to generate it, etc.\n\nTo be able to use it, your authorization server must have support for the\nintrospection endpoint. It's location will be automatically detected using\nthe Metadata discovery document.\n\n```typescript\nimport { OAuth2Client } from 'fetch-mw-oauth2';\n\nconst client = new Client({\n  server: 'https://auth-server.example/',\n\n  clientId: '...',\n\n  /**\n   * Some servers require OAuth2 clientId/clientSecret to be passed.\n   * If they require it, specify it. If not it's fine to omit.\n   */\n  clientSecret: '...',\n\n});\n\n// Get a token\nconst token = client.clientCredentials();\n\n// Introspect!\nconsole.log(client.introspect(token));\n```\n\n[1]: https://datatracker.ietf.org/doc/html/rfc7636 \"Proof Key for Code Exchange by OAuth Public Clients\"\n[2]: https://datatracker.ietf.org/doc/html/rfc8414 \"OAuth 2.0 Authorization Server Metadata\"\n[3]: https://datatracker.ietf.org/doc/html/rfc7662 \"OAuth 2.0 Token Introspection\"\n","readmeFilename":"README.md","gitHead":"571e7982253b66a74c32322557560a502889c7e2","_id":"fetch-mw-oauth2@2.0.7","_nodeVersion":"18.0.0","_npmVersion":"8.6.0","dist":{"integrity":"sha512-zbMPLXgFA5sgqbOJUKf+fb3G2/tIZeWuwgJ2MGRSlqlwqZd8Tl4HwoPfrZT6dBx3f6SeyWdXh7BkevXbAGhU1Q==","shasum":"db8e89476b13158cf75530571e78eb95c3b4d33c","tarball":"https://registry.npmjs.org/fetch-mw-oauth2/-/fetch-mw-oauth2-2.0.7.tgz","fileCount":46,"unpackedSize":144950,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQD6E7FmC+4Zqh5O3imR24Dk1LMGZ+THwvp54LFFOpK0JgIhAMmq5GpEZ3F+a1Ap1E3ZFAsXTDO3qpjqbUtuAe8itCbS"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiZkX/ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrtrA/7B7geChuwdf9ApFdY/q6KvRiGESXZ1gRONXgA1w2uMFHceaZ7\r\nOakTJO6Sa3rJZreFFo4Lsy9bprYmXuw2BDAb4MJWoeGVZmLZkt5GXJ6XUoM9\r\nNF/HeAsGnc2ZpjeiYAr9CIdIwakyUhK2SF90nN+luR2msH4R9jNreFYtgple\r\nHHzrxhXGesFVYFBt5IIEABvTlVn153vSgtYqJUlywNgXdL3L/LdbJRATAHdj\r\nlu9qa0xi2YiQWoFxlbnxqT+pZTFw0VEo2tPS4xHLa+GySRZ9vUkNdRzGXCot\r\nWDKZwDhDzIHKIAOKVj4Lapr34cmjIMtnfe+tAgNTBytdvGFrwUvOasxSud2V\r\nwJ+y2FGFqCOHuH6P7fzHF0aaEThdcz32E9uov5eUcUAtomjVDKm4LsZLIE5l\r\nE+HxEaVHfFUMz+Z+0HI4g4nJzYIWglPPzIjvM6+gTDqsXf/DionLonADp76N\r\nC3ZDGhKEOpUIEbG/N66XHpEYzYXZ0USKqEhQ8pJdKXYh+iveNVOZsB3a9uG2\r\nug6nTHhmNitRR+QX7L8F2PNhq1VeRllMPdJN2xwi50JJ+T7a2fBzlYlXsnq2\r\n4sQ/CDva4Gnc5IjeEza3NZLMoYOoZMYPYspC6bZsWMbVVVrqzqa2lyTaxIKr\r\nlP4qNqLHd/GoHS6wCSek2SBU+fWEs7s34pU=\r\n=6AgB\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"evrt","email":"me@evertpot.com"},"directories":{},"maintainers":[{"name":"evrt","email":"me@evertpot.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fetch-mw-oauth2_2.0.7_1650869759511_0.2208178469967026"},"_hasShrinkwrap":false,"deprecated":"This package has been deprecated. v2 of this library has been renamed to @badgateway/oauth2-client"},"2.0.8":{"name":"fetch-mw-oauth2","version":"2.0.8","description":"Fetch middleware to add OAuth2 support","main":"dist/index.js","scripts":{"test":"make test lint","prepublishOnly":"make build"},"repository":{"type":"git","url":"git+ssh://git@github.com/badgateway/fetch-mw-oauth2.git"},"keywords":["fetch","oauth2"],"author":{"name":"Evert Pot","url":"https://evertpot.com"},"license":"MIT","bugs":{"url":"https://github.com/badgateway/fetch-mw-oauth2/issues"},"homepage":"https://github.com/badgateway/fetch-mw-oauth2#readme","devDependencies":{"@types/node":"^17.0.25","@typescript-eslint/eslint-plugin":"^5.2.0","@typescript-eslint/parser":"^5.2.0","eslint":"^8.1.0","node-fetch":"^3.0.0","ts-loader":"^9.2.6","typescript":"^4.4.4","webpack":"^5.60.0","webpack-cli":"^4.9.1"},"browser":"browser/fetch-mw-oauth2.min.js","types":"./dist/index.d.ts","readme":"# fetch-mw-oauth2\n\nThis package contains an OAuth2 client. It aims to be a fully-featured OAuth2\nutility library, for Node.js, Browsers and written in Typescript.\n\nThis library supports the following features:\n\n* `authorization_code` grant with optional [PKCE][1] support.\n* `password` and `client_credentials` grant.\n* a `fetch()` wrapper that automatically adds Bearer tokens and refreshes them.\n* OAuth2 endpoint discovery via the Server metadata document ([RFC8414][2]).\n* OAuth2 Token Introspection ([RFC7662][3]).\n\n\n## Installation\n\n```sh\nnpm i fetch-mw-oauth2\n```\n\n## Usage\n\nTo get started, set up the Client class.\n\n\n```typescript\nimport { OAuth2Client } from 'fetch-mw-oauth2';\n\nconst client = new Client({\n\n  // The base URI of your OAuth2 server\n  server: 'https://my-auth-server/',\n\n  // OAuth2 client id\n  clientId: '...',\n\n  // OAuth2 client secret. Only required for 'client_credentials', 'password'\n  // flows. You should not specify this for authorization_code.\n  clientSecret: '...',\n\n\n  // The following URIs are all optional. If they are not specified, we will\n  // attempt to discover them using the oauth2 discovery document.\n  // If your server doesn't have support this, you may need to specify these.\n  // you may use relative URIs for any of these.\n\n\n  // Token endpoint. Most flows need this.\n  // If not specified we'll use the information for the discovery document\n  // first, and otherwise default to /token\n  tokenEndpoint: '/token',\n\n  // Authorization endpoint.\n  //\n  // You only need this to generate URLs for authorization_code flows.\n  // If not specified we'll use the information for the discovery document\n  // first, and otherwise default to /authorize\n  authorizationEndpoint: '/authorize',\n\n  // OAuth2 Metadata discovery endpoint.\n  //\n  // This document is used to determine various server features.\n  // If not specified, we assume it's on /.well-known/oauth2-authorization-server\n  discoveryEndpoint: '/.well-known/oauth2-authorization-server',\n\n});\n```\n\n### Tokens\n\nMany functions use or return a 'OAuth2Token' type. This type has the following\nshape:\n\n```typescript\nexport type OAuth2Token = {\n  accessToken: string;\n  refreshToken: string | null;\n\n  /**\n   * When the Access Token expires.\n   *\n   * This is expressed as a unix timestamp in milliseconds.\n   */\n  expiresAt: number | null;\n\n};\n```\n\n\n### client_credentials grant.\n\n```typescript\nconst token = await client.clientCredentials();\n```\n\n### Refreshing tokens\n\n```typescript\nconst newToken = await client.refresh(oldToken);\n```\n\n\n### password grant:\n\n```typescript\nconst token = await client.password({\n  username: '..',\n  password: '..',\n});\n```\n\n### authorization_code\n\nThe `authorization_code` flow is the flow for browser-based applications,\nand roughly consists of 3 major steps:\n\n1. Redirect the user to an authorization endpoint, where they log in.\n2. Authorization endpoint redirects back to app with a 'code' query\n   parameter.\n3. The `code` is exchanged for a access and refresh token.\n\nThis library provides support for these steps, but there's no requirement\nto use its functionality as the system is mostly stateless.\n\n```typescript\nimport { OAuth2Client, generateCodeVerifier } from 'client';\n\nconst client = new OAuth2Client({\n  server: 'https://authserver.example/',\n  clientId: '...',\n\n  // Note, if urls cannot be auto-detected, also specify these:\n  tokenEndpoint: '/token',\n  authorizationEndpoint: '/authorize',\n});\n```\n\n**Redirecting the user to the authorization server**\n\n```typescript\n\n/**\n * This generates a security code that must be passed to the various steps.\n * This is used for 'PKCE' which is an advanced security feature.\n *\n * It doesn't break servers that don't support it, but it makes servers that\n * so support it more secure.\n *\n * It's optional to pass this, but recommended.\n */\nconst codeVerifier = generateCodeVerifier():\n\n// In a browser this might work as follows:\ndocument.location = await authorizationCode.authorizationCode.getAuthorizeUri({\n\n  // URL in the app that the user should get redirected to after authenticating\n  redirectUri: 'https://my-app.example/',\n\n  // Optional string that can be sent along to the auth server. This value will\n  // be sent along with the redirect back to the app verbatim.\n  state: 'some-string',\n\n  codeVerifier,\n\n});\n```\n\n**Handling the redirect back to the app and obtain token**\n\n```typescript\nconst oauth2Token = await client.authorizationCode.getTokenFromCodeRedirect(\n  document.location,\n  {\n    /**\n     * The redirect URI is not actually used for any redirects, but MUST be the\n     * same as what you passed earlier to \"authorizationCode\"\n     */\n    redirectUri: 'https://my-app.example/',\n\n    /**\n     * This is optional, but if it's passed then it also MUST be the same as\n     * what you passed in the first step.\n     *\n     * If set, it will verify that the server sent the exact same state back.\n     */\n    state: 'some-string',\n\n    codeVerifier,\n\n  }\n);\n\nconst oauth2Token = await authorizationCode.getToken(codeResponse);\n```\n\n\n### Fetch Wrapper\n\nWhen using an OAuth2-protected API, typically you will need to obtain an Access\ntoken, and then add this token to each request using an `Authorization: Bearer`\nheader.\n\nBecause access tokens have a limited lifetime, and occasionally needs to be\nrefreshed this is a bunch of potential plumbing.\n\nTo make this easier, this library has a 'fetch wrapper'. This is effectively\njust like a regular fetch function, except it automatically adds the header\nand will automatically refresh tokens when needed.\n\nUsage:\n\n```typescript\nimport { OAuth2Client, OAuth2Fetch } from 'fetch-mw-oauth2';\n\nconst client = new OAuth2Client({\n  server: 'https://my-auth-server',\n  clientId: 'my-client-id'\n});\n\n\nconst fetchWrapper = new OAuth2Fetch({\n  client: client,\n\n  /**\n   * You are responsible for implementing this function.\n   * it's purpose is to supply the 'intitial' oauth2 token.\n   */\n  getNewToken: async () => {\n\n    // Example\n    return client.clientCredentials();\n\n    // Another example\n    return client.authorizationCode({\n      code: '..',\n      redirectUri: '..',\n    });\n\n    // You can return null to fail the process. You may want to do this\n    // when a user needs to be redirected back to the authorization_code\n    // endpoints.\n    return null;\n\n  },\n\n  /**\n   * Optional. This will be called for any fatal authentication errors.\n   */\n  onError: (err) => {\n    // err is of type Error\n  }\n\n});\n```\n\nAfter set up, you can just call `fetch` on the new object ot call your API, and\nthe library will ensure there's always a `Bearer` header.\n\n```typescript\nconst response = fetchWrapper.fetch('https://my-api', {\n  method: 'POST',\n  body: 'Hello world'\n});\n```\n\n### Storing tokens for later use with FetchWrapper\n\nTo keep a user logged in between sessions, you may want to avoid full\nreauthentication. To do this, you'll need to store authentication token.\n\nThe fetch wrapper has 2 functions to help with this:\n\n```typescript\n\nconst fetchWrapper = new OAuth2Fetch({\n  client: client,\n\n  getNewToken: async () => {\n\n    // See above!\n\n  },\n\n  /**\n   * This function is called whenever the active token changes. Using this is\n   * optional, but it may be used to (for example) put the token in off-line\n   * storage for later usage.\n   */\n  storeToken: (token) => {\n    document.localStorage.setItem('token-store', JSON.stringify(token));\n  }\n\n  /**\n   * Also an optional feature. Implement this if you want the wrapper to try a\n   * stored token before attempting a full reauthentication.\n   *\n   * This function may be async. Return null if there was no token.\n   */\n  getStoredToken: () => {\n    const token = document.localStorage.getItem('token-store');\n    if (token) return JSON.parse(token);\n    return null;\n  }\n\n});\n```\n\n\n### Fetch Middleware function\n\nIt might be preferable to use this library as a more traditional 'middleware'.\n\nThe OAuth2Fetch object also exposes a `mw` function that returns a middleware\nfor fetch.\n\n```typescript\nconst mw = oauth2.mw();\nconst response = mw(\n  myRequest,\n  req => fetch(req)\n);\n```\n\nThis syntax looks a bit wild if you're not used to building middlewares, but\nthis effectively allows you to 'decorate' existing request libraries with\nfunctionality from this oauth2 library.\n\nA real example using the [Ketting](https://github.com/badgateway/ketting)\nlibrary:\n\n```typescript\nimport { Client } from 'ketting';\nimport { OAuth2Client, OAuth2Fetch } from 'fetch-mw-oauth2';\n\n/**\n * Create the oauth2 client\n */\nconst oauth2Client = new OAuth2Client({\n  server: 'https://my-auth.example',\n  clientId: 'foo',\n});\n\n/**\n * Create the 'fetch helper'\n */\nconst oauth2Fetch = new OAuth2Fetch({\n  client: oauth2Client,\n});\n\n/**\n * Add the middleware to Ketting\n */\nconst ketting = new Client('http://api-root');\nketting.use(oauth2Fetch.mw());\n```\n\n### Introspection\n\nIntrospection ([RFC7662][3]) lets you find more information about a token,\nsuch as whether it's valid, which user it belongs to, which oauth2 client\nwas used to generate it, etc.\n\nTo be able to use it, your authorization server must have support for the\nintrospection endpoint. It's location will be automatically detected using\nthe Metadata discovery document.\n\n```typescript\nimport { OAuth2Client } from 'fetch-mw-oauth2';\n\nconst client = new Client({\n  server: 'https://auth-server.example/',\n\n  clientId: '...',\n\n  /**\n   * Some servers require OAuth2 clientId/clientSecret to be passed.\n   * If they require it, specify it. If not it's fine to omit.\n   */\n  clientSecret: '...',\n\n});\n\n// Get a token\nconst token = client.clientCredentials();\n\n// Introspect!\nconsole.log(client.introspect(token));\n```\n\n[1]: https://datatracker.ietf.org/doc/html/rfc7636 \"Proof Key for Code Exchange by OAuth Public Clients\"\n[2]: https://datatracker.ietf.org/doc/html/rfc8414 \"OAuth 2.0 Authorization Server Metadata\"\n[3]: https://datatracker.ietf.org/doc/html/rfc7662 \"OAuth 2.0 Token Introspection\"\n","readmeFilename":"README.md","gitHead":"16dfe56b18e895acb98495ec985c3d11202d8d34","_id":"fetch-mw-oauth2@2.0.8","_nodeVersion":"18.0.0","_npmVersion":"8.6.0","dist":{"integrity":"sha512-S/z52yqvRoHbvtEX1DPHSDDpFB4lK8iAfN+Z9j6iMirrnolE5hhRuEWOdfH8FvVGo6mvP6jM9L95aFM0NkOBvg==","shasum":"b0202372f8b169d1f759aad716e0193ef82890f5","tarball":"https://registry.npmjs.org/fetch-mw-oauth2/-/fetch-mw-oauth2-2.0.8.tgz","fileCount":46,"unpackedSize":145717,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCZZX4Ngy8uQPNwgIKM8Rqk3nPySb9C7eWp0DzBGujv6wIgfdyYmloUanW1xa8XxokE0oSVgbKgeXoJzSwpsukJVis="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiaFzPACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpAeg/9GNCO3Gc2qz57f3dA9DvsrKbmHWM0X7KLpdcbMXIMCmYTrPcy\r\nwetLFMi1UzTyshyKEIcLKTRCh18KkBM3N7T6CZuBbKKa6T1QkRuVjwADwFMG\r\nsmhhKxQhBcOLQ416Q5/K8VQNUiIWqnSijydkGDv8JImAaahMzyY8Z//+ESoo\r\n13MRW9E3YFNI92kSjdNrCFv6Ec+4Y0N4XYkFB03Ni7AstBTsPwiz/KlmfxYI\r\ngNCEY8kS+l7FO29mlMpPco2Mp7i1jH83ZzGhR80aEyREdibtL2hXIvSz0SbE\r\nCmC6FlniT4X5p7+ujtObdZcYYEPBLa2TSbC53EB3uf4PCqbtcw4qF1UUE+oC\r\nrgaG4iQbKijGRQNXfs/+pn8cPPjKvPfx424vWWIozKbrcif2XaORqHWzMjiY\r\nqX7ij9HTAQ0xXMgqsBVX2OHm5wMFuBp4+GpxsPtGc2LzU4o9wFmSluF6jWPi\r\nBokEMNyxHfBuIwMGTwf9Hu5wKBcB4j1M9+KXzt8W7vBt4uSzd92Espzp09Bw\r\nykKYHxs6VSKrE+XWXYLAjY80IMIi908dX3hjWgNw9viLuCg+3x5uvxQMNrx5\r\nGX5wvfL9jGRR9mT1l/DZfcSGCy+J0FDoHfprRTSkpyZ3S3MgqJy4ZJcAsuue\r\ndraHuex178vsgoJHj4+F7AlhB1qj3MctDec=\r\n=hK0V\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"evrt","email":"me@evertpot.com"},"directories":{},"maintainers":[{"name":"evrt","email":"me@evertpot.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fetch-mw-oauth2_2.0.8_1651006670817_0.17919146801368546"},"_hasShrinkwrap":false,"deprecated":"This package has been deprecated. v2 of this library has been renamed to @badgateway/oauth2-client"},"2.0.9":{"name":"fetch-mw-oauth2","version":"2.0.9","description":"Fetch middleware to add OAuth2 support","main":"dist/index.js","scripts":{"test":"make test lint","prepublishOnly":"make build"},"repository":{"type":"git","url":"git+ssh://git@github.com/badgateway/fetch-mw-oauth2.git"},"keywords":["fetch","oauth2"],"author":{"name":"Evert Pot","url":"https://evertpot.com"},"license":"MIT","bugs":{"url":"https://github.com/badgateway/fetch-mw-oauth2/issues"},"homepage":"https://github.com/badgateway/fetch-mw-oauth2#readme","devDependencies":{"@types/node":"^17.0.25","@typescript-eslint/eslint-plugin":"^5.2.0","@typescript-eslint/parser":"^5.2.0","eslint":"^8.1.0","node-fetch":"^3.0.0","ts-loader":"^9.2.6","typescript":"^4.4.4","webpack":"^5.60.0","webpack-cli":"^4.9.1"},"browser":"browser/fetch-mw-oauth2.min.js","types":"./dist/index.d.ts","readme":"# fetch-mw-oauth2\n\nThis package contains an OAuth2 client. It aims to be a fully-featured OAuth2\nutility library, for Node.js, Browsers and written in Typescript.\n\nThis library supports the following features:\n\n* `authorization_code` grant with optional [PKCE][1] support.\n* `password` and `client_credentials` grant.\n* a `fetch()` wrapper that automatically adds Bearer tokens and refreshes them.\n* OAuth2 endpoint discovery via the Server metadata document ([RFC8414][2]).\n* OAuth2 Token Introspection ([RFC7662][3]).\n\n\n## Installation\n\n```sh\nnpm i fetch-mw-oauth2\n```\n\n## Usage\n\nTo get started, set up the Client class.\n\n\n```typescript\nimport { OAuth2Client } from 'fetch-mw-oauth2';\n\nconst client = new Client({\n\n  // The base URI of your OAuth2 server\n  server: 'https://my-auth-server/',\n\n  // OAuth2 client id\n  clientId: '...',\n\n  // OAuth2 client secret. Only required for 'client_credentials', 'password'\n  // flows. You should not specify this for authorization_code.\n  clientSecret: '...',\n\n\n  // The following URIs are all optional. If they are not specified, we will\n  // attempt to discover them using the oauth2 discovery document.\n  // If your server doesn't have support this, you may need to specify these.\n  // you may use relative URIs for any of these.\n\n\n  // Token endpoint. Most flows need this.\n  // If not specified we'll use the information for the discovery document\n  // first, and otherwise default to /token\n  tokenEndpoint: '/token',\n\n  // Authorization endpoint.\n  //\n  // You only need this to generate URLs for authorization_code flows.\n  // If not specified we'll use the information for the discovery document\n  // first, and otherwise default to /authorize\n  authorizationEndpoint: '/authorize',\n\n  // OAuth2 Metadata discovery endpoint.\n  //\n  // This document is used to determine various server features.\n  // If not specified, we assume it's on /.well-known/oauth2-authorization-server\n  discoveryEndpoint: '/.well-known/oauth2-authorization-server',\n\n});\n```\n\n### Tokens\n\nMany functions use or return a 'OAuth2Token' type. This type has the following\nshape:\n\n```typescript\nexport type OAuth2Token = {\n  accessToken: string;\n  refreshToken: string | null;\n\n  /**\n   * When the Access Token expires.\n   *\n   * This is expressed as a unix timestamp in milliseconds.\n   */\n  expiresAt: number | null;\n\n};\n```\n\n\n### client_credentials grant.\n\n```typescript\nconst token = await client.clientCredentials();\n```\n\n### Refreshing tokens\n\n```typescript\nconst newToken = await client.refresh(oldToken);\n```\n\n\n### password grant:\n\n```typescript\nconst token = await client.password({\n  username: '..',\n  password: '..',\n});\n```\n\n### authorization_code\n\nThe `authorization_code` flow is the flow for browser-based applications,\nand roughly consists of 3 major steps:\n\n1. Redirect the user to an authorization endpoint, where they log in.\n2. Authorization endpoint redirects back to app with a 'code' query\n   parameter.\n3. The `code` is exchanged for a access and refresh token.\n\nThis library provides support for these steps, but there's no requirement\nto use its functionality as the system is mostly stateless.\n\n```typescript\nimport { OAuth2Client, generateCodeVerifier } from 'client';\n\nconst client = new OAuth2Client({\n  server: 'https://authserver.example/',\n  clientId: '...',\n\n  // Note, if urls cannot be auto-detected, also specify these:\n  tokenEndpoint: '/token',\n  authorizationEndpoint: '/authorize',\n});\n```\n\n**Redirecting the user to the authorization server**\n\n```typescript\n\n/**\n * This generates a security code that must be passed to the various steps.\n * This is used for 'PKCE' which is an advanced security feature.\n *\n * It doesn't break servers that don't support it, but it makes servers that\n * so support it more secure.\n *\n * It's optional to pass this, but recommended.\n */\nconst codeVerifier = generateCodeVerifier():\n\n// In a browser this might work as follows:\ndocument.location = await authorizationCode.authorizationCode.getAuthorizeUri({\n\n  // URL in the app that the user should get redirected to after authenticating\n  redirectUri: 'https://my-app.example/',\n\n  // Optional string that can be sent along to the auth server. This value will\n  // be sent along with the redirect back to the app verbatim.\n  state: 'some-string',\n\n  codeVerifier,\n\n});\n```\n\n**Handling the redirect back to the app and obtain token**\n\n```typescript\nconst oauth2Token = await client.authorizationCode.getTokenFromCodeRedirect(\n  document.location,\n  {\n    /**\n     * The redirect URI is not actually used for any redirects, but MUST be the\n     * same as what you passed earlier to \"authorizationCode\"\n     */\n    redirectUri: 'https://my-app.example/',\n\n    /**\n     * This is optional, but if it's passed then it also MUST be the same as\n     * what you passed in the first step.\n     *\n     * If set, it will verify that the server sent the exact same state back.\n     */\n    state: 'some-string',\n\n    codeVerifier,\n\n  }\n);\n\nconst oauth2Token = await authorizationCode.getToken(codeResponse);\n```\n\n\n### Fetch Wrapper\n\nWhen using an OAuth2-protected API, typically you will need to obtain an Access\ntoken, and then add this token to each request using an `Authorization: Bearer`\nheader.\n\nBecause access tokens have a limited lifetime, and occasionally needs to be\nrefreshed this is a bunch of potential plumbing.\n\nTo make this easier, this library has a 'fetch wrapper'. This is effectively\njust like a regular fetch function, except it automatically adds the header\nand will automatically refresh tokens when needed.\n\nUsage:\n\n```typescript\nimport { OAuth2Client, OAuth2Fetch } from 'fetch-mw-oauth2';\n\nconst client = new OAuth2Client({\n  server: 'https://my-auth-server',\n  clientId: 'my-client-id'\n});\n\n\nconst fetchWrapper = new OAuth2Fetch({\n  client: client,\n\n  /**\n   * You are responsible for implementing this function.\n   * it's purpose is to supply the 'intitial' oauth2 token.\n   */\n  getNewToken: async () => {\n\n    // Example\n    return client.clientCredentials();\n\n    // Another example\n    return client.authorizationCode({\n      code: '..',\n      redirectUri: '..',\n    });\n\n    // You can return null to fail the process. You may want to do this\n    // when a user needs to be redirected back to the authorization_code\n    // endpoints.\n    return null;\n\n  },\n\n  /**\n   * Optional. This will be called for any fatal authentication errors.\n   */\n  onError: (err) => {\n    // err is of type Error\n  }\n\n});\n```\n\nAfter set up, you can just call `fetch` on the new object ot call your API, and\nthe library will ensure there's always a `Bearer` header.\n\n```typescript\nconst response = fetchWrapper.fetch('https://my-api', {\n  method: 'POST',\n  body: 'Hello world'\n});\n```\n\n### Storing tokens for later use with FetchWrapper\n\nTo keep a user logged in between sessions, you may want to avoid full\nreauthentication. To do this, you'll need to store authentication token.\n\nThe fetch wrapper has 2 functions to help with this:\n\n```typescript\n\nconst fetchWrapper = new OAuth2Fetch({\n  client: client,\n\n  getNewToken: async () => {\n\n    // See above!\n\n  },\n\n  /**\n   * This function is called whenever the active token changes. Using this is\n   * optional, but it may be used to (for example) put the token in off-line\n   * storage for later usage.\n   */\n  storeToken: (token) => {\n    document.localStorage.setItem('token-store', JSON.stringify(token));\n  }\n\n  /**\n   * Also an optional feature. Implement this if you want the wrapper to try a\n   * stored token before attempting a full reauthentication.\n   *\n   * This function may be async. Return null if there was no token.\n   */\n  getStoredToken: () => {\n    const token = document.localStorage.getItem('token-store');\n    if (token) return JSON.parse(token);\n    return null;\n  }\n\n});\n```\n\n\n### Fetch Middleware function\n\nIt might be preferable to use this library as a more traditional 'middleware'.\n\nThe OAuth2Fetch object also exposes a `mw` function that returns a middleware\nfor fetch.\n\n```typescript\nconst mw = oauth2.mw();\nconst response = mw(\n  myRequest,\n  req => fetch(req)\n);\n```\n\nThis syntax looks a bit wild if you're not used to building middlewares, but\nthis effectively allows you to 'decorate' existing request libraries with\nfunctionality from this oauth2 library.\n\nA real example using the [Ketting](https://github.com/badgateway/ketting)\nlibrary:\n\n```typescript\nimport { Client } from 'ketting';\nimport { OAuth2Client, OAuth2Fetch } from 'fetch-mw-oauth2';\n\n/**\n * Create the oauth2 client\n */\nconst oauth2Client = new OAuth2Client({\n  server: 'https://my-auth.example',\n  clientId: 'foo',\n});\n\n/**\n * Create the 'fetch helper'\n */\nconst oauth2Fetch = new OAuth2Fetch({\n  client: oauth2Client,\n});\n\n/**\n * Add the middleware to Ketting\n */\nconst ketting = new Client('http://api-root');\nketting.use(oauth2Fetch.mw());\n```\n\n### Introspection\n\nIntrospection ([RFC7662][3]) lets you find more information about a token,\nsuch as whether it's valid, which user it belongs to, which oauth2 client\nwas used to generate it, etc.\n\nTo be able to use it, your authorization server must have support for the\nintrospection endpoint. It's location will be automatically detected using\nthe Metadata discovery document.\n\n```typescript\nimport { OAuth2Client } from 'fetch-mw-oauth2';\n\nconst client = new Client({\n  server: 'https://auth-server.example/',\n\n  clientId: '...',\n\n  /**\n   * Some servers require OAuth2 clientId/clientSecret to be passed.\n   * If they require it, specify it. If not it's fine to omit.\n   */\n  clientSecret: '...',\n\n});\n\n// Get a token\nconst token = client.clientCredentials();\n\n// Introspect!\nconsole.log(client.introspect(token));\n```\n\n[1]: https://datatracker.ietf.org/doc/html/rfc7636 \"Proof Key for Code Exchange by OAuth Public Clients\"\n[2]: https://datatracker.ietf.org/doc/html/rfc8414 \"OAuth 2.0 Authorization Server Metadata\"\n[3]: https://datatracker.ietf.org/doc/html/rfc7662 \"OAuth 2.0 Token Introspection\"\n","readmeFilename":"README.md","gitHead":"b4b776d1fe113407ab04270eb7a6d26638848e6a","_id":"fetch-mw-oauth2@2.0.9","_nodeVersion":"18.0.0","_npmVersion":"8.6.0","dist":{"integrity":"sha512-RVdZd/rfaXKDrcZkaMWJOgjUhsDPBy7rTvwt2uXpTGZUxGrBgqm+IaFw3f3lXLgRPhjt3XvaR2mf0UL0+WX9Gw==","shasum":"5f22cbd333576498efb3a4eafce234a8d3c579aa","tarball":"https://registry.npmjs.org/fetch-mw-oauth2/-/fetch-mw-oauth2-2.0.9.tgz","fileCount":46,"unpackedSize":146007,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIFpcsHwriBZW3hY3ZyX/38WUJiR41f3tp63q5hRsxFJKAiBjczVbtsPQ3BjKVyUu0pz6CydjMVNi8DTIARUEM4H3MA=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiaGWaACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmp/PhAAn8GcynzAA8iHcROBKvf39TsgGe8s+PFa4xIJK/wkDyv8mU2V\r\nKgv3xpVV4DBWEvHWfLYItN/K6+80+ipBhpXWA1LFhPxoJHjlcuSNcicFffy+\r\nbCdzlPLgD5xuu1LbdTBf5lRYibcAhcD6qVCfb95SnV4ltbf1bdC7LtdjzSjD\r\nVgcC/j0ceof8a/DMCcTeeh2F3INGMXrQim/Ai2g9L7Q2ACU7QxHV7yNtHVlC\r\nrggQf1bTIGmIibwY0OLAz1QkJ6RyyYkoZoXlmTGIof7ZSI/km1Y8VbzSc5El\r\nI/rQ0JrvncRLpccggI5rURhQF91BfBUxNC103Zpe0MZpqZI1evtA0+L0uRyU\r\nA6C2oQNaI+SEXHx9swjgffMYT73QTxmJxo1eYV6tXwl6sq6SL2I17cvKdwaA\r\ni3ENHxDbMGJFKSXP2Xu7jco5ZPvaPGpnxL32eNtPtL+kUXBiai3qsn+2ZObg\r\nNNB6p4FPnIIaVapR5epznKQ7ZvnBGsIVRYfuoQL6lXnOsnXzmf8M6We9IU7B\r\nuJT7W6wvwkL1pgJWDBmRCMC4doKIHKohPNA9C9QjianC8kGm2F6O5Clc97Y7\r\nLf0YT+9QmHScuJTLgBCm2cxfA2AOaMAJWlzp4RwZ9KnF5W8D3TdjRLjio/hq\r\nGcbi+kirlSYthRIxnuOGgKLU7E+sLgy8tVg=\r\n=Vv/g\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"evrt","email":"me@evertpot.com"},"directories":{},"maintainers":[{"name":"evrt","email":"me@evertpot.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fetch-mw-oauth2_2.0.9_1651008922356_0.813922117538892"},"_hasShrinkwrap":false,"deprecated":"This package has been deprecated. v2 of this library has been renamed to @badgateway/oauth2-client"},"2.0.10":{"name":"fetch-mw-oauth2","version":"2.0.10","description":"Fetch middleware to add OAuth2 support","main":"dist/index.js","scripts":{"test":"make test","prepublishOnly":"make build","lint":"make lint"},"repository":{"type":"git","url":"git+ssh://git@github.com/badgateway/fetch-mw-oauth2.git"},"keywords":["fetch","oauth2"],"author":{"name":"Evert Pot","url":"https://evertpot.com"},"license":"MIT","bugs":{"url":"https://github.com/badgateway/fetch-mw-oauth2/issues"},"homepage":"https://github.com/badgateway/fetch-mw-oauth2#readme","devDependencies":{"@curveball/bodyparser":"^0.4.14","@curveball/core":"^0.19.0","@types/chai":"^4.3.1","@types/mocha":"^9.1.1","@types/node":"^17.0.25","@typescript-eslint/eslint-plugin":"^5.2.0","@typescript-eslint/parser":"^5.2.0","chai":"^4.3.6","eslint":"^8.1.0","mocha":"^10.0.0","node-fetch":"^2.6.7","ts-loader":"^9.2.6","ts-node":"^10.7.0","typescript":"^4.4.4","webpack":"^5.60.0","webpack-cli":"^4.9.1"},"browser":"browser/fetch-mw-oauth2.min.js","mocha":{"require":["ts-node/register","./test/polyfills.js"],"recursive":true,"extension":["ts","js","tsx"]},"types":"./dist/index.d.ts","readme":"# fetch-mw-oauth2\n\nThis package contains an OAuth2 client. It aims to be a fully-featured OAuth2\nutility library, for Node.js, Browsers and written in Typescript.\n\nThis library supports the following features:\n\n* 9KB minified.\n* `authorization_code` grant with optional [PKCE][1] support.\n* `password` and `client_credentials` grant.\n* a `fetch()` wrapper that automatically adds Bearer tokens and refreshes them.\n* OAuth2 endpoint discovery via the Server metadata document ([RFC8414][2]).\n* OAuth2 Token Introspection ([RFC7662][3]).\n\n\n## Installation\n\n```sh\nnpm i fetch-mw-oauth2\n```\n\n\n## Usage\n\nTo get started, set up the Client class.\n\n\n```typescript\nimport { OAuth2Client } from 'fetch-mw-oauth2';\n\nconst client = new Client({\n\n  // The base URI of your OAuth2 server\n  server: 'https://my-auth-server/',\n\n  // OAuth2 client id\n  clientId: '...',\n\n  // OAuth2 client secret. Only required for 'client_credentials', 'password'\n  // flows. You should not specify this for authorization_code.\n  clientSecret: '...',\n\n\n  // The following URIs are all optional. If they are not specified, we will\n  // attempt to discover them using the oauth2 discovery document.\n  // If your server doesn't have support this, you may need to specify these.\n  // you may use relative URIs for any of these.\n\n\n  // Token endpoint. Most flows need this.\n  // If not specified we'll use the information for the discovery document\n  // first, and otherwise default to /token\n  tokenEndpoint: '/token',\n\n  // Authorization endpoint.\n  //\n  // You only need this to generate URLs for authorization_code flows.\n  // If not specified we'll use the information for the discovery document\n  // first, and otherwise default to /authorize\n  authorizationEndpoint: '/authorize',\n\n  // OAuth2 Metadata discovery endpoint.\n  //\n  // This document is used to determine various server features.\n  // If not specified, we assume it's on /.well-known/oauth2-authorization-server\n  discoveryEndpoint: '/.well-known/oauth2-authorization-server',\n\n});\n```\n\n### Tokens\n\nMany functions use or return a 'OAuth2Token' type. This type has the following\nshape:\n\n```typescript\nexport type OAuth2Token = {\n  accessToken: string;\n  refreshToken: string | null;\n\n  /**\n   * When the Access Token expires.\n   *\n   * This is expressed as a unix timestamp in milliseconds.\n   */\n  expiresAt: number | null;\n\n};\n```\n\n\n### client_credentials grant.\n\n```typescript\nconst token = await client.clientCredentials();\n```\n\n### Refreshing tokens\n\n```typescript\nconst newToken = await client.refresh(oldToken);\n```\n\n\n### password grant:\n\n```typescript\nconst token = await client.password({\n  username: '..',\n  password: '..',\n});\n```\n\n### authorization_code\n\nThe `authorization_code` flow is the flow for browser-based applications,\nand roughly consists of 3 major steps:\n\n1. Redirect the user to an authorization endpoint, where they log in.\n2. Authorization endpoint redirects back to app with a 'code' query\n   parameter.\n3. The `code` is exchanged for a access and refresh token.\n\nThis library provides support for these steps, but there's no requirement\nto use its functionality as the system is mostly stateless.\n\n```typescript\nimport { OAuth2Client, generateCodeVerifier } from 'client';\n\nconst client = new OAuth2Client({\n  server: 'https://authserver.example/',\n  clientId: '...',\n\n  // Note, if urls cannot be auto-detected, also specify these:\n  tokenEndpoint: '/token',\n  authorizationEndpoint: '/authorize',\n});\n```\n\n**Redirecting the user to the authorization server**\n\n```typescript\n\n/**\n * This generates a security code that must be passed to the various steps.\n * This is used for 'PKCE' which is an advanced security feature.\n *\n * It doesn't break servers that don't support it, but it makes servers that\n * so support it more secure.\n *\n * It's optional to pass this, but recommended.\n */\nconst codeVerifier = await generateCodeVerifier():\n\n// In a browser this might work as follows:\ndocument.location = await authorizationCode.authorizationCode.getAuthorizeUri({\n\n  // URL in the app that the user should get redirected to after authenticating\n  redirectUri: 'https://my-app.example/',\n\n  // Optional string that can be sent along to the auth server. This value will\n  // be sent along with the redirect back to the app verbatim.\n  state: 'some-string',\n\n  codeVerifier,\n\n});\n```\n\n**Handling the redirect back to the app and obtain token**\n\n```typescript\nconst oauth2Token = await client.authorizationCode.getTokenFromCodeRedirect(\n  document.location,\n  {\n    /**\n     * The redirect URI is not actually used for any redirects, but MUST be the\n     * same as what you passed earlier to \"authorizationCode\"\n     */\n    redirectUri: 'https://my-app.example/',\n\n    /**\n     * This is optional, but if it's passed then it also MUST be the same as\n     * what you passed in the first step.\n     *\n     * If set, it will verify that the server sent the exact same state back.\n     */\n    state: 'some-string',\n\n    codeVerifier,\n\n  }\n);\n\nconst oauth2Token = await authorizationCode.getToken(codeResponse);\n```\n\n\n### Fetch Wrapper\n\nWhen using an OAuth2-protected API, typically you will need to obtain an Access\ntoken, and then add this token to each request using an `Authorization: Bearer`\nheader.\n\nBecause access tokens have a limited lifetime, and occasionally needs to be\nrefreshed this is a bunch of potential plumbing.\n\nTo make this easier, this library has a 'fetch wrapper'. This is effectively\njust like a regular fetch function, except it automatically adds the header\nand will automatically refresh tokens when needed.\n\nUsage:\n\n```typescript\nimport { OAuth2Client, OAuth2Fetch } from 'fetch-mw-oauth2';\n\nconst client = new OAuth2Client({\n  server: 'https://my-auth-server',\n  clientId: 'my-client-id'\n});\n\n\nconst fetchWrapper = new OAuth2Fetch({\n  client: client,\n\n  /**\n   * You are responsible for implementing this function.\n   * it's purpose is to supply the 'intitial' oauth2 token.\n   */\n  getNewToken: async () => {\n\n    // Example\n    return client.clientCredentials();\n\n    // Another example\n    return client.authorizationCode({\n      code: '..',\n      redirectUri: '..',\n    });\n\n    // You can return null to fail the process. You may want to do this\n    // when a user needs to be redirected back to the authorization_code\n    // endpoints.\n    return null;\n\n  },\n\n  /**\n   * Optional. This will be called for any fatal authentication errors.\n   */\n  onError: (err) => {\n    // err is of type Error\n  }\n\n});\n```\n\nAfter set up, you can just call `fetch` on the new object ot call your API, and\nthe library will ensure there's always a `Bearer` header.\n\n```typescript\nconst response = fetchWrapper.fetch('https://my-api', {\n  method: 'POST',\n  body: 'Hello world'\n});\n```\n\n### Storing tokens for later use with FetchWrapper\n\nTo keep a user logged in between sessions, you may want to avoid full\nreauthentication. To do this, you'll need to store authentication token.\n\nThe fetch wrapper has 2 functions to help with this:\n\n```typescript\n\nconst fetchWrapper = new OAuth2Fetch({\n  client: client,\n\n  getNewToken: async () => {\n\n    // See above!\n\n  },\n\n  /**\n   * This function is called whenever the active token changes. Using this is\n   * optional, but it may be used to (for example) put the token in off-line\n   * storage for later usage.\n   */\n  storeToken: (token) => {\n    document.localStorage.setItem('token-store', JSON.stringify(token));\n  }\n\n  /**\n   * Also an optional feature. Implement this if you want the wrapper to try a\n   * stored token before attempting a full reauthentication.\n   *\n   * This function may be async. Return null if there was no token.\n   */\n  getStoredToken: () => {\n    const token = document.localStorage.getItem('token-store');\n    if (token) return JSON.parse(token);\n    return null;\n  }\n\n});\n```\n\n\n### Fetch Middleware function\n\nIt might be preferable to use this library as a more traditional 'middleware'.\n\nThe OAuth2Fetch object also exposes a `mw` function that returns a middleware\nfor fetch.\n\n```typescript\nconst mw = oauth2.mw();\nconst response = mw(\n  myRequest,\n  req => fetch(req)\n);\n```\n\nThis syntax looks a bit wild if you're not used to building middlewares, but\nthis effectively allows you to 'decorate' existing request libraries with\nfunctionality from this oauth2 library.\n\nA real example using the [Ketting](https://github.com/badgateway/ketting)\nlibrary:\n\n```typescript\nimport { Client } from 'ketting';\nimport { OAuth2Client, OAuth2Fetch } from 'fetch-mw-oauth2';\n\n/**\n * Create the oauth2 client\n */\nconst oauth2Client = new OAuth2Client({\n  server: 'https://my-auth.example',\n  clientId: 'foo',\n});\n\n/**\n * Create the 'fetch helper'\n */\nconst oauth2Fetch = new OAuth2Fetch({\n  client: oauth2Client,\n});\n\n/**\n * Add the middleware to Ketting\n */\nconst ketting = new Client('http://api-root');\nketting.use(oauth2Fetch.mw());\n```\n\n### Introspection\n\nIntrospection ([RFC7662][3]) lets you find more information about a token,\nsuch as whether it's valid, which user it belongs to, which oauth2 client\nwas used to generate it, etc.\n\nTo be able to use it, your authorization server must have support for the\nintrospection endpoint. It's location will be automatically detected using\nthe Metadata discovery document.\n\n```typescript\nimport { OAuth2Client } from 'fetch-mw-oauth2';\n\nconst client = new Client({\n  server: 'https://auth-server.example/',\n\n  clientId: '...',\n\n  /**\n   * Some servers require OAuth2 clientId/clientSecret to be passed.\n   * If they require it, specify it. If not it's fine to omit.\n   */\n  clientSecret: '...',\n\n});\n\n// Get a token\nconst token = client.clientCredentials();\n\n// Introspect!\nconsole.log(client.introspect(token));\n```\n\n\n## Support for older Node versions\n\nThis package works out of the box with modern browsers and Node 18.\n\nTo use this package with Node 16, you need to run:\n\n```sh\nnpm i node-fetch@2\n```\n\nVersion 2 is required, because version 3 has been rewritten in a non-backwards\ncompatible way with ESM.\n\nAfter installing node-fetch, it must be registered globally:\n\n```javascript\nif (!global.fetch) {\n  const nodeFetch = require('node-fetch');\n  global.fetch = nodeFetch;\n  global.Headers = nodeFetch.Headers;\n  global.Request = nodeFetch.Request;\n  global.Response = nodeFetch.Response;\n}\n```\n\nOn Node 14.x you also need the following polyfill:\n\n```javascript\n// For Node 14.x and below\nif (global.btoa === undefined) {\n  global.btoa = input => {\n    return Buffer.from(input).toString('base64');\n  };\n}\n```\n\n[1]: https://datatracker.ietf.org/doc/html/rfc7636 \"Proof Key for Code Exchange by OAuth Public Clients\"\n[2]: https://datatracker.ietf.org/doc/html/rfc8414 \"OAuth 2.0 Authorization Server Metadata\"\n[3]: https://datatracker.ietf.org/doc/html/rfc7662 \"OAuth 2.0 Token Introspection\"\n","readmeFilename":"README.md","gitHead":"0b0959d782f1fc417e775dfdebe5a92f977004cb","_id":"fetch-mw-oauth2@2.0.10","_nodeVersion":"18.1.0","_npmVersion":"8.8.0","dist":{"integrity":"sha512-wxqU77NcbuPIEo1zevDrmxbsk6q/0ZkbePbyyOqXEh06rW70mYqaG8Xh9a+gOpTlK8uOMwRzT02K8Nkz7AVPNQ==","shasum":"3fd33829b076cbd1a72a3d1a1f6facd7c918bed0","tarball":"https://registry.npmjs.org/fetch-mw-oauth2/-/fetch-mw-oauth2-2.0.10.tgz","fileCount":46,"unpackedSize":149243,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCICln88lESpTwTISHMQ9NfsFKXV7PStdZfeoUTXwdfLOUAiEAm2kYKWa1szyqQXiiYZs1uox5cEUfbMhI0bv+HENNIgg="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiegOjACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoUvw//QXDwtMQ6FdbsF21ryMaWsENGhrTHK+YIenF7D88DOTceZqgK\r\nEsx+loexp35PXvSc0bjGXf7EPbCt+le4mH15b6QOwWh1bsQh6Y+CaIprOnYU\r\nz+qVOvfF4AmvstzSHFfWgfKiJKF8GcK4TlVlW8205oz+0y6g/5Blm+xn4UrV\r\nFRvX+mEYa2iVLA2RiBGbdPIVBhrDsjQVpRV7W7X1JCZ02PqI+Q+iulOWsOVq\r\n8WvNmlB22z6lRwuHRNdhEwmPHPI0nHVYVTF92wmFYcAu1DhfD6PE8Ey54v/h\r\njshRZP1iXoww4zRpG7qP266ulputgzQGLNdKHruoU5mCeKfKwpfIfOthgzh4\r\nrwhLOzmZIWPh8hpkLY3FXI7+hF8FitMXz5kfVl9O/0OZnLqTm+KC2ky8Q0G+\r\nl2UmqAs0Tb/046GQDgg3kuhgRaOrCRHq1uT3iMzvi78zomneFB7ISYb4Sokf\r\nyxihjSa8cebleRcEV/25UNPM4Dd8kKIZ8rZerTCK0nWXnMrkkV3uKTR6QjiK\r\nKjW3yoghg+99uUaIj5Sfc4OLaSONTeb0q4s/6oFTOD0Xhub2I1Hi103B6T8c\r\nkmAKwSkORNWwXyb8oBoIhLarTJ3DmegBxSqh5Jis0NXPSeIWDKQz2ivUyAVH\r\ngh+5/QpCizRRXa79Ay4puadZLqCsTWVlACo=\r\n=G6qx\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"evrt","email":"me@evertpot.com"},"directories":{},"maintainers":[{"name":"evrt","email":"me@evertpot.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fetch-mw-oauth2_2.0.10_1652163491662_0.5898237187025126"},"_hasShrinkwrap":false,"deprecated":"This package has been deprecated. v2 of this library has been renamed to @badgateway/oauth2-client"},"2.0.11":{"name":"fetch-mw-oauth2","version":"2.0.11","description":"Fetch middleware to add OAuth2 support","main":"dist/index.js","scripts":{"test":"make test","prepublishOnly":"make build","lint":"make lint"},"repository":{"type":"git","url":"git+ssh://git@github.com/badgateway/fetch-mw-oauth2.git"},"keywords":["fetch","oauth2"],"author":{"name":"Evert Pot","url":"https://evertpot.com"},"license":"MIT","bugs":{"url":"https://github.com/badgateway/fetch-mw-oauth2/issues"},"homepage":"https://github.com/badgateway/fetch-mw-oauth2#readme","engines":{"node":">= 14"},"devDependencies":{"@curveball/bodyparser":"^0.4.14","@curveball/core":"^0.19.0","@types/chai":"^4.3.1","@types/mocha":"^9.1.1","@types/node":"^17.0.25","@typescript-eslint/eslint-plugin":"^5.2.0","@typescript-eslint/parser":"^5.2.0","chai":"^4.3.6","eslint":"^8.1.0","mocha":"^10.0.0","node-fetch":"^2.6.7","ts-loader":"^9.2.6","ts-node":"^10.7.0","typescript":"^4.4.4","webpack":"^5.60.0","webpack-cli":"^4.9.1"},"browser":"browser/fetch-mw-oauth2.min.js","mocha":{"require":["ts-node/register","./test/polyfills.js"],"recursive":true,"extension":["ts","js","tsx"]},"types":"./dist/index.d.ts","readme":"# fetch-mw-oauth2\n\nThis package contains an OAuth2 client. It aims to be a fully-featured OAuth2\nutility library, for Node.js, Browsers and written in Typescript.\n\nThis library supports the following features:\n\n* 9KB minified (3KB gzipped).\n* No dependencies.\n* `authorization_code` grant with optional [PKCE][1] support.\n* `password` and `client_credentials` grant.\n* a `fetch()` wrapper that automatically adds Bearer tokens and refreshes them.\n* OAuth2 endpoint discovery via the Server metadata document ([RFC8414][2]).\n* OAuth2 Token Introspection ([RFC7662][3]).\n\n\n## Installation\n\n```sh\nnpm i fetch-mw-oauth2\n```\n\n\n## Usage\n\nTo get started, set up the Client class.\n\n\n```typescript\nimport { OAuth2Client } from 'fetch-mw-oauth2';\n\nconst client = new OAuth2Client({\n\n  // The base URI of your OAuth2 server\n  server: 'https://my-auth-server/',\n\n  // OAuth2 client id\n  clientId: '...',\n\n  // OAuth2 client secret. Only required for 'client_credentials', 'password'\n  // flows. You should not specify this for authorization_code.\n  clientSecret: '...',\n\n\n  // The following URIs are all optional. If they are not specified, we will\n  // attempt to discover them using the oauth2 discovery document.\n  // If your server doesn't have support this, you may need to specify these.\n  // you may use relative URIs for any of these.\n\n\n  // Token endpoint. Most flows need this.\n  // If not specified we'll use the information for the discovery document\n  // first, and otherwise default to /token\n  tokenEndpoint: '/token',\n\n  // Authorization endpoint.\n  //\n  // You only need this to generate URLs for authorization_code flows.\n  // If not specified we'll use the information for the discovery document\n  // first, and otherwise default to /authorize\n  authorizationEndpoint: '/authorize',\n\n  // OAuth2 Metadata discovery endpoint.\n  //\n  // This document is used to determine various server features.\n  // If not specified, we assume it's on /.well-known/oauth2-authorization-server\n  discoveryEndpoint: '/.well-known/oauth2-authorization-server',\n\n});\n```\n\n### Tokens\n\nMany functions use or return a 'OAuth2Token' type. This type has the following\nshape:\n\n```typescript\nexport type OAuth2Token = {\n  accessToken: string;\n  refreshToken: string | null;\n\n  /**\n   * When the Access Token expires.\n   *\n   * This is expressed as a unix timestamp in milliseconds.\n   */\n  expiresAt: number | null;\n\n};\n```\n\n\n### client_credentials grant.\n\n```typescript\nconst token = await client.clientCredentials();\n```\n\n### Refreshing tokens\n\n```typescript\nconst newToken = await client.refresh(oldToken);\n```\n\n\n### password grant:\n\n```typescript\nconst token = await client.password({\n  username: '..',\n  password: '..',\n});\n```\n\n### authorization_code\n\nThe `authorization_code` flow is the flow for browser-based applications,\nand roughly consists of 3 major steps:\n\n1. Redirect the user to an authorization endpoint, where they log in.\n2. Authorization endpoint redirects back to app with a 'code' query\n   parameter.\n3. The `code` is exchanged for a access and refresh token.\n\nThis library provides support for these steps, but there's no requirement\nto use its functionality as the system is mostly stateless.\n\n```typescript\nimport { OAuth2Client, generateCodeVerifier } from 'client';\n\nconst client = new OAuth2Client({\n  server: 'https://authserver.example/',\n  clientId: '...',\n\n  // Note, if urls cannot be auto-detected, also specify these:\n  tokenEndpoint: '/token',\n  authorizationEndpoint: '/authorize',\n});\n```\n\n**Redirecting the user to the authorization server**\n\n```typescript\n\n/**\n * This generates a security code that must be passed to the various steps.\n * This is used for 'PKCE' which is an advanced security feature.\n *\n * It doesn't break servers that don't support it, but it makes servers that\n * so support it more secure.\n *\n * It's optional to pass this, but recommended.\n */\nconst codeVerifier = await generateCodeVerifier():\n\n// In a browser this might work as follows:\ndocument.location = await authorizationCode.authorizationCode.getAuthorizeUri({\n\n  // URL in the app that the user should get redirected to after authenticating\n  redirectUri: 'https://my-app.example/',\n\n  // Optional string that can be sent along to the auth server. This value will\n  // be sent along with the redirect back to the app verbatim.\n  state: 'some-string',\n\n  codeVerifier,\n\n});\n```\n\n**Handling the redirect back to the app and obtain token**\n\n```typescript\nconst oauth2Token = await client.authorizationCode.getTokenFromCodeRedirect(\n  document.location,\n  {\n    /**\n     * The redirect URI is not actually used for any redirects, but MUST be the\n     * same as what you passed earlier to \"authorizationCode\"\n     */\n    redirectUri: 'https://my-app.example/',\n\n    /**\n     * This is optional, but if it's passed then it also MUST be the same as\n     * what you passed in the first step.\n     *\n     * If set, it will verify that the server sent the exact same state back.\n     */\n    state: 'some-string',\n\n    codeVerifier,\n\n  }\n);\n\nconst oauth2Token = await authorizationCode.getToken(codeResponse);\n```\n\n\n### Fetch Wrapper\n\nWhen using an OAuth2-protected API, typically you will need to obtain an Access\ntoken, and then add this token to each request using an `Authorization: Bearer`\nheader.\n\nBecause access tokens have a limited lifetime, and occasionally needs to be\nrefreshed this is a bunch of potential plumbing.\n\nTo make this easier, this library has a 'fetch wrapper'. This is effectively\njust like a regular fetch function, except it automatically adds the header\nand will automatically refresh tokens when needed.\n\nUsage:\n\n```typescript\nimport { OAuth2Client, OAuth2Fetch } from 'fetch-mw-oauth2';\n\nconst client = new OAuth2Client({\n  server: 'https://my-auth-server',\n  clientId: 'my-client-id'\n});\n\n\nconst fetchWrapper = new OAuth2Fetch({\n  client: client,\n\n  /**\n   * You are responsible for implementing this function.\n   * it's purpose is to supply the 'intitial' oauth2 token.\n   */\n  getNewToken: async () => {\n\n    // Example\n    return client.clientCredentials();\n\n    // Another example\n    return client.authorizationCode({\n      code: '..',\n      redirectUri: '..',\n    });\n\n    // You can return null to fail the process. You may want to do this\n    // when a user needs to be redirected back to the authorization_code\n    // endpoints.\n    return null;\n\n  },\n\n  /**\n   * Optional. This will be called for any fatal authentication errors.\n   */\n  onError: (err) => {\n    // err is of type Error\n  }\n\n});\n```\n\nAfter set up, you can just call `fetch` on the new object ot call your API, and\nthe library will ensure there's always a `Bearer` header.\n\n```typescript\nconst response = fetchWrapper.fetch('https://my-api', {\n  method: 'POST',\n  body: 'Hello world'\n});\n```\n\n### Storing tokens for later use with FetchWrapper\n\nTo keep a user logged in between sessions, you may want to avoid full\nreauthentication. To do this, you'll need to store authentication token.\n\nThe fetch wrapper has 2 functions to help with this:\n\n```typescript\n\nconst fetchWrapper = new OAuth2Fetch({\n  client: client,\n\n  getNewToken: async () => {\n\n    // See above!\n\n  },\n\n  /**\n   * This function is called whenever the active token changes. Using this is\n   * optional, but it may be used to (for example) put the token in off-line\n   * storage for later usage.\n   */\n  storeToken: (token) => {\n    document.localStorage.setItem('token-store', JSON.stringify(token));\n  }\n\n  /**\n   * Also an optional feature. Implement this if you want the wrapper to try a\n   * stored token before attempting a full reauthentication.\n   *\n   * This function may be async. Return null if there was no token.\n   */\n  getStoredToken: () => {\n    const token = document.localStorage.getItem('token-store');\n    if (token) return JSON.parse(token);\n    return null;\n  }\n\n});\n```\n\n\n### Fetch Middleware function\n\nIt might be preferable to use this library as a more traditional 'middleware'.\n\nThe OAuth2Fetch object also exposes a `mw` function that returns a middleware\nfor fetch.\n\n```typescript\nconst mw = oauth2.mw();\nconst response = mw(\n  myRequest,\n  req => fetch(req)\n);\n```\n\nThis syntax looks a bit wild if you're not used to building middlewares, but\nthis effectively allows you to 'decorate' existing request libraries with\nfunctionality from this oauth2 library.\n\nA real example using the [Ketting](https://github.com/badgateway/ketting)\nlibrary:\n\n```typescript\nimport { Client } from 'ketting';\nimport { OAuth2Client, OAuth2Fetch } from 'fetch-mw-oauth2';\n\n/**\n * Create the oauth2 client\n */\nconst oauth2Client = new OAuth2Client({\n  server: 'https://my-auth.example',\n  clientId: 'foo',\n});\n\n/**\n * Create the 'fetch helper'\n */\nconst oauth2Fetch = new OAuth2Fetch({\n  client: oauth2Client,\n});\n\n/**\n * Add the middleware to Ketting\n */\nconst ketting = new Client('http://api-root');\nketting.use(oauth2Fetch.mw());\n```\n\n### Introspection\n\nIntrospection ([RFC7662][3]) lets you find more information about a token,\nsuch as whether it's valid, which user it belongs to, which oauth2 client\nwas used to generate it, etc.\n\nTo be able to use it, your authorization server must have support for the\nintrospection endpoint. It's location will be automatically detected using\nthe Metadata discovery document.\n\n```typescript\nimport { OAuth2Client } from 'fetch-mw-oauth2';\n\nconst client = new Client({\n  server: 'https://auth-server.example/',\n\n  clientId: '...',\n\n  /**\n   * Some servers require OAuth2 clientId/clientSecret to be passed.\n   * If they require it, specify it. If not it's fine to omit.\n   */\n  clientSecret: '...',\n\n});\n\n// Get a token\nconst token = client.clientCredentials();\n\n// Introspect!\nconsole.log(client.introspect(token));\n```\n\n\n## Support for older Node versions\n\nThis package works out of the box with modern browsers and Node 18.\n\nTo use this package with Node 16, you need to run:\n\n```sh\nnpm i node-fetch@2\n```\n\nVersion 2 is required, because version 3 has been rewritten in a non-backwards\ncompatible way with ESM.\n\nAfter installing node-fetch, it must be registered globally:\n\n```javascript\nif (!global.fetch) {\n  const nodeFetch = require('node-fetch');\n  global.fetch = nodeFetch;\n  global.Headers = nodeFetch.Headers;\n  global.Request = nodeFetch.Request;\n  global.Response = nodeFetch.Response;\n}\n```\n\nOn Node 14.x you also need the following polyfill:\n\n```javascript\n// For Node 14.x and below\nif (global.btoa === undefined) {\n  global.btoa = input => {\n    return Buffer.from(input).toString('base64');\n  };\n}\n```\n\n[1]: https://datatracker.ietf.org/doc/html/rfc7636 \"Proof Key for Code Exchange by OAuth Public Clients\"\n[2]: https://datatracker.ietf.org/doc/html/rfc8414 \"OAuth 2.0 Authorization Server Metadata\"\n[3]: https://datatracker.ietf.org/doc/html/rfc7662 \"OAuth 2.0 Token Introspection\"\n","readmeFilename":"README.md","gitHead":"077adef058824185fe5841ac0b1b1f948e067be5","_id":"fetch-mw-oauth2@2.0.11","_nodeVersion":"18.1.0","_npmVersion":"8.8.0","dist":{"integrity":"sha512-fWYMjwV8tl9E6zCX0sXMn5BYRt8QU1F2OPFxD9S4j90PcKf4T9Kf0x9cvJBfFqD0GnS0bmjgJ9Eu1jOcfjSfjA==","shasum":"3c6fdcdfe5dc80b78259a8a57cfe13f9738d32c2","tarball":"https://registry.npmjs.org/fetch-mw-oauth2/-/fetch-mw-oauth2-2.0.11.tgz","fileCount":46,"unpackedSize":149322,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCYy6XlqRkQGP5txtmcfabCmXyw4E58zz1YCkO/hvlGNgIgNizGzc7cCT3vqinv3NuK6sKRmAk6L+ZwhOojx+jbh/s="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJig+4tACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoorBAAl2mx7PVRKJfO1fKv7Z9ju48SFWFXuu50QPRxYGqi90bxNjcX\r\nCuc8qmZYl1xLOAi91K3YLr79hmVpJ5P0zgAwM6I/Vilqa6cuQQjc/7aOaTGO\r\nOzDoByFy+lKSFbQfpt8rgA4n6jZvqqUsc/MZ80JTLQTKql/vHDTwGUinnFWH\r\nE7ogqn4Gpb+SNGF/wriYJ1MhnSrRwZUJIra6dvWV/2E0bWlv999KuZN7s3KX\r\nsN0eTIryNSRoEMaUoPbvt8ONsEpVXIL8GyphBjhNB/BpeMWhzd1XB0259fEr\r\nS8/a/dN+9ks/lR3iA9UY1Mzds89uD0zMuxYBaTwMX6hi/VorSJX1LtNwKmiS\r\nNiqRZ2LfmtgxFhQFry8gMCbfRungWdm7RhK+ENEBvJwMjS7Ej9+zGFuvDl4r\r\np64L5C/c84sLaeaVLnKrRi8F2fOadmBvKAqkThr8ZR97pB/3bQVPELKHtBDT\r\nu+Aqbx9r54c9kPGeCiS+S/mRIqiM5UIOoef89ShgkVJgeMdlKobIKSbyX62y\r\njOT8fBmCU1m9VLDAY5K/RNtFF2nDhje87GpnxSnK02A722SUxbx4du8TAD7x\r\n0lSQAbnf25I0HbW6enmTzi9bv/HFCZW5yVS4tO71foR7P7arBTToiw1b1ZzT\r\n5PC3gjD2fOJkl617U/uSlD59ww6sbbK+xPs=\r\n=KWZQ\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"evrt","email":"me@evertpot.com"},"directories":{},"maintainers":[{"name":"evrt","email":"me@evertpot.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fetch-mw-oauth2_2.0.11_1652813357344_0.3961124942784715"},"_hasShrinkwrap":false,"deprecated":"This package has been deprecated. v2 of this library has been renamed to @badgateway/oauth2-client"},"1.0.1":{"name":"fetch-mw-oauth2","version":"1.0.1","description":"Fetch middleware to add OAuth2 support","main":"dist/index.js","scripts":{"test":"make test lint","prepublishOnly":"make build"},"repository":{"type":"git","url":"git+ssh://git@github.com/badgateway/fetch-mw-oauth2.git"},"keywords":["fetch","oauth2"],"author":{"name":"Evert Pot","url":"https://evertpot.com"},"license":"MIT","bugs":{"url":"https://github.com/badgateway/fetch-mw-oauth2/issues"},"homepage":"https://github.com/badgateway/fetch-mw-oauth2#readme","devDependencies":{"@types/node":"^12.20.36","@typescript-eslint/eslint-plugin":"^5.2.0","@typescript-eslint/parser":"^5.2.0","eslint":"^8.1.0","node-fetch":"^3.0.0","ts-loader":"^9.2.6","typescript":"^4.4.4","webpack":"^5.60.0","webpack-cli":"^4.9.1"},"browser":"browser/fetch-mw-oauth2.min.js","types":"./dist/index.d.ts","gitHead":"25ab58a0d7b5a3669c4771b8968bceb6eacdc27b","_id":"fetch-mw-oauth2@1.0.1","_nodeVersion":"18.3.0","_npmVersion":"8.11.0","dist":{"integrity":"sha512-nyAgGM1FqVPFjiG38zYmX3LOpI8kFUb7oXbHcfhnz4441WFS8nu1/LqNwJ9JtWwZw4Fr1tJP+mjE7bCRFigzaQ==","shasum":"c1a15d045e699da401ee314c639293ce14fe0a33","tarball":"https://registry.npmjs.org/fetch-mw-oauth2/-/fetch-mw-oauth2-1.0.1.tgz","fileCount":48,"unpackedSize":150860,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIBXyAB89cevX23ye+jyiizp7jYTvun73Z9wICGYlm5X+AiEAwhG2qOQ9yGPKe+TEb9ERrz72gHafTpJuVsqPSeEI+Tw="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJir6dVACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqEsBAAoPxMb1Ko/scVeSGyt5XFtQMQTVuBuMkZT15qMPm9Jg3oqKjh\r\nP8N5/+Ih9R90cZDqGJyEUF7vFPS3REP7+gGlLO0F/ZL47rR1MfF8Oh+9s5Sw\r\ngjn9En32F7nj4pbZNoSPQ9MgsQxGDKpXkdvBthI+BGE2mnCQ2WfoC7eHQCfS\r\nwNAJAWHme3xvsAujBSNAy2MUYApcLWVJA/zqx5m0je0xzgZ0osgOE4Q4oPSV\r\n1cknRL+wqMQM6FMD6yM4iO8W6Ld3veg6Pw8YhsEyTPTk1UcorxfrfN7Sfdza\r\nvvF3qi1/VCXSQrk/tYvZfqNvxg6MgZFodlrzs4jkSQ9K+AU+jW5qJ7DuwBeR\r\nxOTov4iTXOtSWEzoLUuLZZPp9Qh8V7XoScNMa7W5ddCxWla7fwQrsxPAzPyS\r\nwnrjL/ZgZJG/2S/Gq1oCyKMONh1d2nZ3g+XhWgA8RImLYZacickcl2JrDjx3\r\nPRvU1yfgt6AF2FGAUkG3KAluY1McNXZWA23vFk4S8rsScmpfMEufJZZiICDm\r\nYsu9gZsEB4JjExhL5OJ8zIrAo7KPKjTe65fuW4/vMFy1K32HNfLPH7i4iO5d\r\n+4qny9pJq5OkvxdxhjRjqQBXQp5AI4Wn24mQ3nq9drBP8jUj/M7Fuqp7hFEK\r\nQ480c2YCQTiHec9xkhySWGtC8EPxgirSfHw=\r\n=XHz/\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"evrt","email":"me@evertpot.com"},"directories":{},"maintainers":[{"name":"evrt","email":"me@evertpot.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fetch-mw-oauth2_1.0.1_1655678805628_0.7410568803660846"},"_hasShrinkwrap":false,"deprecated":"This package has been deprecated. v2 of this library has been renamed to @badgateway/oauth2-client"},"1.0.2":{"name":"fetch-mw-oauth2","version":"1.0.2","description":"Fetch middleware to add OAuth2 support","main":"dist/index.js","scripts":{"test":"make test lint","prepublishOnly":"make build"},"repository":{"type":"git","url":"git+ssh://git@github.com/badgateway/fetch-mw-oauth2.git"},"keywords":["fetch","oauth2"],"author":{"name":"Evert Pot","url":"https://evertpot.com"},"license":"MIT","bugs":{"url":"https://github.com/badgateway/fetch-mw-oauth2/issues"},"homepage":"https://github.com/badgateway/fetch-mw-oauth2#readme","devDependencies":{"@types/node":"^12.20.36","@typescript-eslint/eslint-plugin":"^5.2.0","@typescript-eslint/parser":"^5.2.0","eslint":"^8.1.0","node-fetch":"^3.0.0","ts-loader":"^9.2.6","typescript":"^4.4.4","webpack":"^5.60.0","webpack-cli":"^4.9.1"},"browser":"browser/fetch-mw-oauth2.min.js","types":"./dist/index.d.ts","gitHead":"bc660417fc7529accc3fca5ff2164e24003b263d","_id":"fetch-mw-oauth2@1.0.2","_nodeVersion":"18.4.0","_npmVersion":"8.12.1","dist":{"integrity":"sha512-q++P/1vekmDR5kIOCyiTeovcPeZPznlC2C116Zs68AP/S1bTlmXOtfZBeG0rkqe/kMSQCkgyZI6AsOMtgsmLxA==","shasum":"c98b581b3ac018e4874240a04115c2ae8fae9860","tarball":"https://registry.npmjs.org/fetch-mw-oauth2/-/fetch-mw-oauth2-1.0.2.tgz","fileCount":34,"unpackedSize":70602,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDXbQ909o1tC5MnrdgJeCgTIQzAlKQrL5IDHg1P/6xq2gIhALQfWNEjaIySaktjJJkJObRqNhDiDmrPaMnc+rbHCgkJ"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJi0ZHGACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmqtqw//U/sBMAqFX0YzbbtFGa6lK9X+dbbAJxyLkcYst6dQxvDFMcgh\r\na8guyb0c935W1YzaJeVJTsPm/l8yY1d1QpuposoU9z/ISGxEF9GvgLvNZxkF\r\nQ8L/tg/i7OQ+9reIR2VAQZ/zKaxqDxP385fMU5i9sZL9tKssIEJKD8XbC7+D\r\nEJU8Mc6dbytJNVy+uH2oLr0e29lVUqHWYqcCmiSiATNWaJjH0ZzS3ZBviEys\r\nFbUdgu2aqCb12hSqGpM/24mAycQ03NxIuw8wxY5udjYOwPCpwprBOSX1jFIJ\r\nmywZuTnxdhBx9G/6fO7WPb7BrLDiZQMNzbwDfFTw12625J/au0/byT350vWL\r\nIEH6AsP34mdiXrt8oyrvcF3BrG6Fua0MxSe1GMjwD6GrTbPN33ZaYDxJt5UR\r\nRpU64w9S/FmljKJFTbQkJuEQ5MwiYC/WBoFKVhaXkY6hLTB6WAuENknV+Hvl\r\nrJkkToBACAZi8vIPwC0gVpeQKBWEwara8D8RYLMnhnAQcOid+FQ7jKiZyjDH\r\n1pGRzdLlhsz+kggofItx1Rj6sDNuV1osQiqspASQvv35qXzyYv2N5B6jXpq1\r\n0vy3LmkJMso63wuVgZPrcglYaEQmF9rsLdZW91BddufGAToUdBrCTqlfLKSJ\r\nUnqfVnxMt1ZrE+QO0Cs3AcbrybvtFA7Jvp4=\r\n=UCJw\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"evrt","email":"me@evertpot.com"},"directories":{},"maintainers":[{"name":"evrt","email":"me@evertpot.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fetch-mw-oauth2_1.0.2_1657901510268_0.1694334969490876"},"_hasShrinkwrap":false}},"time":{"created":"2019-03-11T20:48:32.570Z","0.1.0":"2019-03-11T20:48:32.782Z","modified":"2022-07-15T16:11:50.589Z","0.2.0":"2019-03-12T19:47:46.348Z","0.2.1":"2019-03-13T18:39:17.671Z","0.3.0":"2019-03-13T20:39:03.548Z","0.3.1":"2019-03-13T22:23:07.217Z","0.3.3":"2019-03-18T20:06:54.148Z","0.3.4":"2019-03-19T03:19:20.346Z","0.3.5":"2019-09-05T14:39:00.896Z","0.4.0":"2019-11-06T20:11:39.436Z","0.4.1":"2019-12-09T14:48:02.861Z","0.4.2":"2019-12-09T15:26:11.695Z","0.5.0":"2020-04-19T21:46:24.137Z","0.6.0":"2020-11-09T21:08:52.241Z","0.6.1":"2020-11-20T03:03:22.262Z","0.7.0":"2020-12-01T03:50:53.858Z","0.7.1":"2020-12-01T03:56:57.494Z","0.7.2":"2020-12-01T05:05:48.511Z","0.7.3":"2020-12-01T05:15:05.901Z","0.7.5":"2020-12-03T22:21:56.715Z","0.7.6":"2021-02-23T01:04:37.316Z","0.7.7":"2021-02-23T01:08:57.210Z","1.0.0":"2021-10-28T21:15:18.164Z","2.0.0":"2022-04-19T22:51:16.261Z","2.0.1":"2022-04-19T23:18:42.382Z","2.0.2":"2022-04-20T00:57:08.348Z","2.0.3":"2022-04-20T01:41:56.478Z","2.0.4":"2022-04-20T02:22:12.193Z","2.0.5":"2022-04-25T06:20:18.409Z","2.0.6":"2022-04-25T06:35:54.773Z","2.0.7":"2022-04-25T06:55:59.643Z","2.0.8":"2022-04-26T20:57:51.015Z","2.0.9":"2022-04-26T21:35:22.575Z","2.0.10":"2022-05-10T06:18:11.950Z","2.0.11":"2022-05-17T18:49:17.507Z","1.0.1":"2022-06-19T22:46:45.791Z","1.0.2":"2022-07-15T16:11:50.513Z"},"maintainers":[{"name":"evrt","email":"me@evertpot.com"}],"description":"Fetch middleware to add OAuth2 support","homepage":"https://github.com/badgateway/fetch-mw-oauth2#readme","keywords":["fetch","oauth2"],"repository":{"type":"git","url":"git+ssh://git@github.com/badgateway/fetch-mw-oauth2.git"},"author":{"name":"Evert Pot","url":"https://evertpot.com"},"bugs":{"url":"https://github.com/badgateway/fetch-mw-oauth2/issues"},"license":"MIT","readme":"# fetch-mw-oauth2\n\n_Note that v2 of this package has been renamed to `@badgateway/oauth2-client`. This\npackage has the same features (and more). v1 will receive some maintenance for the\nforseeable future, but uprading is strongly recommended._\n\nThis library adds support to OAuth2 to fetch by wrapping the fetch function.\nIt works both for `fetch()` in a browser, as well as [node-fetch][1].\n\n## Installation\n\n```sh\nnpm i fetch-mw-oauth2\n```\n\n## Usage\n\nThe `fetch-mw-oauth2` package effectively works as follows:\n\n1. You pass it OAuth2 instructions\n2. It returns an object with a new `fetch()` function.\n\nThis new `fetch()` function can now be used in place of the regular fetch,\nbut it takes responsibility of oauth2 authentication.\n\n### Setup with access and/or refresh token\n\nIf you already have an access and/or refresh token obtained through other\nmeans, you can set up the object as such:\n\n```javascript\nconst { OAuth2 } = require('fetch-mw-oauth2');\n\nconst oauth2 = new OAuth2({\n  clientId: '...',\n  clientSecret: '...', // Optional in some cases\n  tokenEndpoint: 'https://auth.example.org/token',\n}, {\n  accessToken: '...',\n  refreshToken: '...',\n});\n\nconst response = await oauth2.fetch('https://my-api.example.org/articles', {\n  method: 'POST',\n  body: 'Hello world',\n});\n```\n\nThe fetch function simply calls the javascript `fetch()` function but adds\nan `Authorization: Bearer ...` header.\n\n### Setup via authorization_code grant\n\n```javascript\nconst { OAuth2 } = require('fetch-mw-oauth2');\n\nconst oauth2 = new OAuth2({\n  grantType: 'authorization_code',\n  clientId: '...',\n  code: '...',\n  redirect_uri: 'https://my-app.example.org/cb',\n  tokenEndpoint: 'https://auth.example.org/token',\n  codeVerifier: '...' // If PKCE was used in authorization request\n});\n```\n\nThe library does not take responsibility for redirecting a user to an\nauthorization endpoint and redirecting back. That's up to you. After that's\ndone though, you should have a `code` variable that you can use to setup\nthe OAuth2 object.\n\n\n### Setup via 'password' grant\n\n```javascript\nconst { OAuth2 } = require('fetch-mw-oauth2');\n\nconst oauth2 = new OAuth2({\n  grantType: 'password',\n  clientId: '...',\n  clientSecret: '...',\n  userName: '...',\n  password: '...',\n  tokenEndpoint: 'https://auth.example.org/token',\n});\n```\n\n### Setup via 'client_credentials' grant\n\n```javascript\nconst { OAuth2 } = require('fetch-mw-oauth2');\n\nconst oauth2 = new OAuth2({\n  grantType: 'client_credentials',\n  clientId: '...',\n  clientSecret: '...',\n  tokenEndpoint: 'https://auth.example.org/token',\n});\n```\n\n## fetchMw function\n\nIt might be preferable to use this library as a more traditional 'middleware'.\n\nThe OAuth2 object also exposes a `fetchMw` function that takes 2 arguments:\n\n1. `request`\n2. `next`\n\nThe next argument is a function that also takes a request and returns a\nresponse.\n\nUsually you will want to use this with some kind of fetch middleware container,\nas such:\n\n```typescript\nmyFetchMiddleware(oauth2.fetchMw);\n```\n\nBut it's also possible to use it directly. For example:\n\n```typescript\noauth2.fetchMw(myRequest, innerRequest => fetch(innerRequest));\n```\n\n## Project status\n\nThe current features have been implemented:\n\n1. `client_credentials` grant-type support.\n2. `password` grant-type support.\n3. `authorization_code` grant-type support\n4. Automatically refreshing tokens\n\nThe following features are planned mid/long-term\n\n1. Supply an OAuth2 discovery document instead of authorization and token uris.\n2. `implicit` grant-type support\n\n[1]: https://www.npmjs.com/package/node-fetch\n","readmeFilename":"README.md"}