{"_id":"fusion-plugin-csrf-protection","_rev":"487-608d01488bf9266b18680984c753c4c8","name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","dist-tags":{"latest":"3.4.7","prerelease":"2.0.1-0","canary":"0.0.0-canary.ca778ef.0"},"versions":{"0.1.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.1.0","main":"./dist/node.cjs.js","module":"./dist/node.es.js","browser":{"./dist/node.cjs.js":"./dist/browser.cjs.js","./dist/node.es.js":"./dist/browser.es.js"},"es2015":{"./dist/node.cjs.js":"./dist/node.cjs.es2015.js","./dist/node.es.js":"./dist/node.es.es2015.js","./dist/browser.cjs.js":"./dist/browser.cjs.es2015.js","./dist/browser.es.js":"./dist/browser.es.es2015.js"},"dependencies":{"base64-url":"^2.0.0"},"devDependencies":{"babel-eslint":"^8.0.0","babel-plugin-transform-flow-strip-types":"^6.22.0","babel-preset-react":"6.24.1","body-parser":"^1.12.3","create-universal-package":"^1.0.0-rc.14","eslint":"^4.2.0","eslint-config-fusion":"^0.1.0","eslint-plugin-cup":"^1.0.0-rc.4","eslint-plugin-flowtype":"^2.35.0","eslint-plugin-prettier":"^2.1.2","eslint-plugin-react":"^7.1.0","express":"^4.8.2","fusion-plugin":"^0.1.0","generic-session":"^0.1.0","get-port":"^3.0.0","prettier":"1.4.2","sinon":"^4.0.0","tape-cup":"^4.7.1","unitest":"^1.0.0"},"peerDependencies":{"fusion-plugin":"^0.1.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","transpile":"npm run clean && cup build","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","prepublish":"npm run transpile"},"_id":"fusion-plugin-csrf-protection@0.1.0","_npmVersion":"5.5.1","_nodeVersion":"8.6.0","_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"dist":{"integrity":"sha512-7mC3sCiaesw3llL63QWAdsgt/4CdRHCWNwogtnMlDYQUmwahYcc1VFNAHMA0vzFeXl/wdmo4cZUmut1HBuMd9A==","shasum":"1a0745015304d23307e1e2c26b775f5b9fe24bcc","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.1.0.tgz","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDVApvgyRHN4InYD+EifsbUKR9x3WhxotY8hBucatBwVAIgYPrUeBHMF8WUYxYNrDUjf1fsJNzq3wiFV+0jL8gB/Zo="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection-0.1.0.tgz_1509479279391_0.02941639651544392"},"directories":{}},"0.1.1":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.1.1","files":["dist"],"main":"./dist/node.cjs.js","module":"./dist/node.es.js","browser":{"./dist/node.cjs.js":"./dist/browser.cjs.js","./dist/node.es.js":"./dist/browser.es.js"},"es2015":{"./dist/node.cjs.js":"./dist/node.cjs.es2015.js","./dist/node.es.js":"./dist/node.es.es2015.js","./dist/browser.cjs.js":"./dist/browser.cjs.es2015.js","./dist/browser.es.js":"./dist/browser.es.es2015.js"},"dependencies":{"base64-url":"^2.0.0"},"devDependencies":{"babel-eslint":"^8.0.0","babel-plugin-transform-flow-strip-types":"^6.22.0","babel-preset-react":"6.24.1","body-parser":"^1.12.3","create-universal-package":"^1.0.0-rc.14","eslint":"^4.2.0","eslint-config-fusion":"^0.1.0","eslint-plugin-cup":"^1.0.0-rc.4","eslint-plugin-flowtype":"^2.35.0","eslint-plugin-prettier":"^2.1.2","eslint-plugin-react":"^7.1.0","express":"^4.8.2","fusion-plugin":"^0.1.1","generic-session":"^0.1.0","get-port":"^3.0.0","prettier":"1.4.2","sinon":"^4.0.0","tape-cup":"^4.7.1","unitest":"^1.0.0"},"peerDependencies":{"fusion-plugin":"^0.1.1"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","transpile":"npm run clean && cup build","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","prepublish":"npm run transpile"},"_id":"fusion-plugin-csrf-protection@0.1.1","_npmVersion":"5.5.1","_nodeVersion":"8.6.0","_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"dist":{"integrity":"sha512-PhHBnXXLfpv0mUYJNP8lKeLiUJo9SrthguwoLss06ozaNjPtDsHUopWIQmVV1AkIlyyiTuN7hdrZmtnMCYvgOg==","shasum":"51e3cd37ea2797c28391b0f1df32be90d4d04857","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.1.1.tgz","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQC+tccu3QVOq9uEcnXn5IrhubBYtFJ5h1/yXMGpRbqlPgIhAK9nltl051Zp0pBheHLT3lpGLS6ZTjSQ0jwMvwymvyzO"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection-0.1.1.tgz_1509481522576_0.2029666716698557"},"directories":{}},"0.1.2":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"type":"git","url":"git+https://github.com/fusionjs/fusion-plugin-csrf-protection.git"},"version":"0.1.2","files":["dist"],"main":"./dist/node.cjs.js","module":"./dist/node.es.js","browser":{"./dist/node.cjs.js":"./dist/browser.cjs.js","./dist/node.es.js":"./dist/browser.es.js"},"es2015":{"./dist/node.cjs.js":"./dist/node.cjs.es2015.js","./dist/node.es.js":"./dist/node.es.es2015.js","./dist/browser.cjs.js":"./dist/browser.cjs.es2015.js","./dist/browser.es.js":"./dist/browser.es.es2015.js"},"dependencies":{"base64-url":"^2.0.0"},"devDependencies":{"babel-eslint":"^8.0.0","babel-plugin-transform-flow-strip-types":"^6.22.0","babel-preset-react":"6.24.1","body-parser":"^1.12.3","create-universal-package":"^1.0.0-rc.14","eslint":"^4.2.0","eslint-config-fusion":"^0.1.2","eslint-plugin-cup":"^1.0.0-rc.4","eslint-plugin-flowtype":"^2.35.0","eslint-plugin-prettier":"^2.1.2","eslint-plugin-react":"^7.1.0","express":"^4.8.2","fusion-core":"^0.1.2","generic-session":"^0.1.0","get-port":"^3.0.0","prettier":"1.4.2","sinon":"^4.0.0","tape-cup":"^4.7.1","unitest":"^1.0.0"},"peerDependencies":{"fusion-core":"^0.1.2"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","transpile":"npm run clean && cup build","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","prepublish":"npm run transpile"},"bugs":{"url":"https://github.com/fusionjs/fusion-plugin-csrf-protection/issues"},"homepage":"https://github.com/fusionjs/fusion-plugin-csrf-protection#readme","_id":"fusion-plugin-csrf-protection@0.1.2","_npmVersion":"5.5.1","_nodeVersion":"8.6.0","_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"dist":{"integrity":"sha512-j7HzP1+uI5WCZPs5qWsF1bcalUYSYw8xK+YrwyaWCFFhcpT4GhbXA/Rp97/2p07VgxT7JzW0jFKDLxspu8CXBA==","shasum":"dc0f2e67f1fb9e60afd1aae525cb44d373c3d258","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.1.2.tgz","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIH1b9Mj5QmsKvyp3POnHQM+sO8WLsk+DqQrCV/R7264UAiEA10BIimdJBY5j4zP/gAooyM+hNePd4EHK5MM7UYlY4gc="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection-0.1.2.tgz_1509495185386_0.1158995209261775"},"directories":{}},"0.1.3":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"type":"git","url":"git+https://github.com/fusionjs/fusion-plugin-csrf-protection.git"},"version":"0.1.3","files":["dist"],"main":"./dist/node.cjs.js","module":"./dist/node.es.js","browser":{"./dist/node.cjs.js":"./dist/browser.cjs.js","./dist/node.es.js":"./dist/browser.es.js"},"es2015":{"./dist/node.cjs.js":"./dist/node.cjs.es2015.js","./dist/node.es.js":"./dist/node.es.es2015.js","./dist/browser.cjs.js":"./dist/browser.cjs.es2015.js","./dist/browser.es.js":"./dist/browser.es.es2015.js"},"dependencies":{"base64-url":"^2.0.0"},"devDependencies":{"babel-eslint":"^8.0.0","babel-plugin-transform-flow-strip-types":"^6.22.0","babel-preset-react":"6.24.1","body-parser":"^1.12.3","create-universal-package":"^1.0.0-rc.14","eslint":"^4.2.0","eslint-config-fusion":"^0.1.2","eslint-plugin-cup":"^1.0.0-rc.4","eslint-plugin-flowtype":"^2.35.0","eslint-plugin-prettier":"^2.1.2","eslint-plugin-react":"^7.1.0","express":"^4.8.2","fusion-core":"^0.1.3","generic-session":"^0.1.0","get-port":"^3.0.0","prettier":"1.4.2","sinon":"^4.0.0","tape-cup":"^4.7.1","unitest":"^1.0.0"},"peerDependencies":{"fusion-core":"^0.1.3"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","transpile":"npm run clean && cup build","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","prepublish":"npm run transpile"},"bugs":{"url":"https://github.com/fusionjs/fusion-plugin-csrf-protection/issues"},"homepage":"https://github.com/fusionjs/fusion-plugin-csrf-protection#readme","_id":"fusion-plugin-csrf-protection@0.1.3","_npmVersion":"5.5.1","_nodeVersion":"8.6.0","_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"dist":{"integrity":"sha512-Mb1zHsXrPP2+hyJU+HSiucL6webtOJWpT/1wOv9wfVjeWlJRaWrECQpc8YN480+PpfQkz5y+ojh98rKWyjM2OA==","shasum":"3bf1d5a5ac07e0aeae0a37bc1e575cb8e6a889f6","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.1.3.tgz","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIH/pvIY4wPj/tCXeYIPFHHONpHLx+K/I3k6/Nlx4NX/CAiA3ZWgm6xRpHuKCPgpEc0bFtY0J/zQCv3QpmjP2KgjVHA=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection-0.1.3.tgz_1509499783818_0.03285123687237501"},"directories":{}},"0.1.4":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"type":"git","url":"git+https://github.com/fusionjs/fusion-plugin-csrf-protection.git"},"version":"0.1.4","files":["dist"],"main":"./dist/node.cjs.js","module":"./dist/node.es.js","browser":{"./dist/node.cjs.js":"./dist/browser.cjs.js","./dist/node.es.js":"./dist/browser.es.js"},"es2015":{"./dist/node.cjs.js":"./dist/node.cjs.es2015.js","./dist/node.es.js":"./dist/node.es.es2015.js","./dist/browser.cjs.js":"./dist/browser.cjs.es2015.js","./dist/browser.es.js":"./dist/browser.es.es2015.js"},"dependencies":{"base64-url":"^2.0.0"},"devDependencies":{"babel-eslint":"^8.0.0","babel-plugin-transform-flow-strip-types":"^6.22.0","babel-preset-react":"6.24.1","body-parser":"^1.12.3","create-universal-package":"^1.0.0-rc.14","eslint":"^4.2.0","eslint-config-fusion":"^0.1.2","eslint-plugin-cup":"^1.0.0-rc.4","eslint-plugin-flowtype":"^2.35.0","eslint-plugin-prettier":"^2.1.2","eslint-plugin-react":"^7.1.0","express":"^4.8.2","fusion-core":"^0.1.4","generic-session":"^0.1.0","get-port":"^3.0.0","prettier":"1.4.2","sinon":"^4.0.0","tape-cup":"^4.7.1","unitest":"^1.0.0"},"peerDependencies":{"fusion-core":"^0.1.4"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","transpile":"npm run clean && cup build","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","prepublish":"npm run transpile"},"engines":{"node":">= 8.9.0"},"bugs":{"url":"https://github.com/fusionjs/fusion-plugin-csrf-protection/issues"},"homepage":"https://github.com/fusionjs/fusion-plugin-csrf-protection#readme","_id":"fusion-plugin-csrf-protection@0.1.4","_npmVersion":"5.5.1","_nodeVersion":"8.9.0","_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"dist":{"integrity":"sha512-OKt7Nx7yHM/tfDR82oIgLZ1CAq8+b+UblNnexUaZOSAcefSgAjYpfN7O5bRQWeFSzgM+U8s48sTKQ6AlnOavpA==","shasum":"332f85fedf750fc4ed961219ebef092ad755815a","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.1.4.tgz","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDkeGFBlErz2MO0leQyadBd3xlTgqbJ4E7+V/Cb0sTZqAIgeV3jrOkrQGP49TM6PPYKb0U5n075r7UFCZOud7M0+cA="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection-0.1.4.tgz_1509565706696_0.752285928465426"},"directories":{}},"0.1.8":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"type":"git","url":"git+https://github.com/fusionjs/fusion-plugin-csrf-protection.git"},"version":"0.1.8","files":["dist"],"main":"./dist/node.cjs.js","module":"./dist/node.es.js","browser":{"./dist/node.cjs.js":"./dist/browser.cjs.js","./dist/node.es.js":"./dist/browser.es.js"},"es2015":{"./dist/node.cjs.js":"./dist/node.cjs.es2015.js","./dist/node.es.js":"./dist/node.es.es2015.js","./dist/browser.cjs.js":"./dist/browser.cjs.es2015.js","./dist/browser.es.js":"./dist/browser.es.es2015.js"},"dependencies":{"base64-url":"^2.0.0"},"devDependencies":{"babel-eslint":"^8.0.0","babel-plugin-transform-flow-strip-types":"^6.22.0","babel-preset-react":"6.24.1","body-parser":"^1.12.3","create-universal-package":"^1.0.0-rc.14","eslint":"^4.2.0","eslint-config-fusion":"^0.1.2","eslint-plugin-cup":"^1.0.0-rc.4","eslint-plugin-flowtype":"^2.35.0","eslint-plugin-prettier":"^2.1.2","eslint-plugin-react":"^7.1.0","express":"^4.8.2","fusion-core":"^0.1.8","generic-session":"^0.1.0","get-port":"^3.0.0","prettier":"1.4.2","sinon":"^4.0.0","tape-cup":"^4.7.1","unitest":"^1.0.0"},"peerDependencies":{"fusion-core":"^0.1.8"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","transpile":"npm run clean && cup build","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","prepublish":"npm run transpile"},"engines":{"node":">= 8.9.0"},"bugs":{"url":"https://github.com/fusionjs/fusion-plugin-csrf-protection/issues"},"homepage":"https://github.com/fusionjs/fusion-plugin-csrf-protection#readme","_id":"fusion-plugin-csrf-protection@0.1.8","_shasum":"4501b1309a1a4f38825f350077eabe51f7c51b10","_from":".","_npmVersion":"3.10.10","_nodeVersion":"8.9.0","_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"dist":{"shasum":"4501b1309a1a4f38825f350077eabe51f7c51b10","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.1.8.tgz","integrity":"sha512-Bci7uE9XDRvDV36yjDFXrnxhAkAoviH3GU4EmqlWHufqpi0v48NLWCeyCxQutikMFZSDLE+VCLXZsNqQckkvSA==","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDDeZkkI02yB2kfFQUiaabX4qHbg8yW6+zs9aAYh5lyrAIhAKHi4B0jICPLFqp2kMnT6JduFTh1HD3VuD4VtdYTjKq3"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection-0.1.8.tgz_1509675489791_0.061023757327347994"},"directories":{}},"0.2.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"type":"git","url":"git+https://github.com/fusionjs/fusion-plugin-csrf-protection.git"},"version":"0.2.0","files":["dist"],"main":"./dist/node.cjs.js","module":"./dist/node.es.js","browser":{"./dist/node.cjs.js":"./dist/browser.cjs.js","./dist/node.es.js":"./dist/browser.es.js"},"es2015":{"./dist/node.cjs.js":"./dist/node.cjs.es2015.js","./dist/node.es.js":"./dist/node.es.es2015.js","./dist/browser.cjs.js":"./dist/browser.cjs.es2015.js","./dist/browser.es.js":"./dist/browser.es.es2015.js"},"dependencies":{"base64-url":"^2.0.0"},"devDependencies":{"babel-eslint":"^8.0.0","babel-plugin-transform-flow-strip-types":"^6.22.0","babel-preset-react":"6.24.1","body-parser":"^1.12.3","create-universal-package":"^1.0.0-rc.14","eslint":"^4.2.0","eslint-config-fusion":"^0.1.2","eslint-plugin-cup":"^1.0.0-rc.4","eslint-plugin-flowtype":"^2.35.0","eslint-plugin-prettier":"^2.1.2","eslint-plugin-react":"^7.1.0","express":"^4.8.2","fusion-core":"^0.1.4","generic-session":"^0.1.0","get-port":"^3.0.0","prettier":"1.4.2","sinon":"^4.0.0","tape-cup":"^4.7.1","unitest":"^1.0.0"},"peerDependencies":{"fusion-core":"^0.1.4"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","transpile":"npm run clean && node_modules/.bin/cup build","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","prepublish":"npm run transpile"},"engines":{"node":">= 8.9.0"},"gitHead":"8d5d82ed1114f7a43e95b83f092fbf52df33bc48","bugs":{"url":"https://github.com/fusionjs/fusion-plugin-csrf-protection/issues"},"homepage":"https://github.com/fusionjs/fusion-plugin-csrf-protection#readme","_id":"fusion-plugin-csrf-protection@0.2.0","_npmVersion":"5.5.1","_nodeVersion":"8.9.0","_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"dist":{"integrity":"sha512-I9FcRa/cRzKiFQbM1Q7IK7r/FyCGzjk0hG4dYpaf1ToUtrmZBUwoU+sZsfYRVPDaGPtaTHLe+I9F71wFOruhzg==","shasum":"f8e4ad728934328ebdff7900a56e6e556b9dd24f","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.2.0.tgz","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCe4/0ARjHnUrcFg1CnzhLO2hGwGpbvnXFVo8bQw1TQjgIhAOsSXRbGer0RYjKxslVKh3CdSsriXQ0EpQCenP+U9IfI"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection-0.2.0.tgz_1509759332709_0.31765871471725404"},"directories":{}},"0.2.1":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"type":"git","url":"git+https://github.com/fusionjs/fusion-plugin-csrf-protection.git"},"version":"0.2.1","files":["dist"],"main":"./dist/node.cjs.js","module":"./dist/node.es.js","browser":{"./dist/node.cjs.js":"./dist/browser.es5.cjs.js","./dist/node.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.cjs.js":"./dist/browser.es2015.cjs.js","./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.cjs.js":"./dist/browser.es2017.cjs.js","./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.cjs.js":"./dist/browser.es2017.cjs.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.0.1"},"devDependencies":{"babel-eslint":"^8.0.2","@babel/plugin-transform-flow-strip-types":"^7.0.0-beta.32","@babel/preset-react":"7.0.0-beta.32","body-parser":"^1.18.2","create-universal-package":"^2.1.1","eslint":"^4.11.0","eslint-config-fusion":"^0.1.2","eslint-plugin-cup":"^1.0.0","eslint-plugin-flowtype":"^2.39.1","eslint-plugin-prettier":"^2.3.1","eslint-plugin-react":"^7.4.0","express":"^4.16.2","fusion-core":"^0.2.3","generic-session":"^0.1.2","get-port":"^3.2.0","prettier":"1.8.2","sinon":"^4.1.2","tape-cup":"^4.7.1","unitest":"^1.1.0"},"peerDependencies":{"fusion-core":"^0.2.3"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","transpile":"npm run clean && cup build","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","prepublish":"npm run transpile"},"engines":{"node":">= 8.9.0"},"gitHead":"5b5ce58ee84e59b3c69d28e54a251c32abea6809","bugs":{"url":"https://github.com/fusionjs/fusion-plugin-csrf-protection/issues"},"homepage":"https://github.com/fusionjs/fusion-plugin-csrf-protection#readme","_id":"fusion-plugin-csrf-protection@0.2.1","_npmVersion":"5.5.1","_nodeVersion":"8.9.0","_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"dist":{"integrity":"sha512-LQGhc2PcEkc/HuE7p/4KARLBK+chFq7etmV66ii5dvT28ELOEedlPhZeR6Su1vR5/xt8A7C30ziP6chF2EDN+w==","shasum":"8de15e39b4b4f6ec3cf42113bbcc6478458a099c","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.2.1.tgz","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCm0dJkpwxlIEKA5Hf4arfbqp7IOkC7ooy7WWCdKZRvCAIgItlNhJQFSDggQLPFc5YLxBsCDbDDDISPIw45tnEiXAw="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection-0.2.1.tgz_1510781637047_0.5036565426271409"},"directories":{}},"0.2.2":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"type":"git","url":"git+https://github.com/fusionjs/fusion-plugin-csrf-protection.git"},"version":"0.2.2","files":["dist"],"main":"./dist/node.cjs.js","module":"./dist/node.es.js","browser":{"./dist/node.cjs.js":"./dist/browser.es5.cjs.js","./dist/node.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.cjs.js":"./dist/browser.es2015.cjs.js","./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.cjs.js":"./dist/browser.es2017.cjs.js","./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.cjs.js":"./dist/browser.es2017.cjs.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.0.1"},"devDependencies":{"@babel/plugin-transform-flow-strip-types":"^7.0.0-beta.32","@babel/preset-react":"7.0.0-beta.32","babel-eslint":"^8.0.2","body-parser":"^1.18.2","create-universal-package":"^2.1.1","eslint":"^4.11.0","eslint-config-fusion":"^0.1.2","eslint-plugin-cup":"^1.0.0","eslint-plugin-flowtype":"^2.39.1","eslint-plugin-prettier":"^2.3.1","eslint-plugin-react":"^7.4.0","express":"^4.16.2","flow-bin":"^0.59.0","fusion-core":"^0.2.3","fusion-test-utils":"^0.2.1","generic-session":"^0.1.2","get-port":"^3.2.0","nyc":"^11.3.0","prettier":"1.8.2","sinon":"^4.1.2","tape-cup":"^4.7.1","unitest":"^1.1.0"},"peerDependencies":{"fusion-core":"^0.2.3"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","transpile":"npm run clean && cup build","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run transpile"},"engines":{"node":">= 8.9.0"},"gitHead":"d4f8e9cbc29c1168e6ec425b54eae15b58d85144","bugs":{"url":"https://github.com/fusionjs/fusion-plugin-csrf-protection/issues"},"homepage":"https://github.com/fusionjs/fusion-plugin-csrf-protection#readme","_id":"fusion-plugin-csrf-protection@0.2.2","_npmVersion":"5.5.1","_nodeVersion":"8.9.0","_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"dist":{"integrity":"sha512-Rga5U1W53X5cErlrNJRMJB0qs8bX57e2pg+zsCt9LDiFU4sywhIgswpEMR2stdR2xH4po4rSGgGhXjU7aRYvvQ==","shasum":"0cddcc1f4c10b521031b9cad8567fdb1a7eaf423","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.2.2.tgz","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDGHB/GHXiGyeY89937DgPJK4jgcd/lXUY/xfzIfosYbgIgNEGEp8qP5CpVFhjza8lY2dezbgXb8Ev3T5WlvCu1hc8="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection-0.2.2.tgz_1512759647395_0.9064953741617501"},"directories":{}},"0.3.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"type":"git","url":"git+https://github.com/fusionjs/fusion-plugin-csrf-protection.git"},"version":"0.3.0","files":["dist","src"],"main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.0.1"},"devDependencies":{"@babel/preset-react":"7.0.0-beta.38","babel-eslint":"^8.2.1","body-parser":"^1.18.2","create-universal-package":"^3.2.5","eslint":"^4.15.0","eslint-config-fusion":"^0.2.1","eslint-plugin-cup":"^1.0.0","eslint-plugin-flowtype":"^2.41.0","eslint-plugin-import":"^2.8.0","eslint-plugin-prettier":"^2.5.0","eslint-plugin-react":"^7.5.1","express":"^4.16.2","flow-bin":"^0.63.1","fusion-core":"^0.3.0-4","fusion-test-utils":"^0.4.0","fusion-tokens":"^0.0.4","generic-session":"^0.1.2","get-port":"^3.2.0","nyc":"^11.4.1","prettier":"1.10.2","sinon":"^4.1.6","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"^0.3.0-4","fusion-tokens":"^0.0.4"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","transpile":"npm run clean && cup build","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run transpile"},"engines":{"node":">= 8.9.0"},"gitHead":"5ac6088e45c83435a4222185f297ed5e8c7c3a18","bugs":{"url":"https://github.com/fusionjs/fusion-plugin-csrf-protection/issues"},"homepage":"https://github.com/fusionjs/fusion-plugin-csrf-protection#readme","_id":"fusion-plugin-csrf-protection@0.3.0","_npmVersion":"5.6.0","_nodeVersion":"8.9.4","_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"dist":{"integrity":"sha512-HQ5hzOPF0RfI2Cd3T5cH47Q1VxlHA8ZHf8LcwfC8mnTeOc0JTHTmAVyf65aX9wdfdotg1SWLq1Xl0cf0ZQHY+A==","shasum":"fa2cd0830aa0c99ca99a7ec1423f40cdf92f68e2","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.3.0.tgz","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIGKUFNYS7dszyv/X7eQWjbbASQY8Wu9nHJntQOvwr6CYAiEA4JBRhQCr/euNNeWmPxSnIKkECp1IGOUzUK3K9pdcX98="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection-0.3.0.tgz_1516227599127_0.35858903592452407"},"directories":{}},"0.3.1":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"type":"git","url":"git+https://github.com/fusionjs/fusion-plugin-csrf-protection.git"},"version":"0.3.1","files":["dist","src"],"main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.0.1"},"devDependencies":{"@babel/preset-react":"7.0.0-beta.38","babel-eslint":"8.2.1","body-parser":"1.18.2","create-universal-package":"3.2.6","eslint":"4.16.0","eslint-config-fusion":"0.2.1","eslint-plugin-cup":"1.0.0","eslint-plugin-flowtype":"2.42.0","eslint-plugin-import":"2.8.0","eslint-plugin-prettier":"2.5.0","eslint-plugin-react":"7.6.0","express":"4.16.2","flow-bin":"0.64.0","fusion-core":"0.3.0-5","fusion-test-utils":"0.4.2","fusion-tokens":"0.0.5","generic-session":"0.1.2","get-port":"3.2.0","nyc":"11.4.1","prettier":"1.10.2","sinon":"4.2.1","tape-cup":"4.7.1","unitest":"2.1.1"},"peerDependencies":{"fusion-core":"^0.3.0-5","fusion-tokens":"^0.0.5"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","transpile":"npm run clean && cup build","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run transpile"},"engines":{"node":">= 8.9.0"},"gitHead":"ee71b0bffead056cc10c2439e0d54b0713a0a1f9","bugs":{"url":"https://github.com/fusionjs/fusion-plugin-csrf-protection/issues"},"homepage":"https://github.com/fusionjs/fusion-plugin-csrf-protection#readme","_id":"fusion-plugin-csrf-protection@0.3.1","_npmVersion":"5.6.0","_nodeVersion":"8.9.4","_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"dist":{"integrity":"sha512-mLjPvf983qQ2h2tMI+9qvz55ylDwsypOG8R4ZrlENsWn+7fflgJs0oSQp6hM70IvQ0jhSHMREN8YCeAWRSlyGw==","shasum":"b4b117569669a16ce04b34ace7f1a58991e7a40f","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.3.1.tgz","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDAopRoZvQDhKHeMRySKM1jdulHpUwIJORKtYOJr+MYCAIhAJjM2PlUjgf88gKvEi1bwVxuEW3k9jWG94opBMHF8Qbt"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection-0.3.1.tgz_1517002410729_0.7153068108018488"},"directories":{}},"0.3.2":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"type":"git","url":"git+https://github.com/fusionjs/fusion-plugin-csrf-protection.git"},"version":"0.3.2","files":["dist","src"],"main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.1.0"},"devDependencies":{"@babel/preset-react":"7.0.0-beta.38","babel-eslint":"8.2.1","body-parser":"1.18.2","create-universal-package":"3.3.0","eslint":"4.16.0","eslint-config-fusion":"0.2.1","eslint-plugin-cup":"1.0.0","eslint-plugin-flowtype":"2.42.0","eslint-plugin-import":"^2.8.0","eslint-plugin-prettier":"2.5.0","eslint-plugin-react":"7.6.1","express":"4.16.2","flow-bin":"0.64.0","fusion-core":"0.3.0-5","fusion-test-utils":"0.4.2","fusion-tokens":"0.0.5","generic-session":"0.1.2","get-port":"3.2.0","nyc":"11.4.1","prettier":"1.10.2","sinon":"4.2.2","tape-cup":"4.7.1","unitest":"2.1.1"},"peerDependencies":{"fusion-core":"^0.3.0-5","fusion-tokens":"^0.0.5"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","transpile":"npm run clean && cup build","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run transpile"},"engines":{"node":">= 8.9.0"},"gitHead":"39211c859d972117cfbeeb280982a63578f17e27","bugs":{"url":"https://github.com/fusionjs/fusion-plugin-csrf-protection/issues"},"homepage":"https://github.com/fusionjs/fusion-plugin-csrf-protection#readme","_id":"fusion-plugin-csrf-protection@0.3.2","_npmVersion":"5.6.0","_nodeVersion":"8.9.4","_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"dist":{"integrity":"sha512-wTF91Goxme3o6oHnMEbewGD8atYBTljiF0/m1wkmKVW2uztdoCu3MXLOJOlpiCOMutG3VlvU2lOJQG5LtqtBMw==","shasum":"42c6419a25b866624ad5513642a508977f4de52f","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.3.2.tgz","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDyVZ+jzAylX+Sc1HR5Ugz+50OwGlG+NFFRtCe1+pmNNwIgcRSf8SgQ8CiOhNkPJhxFx2VKexxtjzgmn0YB6aNKYqA="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection-0.3.2.tgz_1517261224267_0.8990385835058987"},"directories":{}},"0.3.3":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"type":"git","url":"git+https://github.com/fusionjs/fusion-plugin-csrf-protection.git"},"version":"0.3.3","files":["dist","src"],"main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.1.0"},"devDependencies":{"@babel/preset-react":"7.0.0-beta.38","babel-eslint":"8.2.1","body-parser":"1.18.2","create-universal-package":"3.3.1","eslint":"4.16.0","eslint-config-fusion":"0.2.1","eslint-plugin-cup":"1.0.0","eslint-plugin-flowtype":"2.42.0","eslint-plugin-import":"^2.8.0","eslint-plugin-prettier":"2.5.0","eslint-plugin-react":"7.6.1","express":"4.16.2","flow-bin":"0.64.0","fusion-core":"0.3.0-5","fusion-test-utils":"0.4.2","fusion-tokens":"0.0.5","generic-session":"0.1.2","get-port":"3.2.0","nyc":"11.4.1","prettier":"1.10.2","sinon":"4.2.2","tape-cup":"4.7.1","unitest":"2.1.1"},"peerDependencies":{"fusion-core":"^0.3.0-5","fusion-tokens":"^0.0.5"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","transpile":"npm run clean && cup build","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run transpile"},"engines":{"node":">= 8.9.0"},"gitHead":"b1c6af37c695848f148fe9ebec5393999257ab97","bugs":{"url":"https://github.com/fusionjs/fusion-plugin-csrf-protection/issues"},"homepage":"https://github.com/fusionjs/fusion-plugin-csrf-protection#readme","_id":"fusion-plugin-csrf-protection@0.3.3","_npmVersion":"5.6.0","_nodeVersion":"8.9.4","_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"dist":{"integrity":"sha512-8njYpRJHEsRr3AlgHethjnOiN5sNVuNSPPFewCPtdejy96IeLpVIM8EOdT2qgGDGIa7LBn8vRU1I2mGdsm12Qw==","shasum":"04827486d29f55267e10fe29d8afaa06da1be68b","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.3.3.tgz","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIEbCYO4nbOH9DztsreQYK52Fh9Niton2rg87ztvp5z1RAiAx/N84kA7oi1Pke1f3SeY/Z9RoBtc0uFLcka44MsEXvA=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection-0.3.3.tgz_1517352683150_0.45470510865561664"},"directories":{}},"0.3.4":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"type":"git","url":"git+https://github.com/fusionjs/fusion-plugin-csrf-protection.git"},"version":"0.3.4","files":["dist","src"],"main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.1.0"},"devDependencies":{"@babel/preset-react":"7.0.0-beta.38","babel-eslint":"8.2.1","body-parser":"1.18.2","create-universal-package":"3.4.0","eslint":"4.16.0","eslint-config-fusion":"0.2.1","eslint-plugin-cup":"1.0.0","eslint-plugin-flowtype":"2.42.0","eslint-plugin-import":"^2.8.0","eslint-plugin-prettier":"2.5.0","eslint-plugin-react":"7.6.1","express":"4.16.2","flow-bin":"0.64.0","fusion-core":"^0.3.3","fusion-test-utils":"0.4.2","fusion-tokens":"0.0.6","generic-session":"0.1.2","get-port":"3.2.0","nyc":"11.4.1","prettier":"1.10.2","sinon":"4.2.2","tape-cup":"4.7.1","unitest":"2.1.1"},"peerDependencies":{"fusion-core":"^0.3.2","fusion-tokens":"^0.0.6"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","transpile":"npm run clean && cup build","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run transpile"},"engines":{"node":">= 8.9.0"},"gitHead":"c35ac8bc85fe3a7f2adcd144c9754f6a0086ffb6","bugs":{"url":"https://github.com/fusionjs/fusion-plugin-csrf-protection/issues"},"homepage":"https://github.com/fusionjs/fusion-plugin-csrf-protection#readme","_id":"fusion-plugin-csrf-protection@0.3.4","_npmVersion":"5.6.0","_nodeVersion":"8.9.4","_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"dist":{"integrity":"sha512-1t19C09G47v77cHxuAk0+HUWbLbShP+C2duwjg0XnrUlKubvAUkPPRPjxgDGxUMPJMrvss3rAn5mKdu2liY52Q==","shasum":"7d68c2a5e740d25b15aa502e4ccf4dc49b53fa63","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.3.4.tgz","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCTzararPH7Jh9mECN6icDyzDN3C4L5UbLt23Y37M7+xgIhAMbsAvz1bVKoT1sghfAEoHsTcjtRcVzRq7TPmXAqrOjp"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection-0.3.4.tgz_1517600301362_0.43991910200566053"},"directories":{}},"1.0.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"type":"git","url":"git+https://github.com/fusionjs/fusion-plugin-csrf-protection.git"},"version":"1.0.0","files":["dist","src"],"main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.1.0"},"devDependencies":{"@babel/preset-react":"7.0.0-beta.39","babel-eslint":"8.2.1","body-parser":"1.18.2","create-universal-package":"3.4.0","eslint":"4.17.0","eslint-config-fusion":"^1.0.0","eslint-plugin-cup":"1.0.0","eslint-plugin-flowtype":"2.42.0","eslint-plugin-import":"^2.8.0","eslint-plugin-prettier":"2.6.0","eslint-plugin-react":"7.6.1","express":"4.16.2","flow-bin":"0.65.0","fusion-core":"^1.0.0","fusion-test-utils":"^1.0.0","fusion-tokens":"^1.0.0","generic-session":"0.1.2","get-port":"3.2.0","nyc":"11.4.1","prettier":"1.10.2","sinon":"4.2.2","tape-cup":"4.7.1","unitest":"2.1.1"},"peerDependencies":{"fusion-core":"^1.0.0","fusion-tokens":"^1.0.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","transpile":"npm run clean && cup build","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run transpile"},"engines":{"node":">= 8.9.0"},"gitHead":"efe20526adac6c206cb327c331f92704be3620f9","bugs":{"url":"https://github.com/fusionjs/fusion-plugin-csrf-protection/issues"},"homepage":"https://github.com/fusionjs/fusion-plugin-csrf-protection#readme","_id":"fusion-plugin-csrf-protection@1.0.0","_npmVersion":"5.6.0","_nodeVersion":"8.9.4","_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"dist":{"integrity":"sha512-3MymrpcagjJ/6XzVnbq14XVtlysUbAVUIWiCx+NHh6rfwyVPuOiRzmvYeAaBOW0uwJkJFcx0bkMde4hKW6/ybg==","shasum":"46a04bbd3461aacb0c6d5bdb969a97efc4d87482","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-1.0.0.tgz","fileCount":24,"unpackedSize":99450,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCFpFnj2oQguOTXI+DojVnr98WouoilZXZlxnfTd8BJAgIgHjQ2zIBXzp1EUqb4EfMgkFoS3N+VzzVmqxJCMeK/LKI="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_1.0.0_1518216000015_0.5737529009173099"},"_hasShrinkwrap":false},"1.0.1":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"type":"git","url":"git+https://github.com/fusionjs/fusion-plugin-csrf-protection.git"},"version":"1.0.1","files":["dist","src"],"main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.1.0"},"devDependencies":{"@babel/preset-react":"7.0.0-beta.40","babel-eslint":"8.2.1","body-parser":"1.18.2","create-universal-package":"3.4.0","eslint":"4.17.0","eslint-config-fusion":"^1.0.0","eslint-plugin-cup":"1.0.0","eslint-plugin-flowtype":"2.42.0","eslint-plugin-import":"^2.8.0","eslint-plugin-prettier":"2.6.0","eslint-plugin-react":"7.6.1","express":"4.16.2","flow-bin":"0.65.0","fusion-core":"^1.0.0","fusion-test-utils":"^1.0.0","fusion-tokens":"^1.0.0","generic-session":"0.1.2","get-port":"3.2.0","nyc":"11.4.1","prettier":"1.10.2","sinon":"4.3.0","tape-cup":"4.7.1","unitest":"2.1.1"},"peerDependencies":{"fusion-core":"^1.0.0","fusion-tokens":"^1.0.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","transpile":"npm run clean && cup build","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run transpile"},"engines":{"node":">= 8.9.0"},"gitHead":"8a766b010d0ab33023c586938304c408762ea052","bugs":{"url":"https://github.com/fusionjs/fusion-plugin-csrf-protection/issues"},"homepage":"https://github.com/fusionjs/fusion-plugin-csrf-protection#readme","_id":"fusion-plugin-csrf-protection@1.0.1","_npmVersion":"5.6.0","_nodeVersion":"8.9.4","_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"dist":{"integrity":"sha512-edhvug55lYIhrnmb+XqVRRrSsUpaERC/Rg1gWLViGNftLJTPgkCcZaaTdqeF66OumteXVOKGqy2GOggVnGaMHQ==","shasum":"955939bcb1aa63b6abc238e3d1ab1a3352db3b8d","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-1.0.1.tgz","fileCount":24,"unpackedSize":99519,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDf7YcWrfadnz1upMEfQBm8XVTNIZBqcnXjCI6owCXt2QIhAJUi3flSw6gnUadkVWQPEzLwXK0qIzg+08GYXwZGC6vg"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_1.0.1_1518460988166_0.47168843608126965"},"_hasShrinkwrap":false},"1.0.2":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"type":"git","url":"git+https://github.com/fusionjs/fusion-plugin-csrf-protection.git"},"version":"1.0.2","files":["dist","src"],"main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.1.0"},"devDependencies":{"@babel/preset-react":"7.0.0-beta.40","babel-eslint":"8.2.1","body-parser":"1.18.2","create-universal-package":"3.4.0","eslint":"4.17.0","eslint-config-fusion":"^1.0.0","eslint-plugin-cup":"1.0.0","eslint-plugin-flowtype":"2.43.0","eslint-plugin-import":"^2.8.0","eslint-plugin-prettier":"2.6.0","eslint-plugin-react":"7.6.1","express":"4.16.2","flow-bin":"0.65.0","fusion-core":"^1.0.0","fusion-test-utils":"^1.0.1","fusion-tokens":"^1.0.1","generic-session":"0.1.2","get-port":"3.2.0","nyc":"11.4.1","prettier":"1.10.2","sinon":"4.3.0","tape-cup":"4.7.1","unitest":"2.1.1"},"peerDependencies":{"fusion-core":"^1.0.0","fusion-tokens":"^1.0.1"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","transpile":"npm run clean && cup build","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run transpile"},"engines":{"node":">= 8.9.0"},"gitHead":"1c321047bb6ee5b1e8632f431823e2867efe04ef","bugs":{"url":"https://github.com/fusionjs/fusion-plugin-csrf-protection/issues"},"homepage":"https://github.com/fusionjs/fusion-plugin-csrf-protection#readme","_id":"fusion-plugin-csrf-protection@1.0.2","_npmVersion":"5.6.0","_nodeVersion":"8.9.4","_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"dist":{"integrity":"sha512-Dzw54pLoJkMdqWAqo1DSnHK5FBkgyrxrdGFemxWrSMPK//J0nKclWMgT08RufwVl4nZTd+P5C+jhApPE7ctfxQ==","shasum":"01caa90ec8c23f2af0e8fe1197a4cef3614a5f38","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-1.0.2.tgz","fileCount":24,"unpackedSize":99742,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDSn0yDHFtKJyqEpwhT0CeLa549EuWKwT8Rrf+yOVJQNgIgOvMYJXzUNCDIMUv0fvwPauBDrtEE0SVCXvWRTOUAESY="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_1.0.2_1518475337054_0.5535843831999878"},"_hasShrinkwrap":false},"1.0.3":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"type":"git","url":"git+https://github.com/fusionjs/fusion-plugin-csrf-protection.git"},"version":"1.0.3","files":["dist","src"],"main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"7.0.0-beta.40","babel-eslint":"^8.2.3","body-parser":"1.18.2","create-universal-package":"3.4.1","eslint":"^4.19.1","eslint-config-fusion":"^1.0.1","eslint-plugin-cup":"1.0.0","eslint-plugin-flowtype":"^2.46.3","eslint-plugin-import":"^2.11.0","eslint-plugin-prettier":"2.6.0","eslint-plugin-react":"7.7.0","express":"^4.16.3","flow-bin":"^0.70.0","fusion-core":"^1.2.5","fusion-test-utils":"^1.0.5","fusion-tokens":"^1.0.3","generic-session":"0.1.2","get-port":"3.2.0","nyc":"^11.7.1","prettier":"^1.12.1","sinon":"^4.5.0","tape-cup":"4.7.1","unitest":"2.1.1"},"peerDependencies":{"fusion-core":"^1.0.0","fusion-tokens":"^1.0.1"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","transpile":"npm run clean && cup build","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run transpile"},"engines":{"node":">= 8.9.0"},"gitHead":"b120beb54100d151fd4a3236212f3bba1b21ca01","bugs":{"url":"https://github.com/fusionjs/fusion-plugin-csrf-protection/issues"},"homepage":"https://github.com/fusionjs/fusion-plugin-csrf-protection#readme","_id":"fusion-plugin-csrf-protection@1.0.3","_npmVersion":"5.6.0","_nodeVersion":"8.9.4","_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"dist":{"integrity":"sha512-x66HCpQyNIdDphZGTrM8ilS3tQZ0UX553zzpDkrLAaOuHt+0pYqRhsIYXxHruBqkUWRmqGUnZNYxrqas52B2eA==","shasum":"a31d5a43c1763c8b1b0cbadb2225872a68e23f9f","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-1.0.3.tgz","fileCount":25,"unpackedSize":105456,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJa6jZICRA9TVsSAnZWagAAwyIP/RSQnxsGWi52G6LZPipm\npvoCN6o0rVDEjWAtXNkUTlGnyheCAMGQntCw0whfhf+igpTgH8DhcYsynUP4\nG9ksladu7P1vokBKUs7yxft9wY44qVfMC/LepMh2zbI3zRD75N3KllzkTW6w\ncvrI/ZoC9d4yiM+xu+SMexNtq2KVOm3FcFRJTL4Oo5rVysmkyR0m59NDiFxI\ns4tvz3TTsDWgnLGCaWzmDAqo+9IH9WKMzw7LmzDK7SHTb3PTzClXf3pZT57P\nf25nzisqPczKPPrfOw3uTROtzoGqA13S+hQwdCYjjDM6EIojQVsHQlSvviLM\ny7oU5OgB9M0Z19yvHqxOjp0OJ2RP6d7nFc21W9grtkQnV7bVR9upSNG2Tw40\nbNCXGWjLeuqP4Vb4kNTooC+apJ7I202GuU2csYBjOOTCZc9ty0CobbXkp9qY\nOX1hi7+li/WGxDxzBmtICpFYIi6/nrQC13ZOh2SI7S5LvfagibZsp1eCwzsO\nJPSM+BhBX/GrOvthcqOpGKBAehrixym6wVl7D1WwdS9dDzLDO4qS4E3DjKdQ\nj9Vfk9kmP8o/dKy8CwULcKSxHJ3LXypoBfJWLcIFgGTm+6RTygIxt8fse40Q\nuQqJtuUCClC5bmyhxtfJQHV1E4uKAmbzsDhPTn1MFBJ4T0XL5l7Cq/1hO1+0\nB55S\r\n=j6dW\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIA2r9JW5MdaHVUrwS6dfm+vC2jjsHDisG6KdhD5sFPNZAiByd5dKoY2PdN8nxkJGkreZDgBRuugWec+tEKpf2mxSow=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_1.0.3_1525298759750_0.005014841456039809"},"_hasShrinkwrap":false},"1.0.4":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"type":"git","url":"git+https://github.com/fusionjs/fusion-plugin-csrf-protection.git"},"version":"1.0.4","files":["dist","src"],"main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"7.0.0-beta.52","babel-eslint":"^8.2.3","body-parser":"^1.18.3","create-universal-package":"^3.4.4","eslint":"^4.19.1","eslint-config-fusion":"^2.0.0","eslint-plugin-cup":"^1.0.2","eslint-plugin-flowtype":"^2.46.3","eslint-plugin-import":"^2.12.0","eslint-plugin-prettier":"2.6.2","eslint-plugin-react":"^7.8.2","express":"^4.16.3","flow-bin":"^0.76.0","fusion-core":"^1.3.0","fusion-test-utils":"^1.1.0","fusion-tokens":"^1.0.3","generic-session":"0.1.2","get-port":"3.2.0","nyc":"^11.8.0","prettier":"^1.12.1","sinon":"^5.0.7","tape-cup":"4.7.1","unitest":"2.1.1"},"peerDependencies":{"fusion-core":"^1.0.0","fusion-tokens":"^1.0.1"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","transpile":"npm run clean && cup build","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run transpile"},"engines":{"node":">= 8.9.0"},"gitHead":"4048ed0d1f71671a9ce79f29d0ef5eed9757f384","bugs":{"url":"https://github.com/fusionjs/fusion-plugin-csrf-protection/issues"},"homepage":"https://github.com/fusionjs/fusion-plugin-csrf-protection#readme","_id":"fusion-plugin-csrf-protection@1.0.4","_npmVersion":"5.6.0","_nodeVersion":"8.11.3","_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"dist":{"integrity":"sha512-au1PgDp9l+eo5Yq94ca8nLeD1eWepYK55I0uoFq3S+MKmcnrk4fvjMYol2WSZqJv2Gwg++M4zhEDoKK/PdfWug==","shasum":"f85deeda5690eb59790965968f93d23aec87e6b2","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-1.0.4.tgz","fileCount":25,"unpackedSize":106015,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJbWmIWCRA9TVsSAnZWagAAYgIQAIsN0FN48TGd+8ho6OxM\nloThzJjij1ztCMYIATIJ5LCYhy8ljkLhP2wdi42KVIxfV+oFI6+sG/ujzTsz\n3s92AOCqdsAAey6cp0cnlj8JLuNAorT3jvgSThIRu8CbTcYgwcAG0ezpE78j\nyvURdf8kKaL+GQhf/Jy0JnxAFZKj+bTCCqp1OR9wRIupQkXD99bH7PSdxauu\nCHli8qmXctAxJhlkzMABWaCp9RiPheOzj5IPfpe1FWC7VY9iKu4T/nv2C19d\nVOQ2L7novs89zn390O2oLyCw0y+COrLe2o4T+D+bExIi9b57Bz3KKu0K6hwq\nve13c31MbCNj7NvWbusZipKYXrsXJXt84JaYDy/I++hooxZXVO/IcR+oQwou\nSIWJiSlgNzKQMWwoZ1MIJfRHO7U8k5No9Y0UXRW7bAb2DLa0Vnk2BQQa1j4N\n9CHd5nE79yLK1A7Sw+Hd6eddJ/MzGhjm5MrtKCSjmkRJjjq86hF/q+ZrjFNd\n8L9wrhZTCvNRBStxMuT0BeZUnBBDx4jdw48S1wTEI7PO139l28hvbP+u9Wuu\neKfPoJfzDrHeMsm6GVH4ug+m+FS2KWNpaWHQH61UeouFeVyctDh/pQNhNfQm\nmvvNexsP6QnVEZ4HZRZ6NEAqeFKWzOJWzt9VLiv/FwPxRre3UctAhI88gxSH\nKPZu\r\n=HhvW\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIFYZ6uucfkhcowk2LI/PR5uvULnMnZSqsqM9YWim+84dAiB8wZY2l9AWRAugMY82asaNu4t6MAJirdF+3Wy1jDgn3g=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_1.0.4_1532650006733_0.5056541046949494"},"_hasShrinkwrap":false},"1.0.5":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"type":"git","url":"git+https://github.com/fusionjs/fusion-plugin-csrf-protection.git"},"version":"1.0.5","files":["dist","src"],"main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0","eslint-plugin-jest":"^21.18.0"},"devDependencies":{"@babel/preset-react":"7.0.0-rc.1","babel-eslint":"^8.2.3","body-parser":"^1.18.3","create-universal-package":"^3.4.4","eslint":"^5.0.0","eslint-config-fusion":"^4.0.0","eslint-plugin-cup":"^2.0.0","eslint-plugin-flowtype":"^2.46.3","eslint-plugin-import":"^2.12.0","eslint-plugin-prettier":"2.6.2","eslint-plugin-react":"^7.8.2","express":"^4.16.3","flow-bin":"^0.78.0","fusion-core":"^1.3.0","fusion-test-utils":"^1.1.0","fusion-tokens":"^1.0.3","generic-session":"0.1.2","get-port":"4.0.0","nyc":"^12.0.0","prettier":"^1.12.1","sinon":"^5.0.7","tape-cup":"4.7.1","unitest":"2.1.1"},"peerDependencies":{"fusion-core":"^1.0.0","fusion-tokens":"^1.0.1"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","transpile":"npm run clean && cup build","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run transpile"},"engines":{"node":">= 8.9.0"},"gitHead":"d434d0fd65014b1bc6f47530a62a8d48e33837c5","bugs":{"url":"https://github.com/fusionjs/fusion-plugin-csrf-protection/issues"},"homepage":"https://github.com/fusionjs/fusion-plugin-csrf-protection#readme","_id":"fusion-plugin-csrf-protection@1.0.5","_npmVersion":"5.6.0","_nodeVersion":"8.11.3","_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"dist":{"integrity":"sha512-dHbZYHgsOiCAHWovOil+Rll5vdvxX6tEyXeNG9D/EWYWuZBRPg63gIbT9cEOQgJak6m9dkVBPJVduoRp7iO+jg==","shasum":"32e5cd45c00b49dd6402901471044c404ed3a375","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-1.0.5.tgz","fileCount":25,"unpackedSize":105834,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJbe7AMCRA9TVsSAnZWagAAXrUP/1eCsChhZK2ZE8R9Kkzn\nqztyZuuWUN2V9nXGHBFJkBkAVxhx8/Kd4SVqH+xSvdrga22HVqw3g4daw2Qs\nZE/UGNrLprCpnxKSC+m8wxSRohALkjSXFoG2O2Uw3MHW/O29iC0fBPFpqebG\nrudLd3Kxm9eb6ady5scT3tcWU+Lg+7nPgcnPQy6ficafgCliw+yW0Ls3f7or\n8WVE4MBsODhPn8BToz6QQPhG746wtufZZrT6b2FWPnjnKPMzAgv1VAu87iJQ\npomhJt8Lj49CifuPM0HAwNVE3eD16Jz9ZE1RP74hoq0rtPWMHoPbGrhs8Ulj\n5gWvKvpVHMiRa4X5wIU+rnmk8NLd+R9USjVxVTxlS01hsWUL6KbWIoQi0CFv\nA1S1E9FiEH1Qy2v+pdVsI2TE3SyKN1/8U6MnPeSwDQUHSRHLegCKO1SjVgp+\nYraJfdS59TSj3o6jv/TjzqANahr9DSgLr5BJweQQ8DyUMzYc7PIUKsESe1EH\ncjdvGWMfeYN+yG/urPMe0Xtf3YjXVxGIGiEH/+5sYL2lohP6I6UC7Dwu4f/J\nTVmO3a0DSa/JrnDRVCPtQQpS84ADGDCp3+hUwymEUY4jmWTAfBlXvhTEPxty\nmqe6N+qUe2sg7BLC0wksLqNqq+IaqNNqtqbrTB9AtePfi5fWwPe69ZLzZXnT\nC5G3\r\n=2Wjg\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCAndVSqClxfqT2eyBA4vEyD7NYbAMot3m37FwYoZO0sgIhAMcZSnIgA1QVNKwswpjnOr1z5aQgTD19HqFhr/YfPn/J"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_1.0.5_1534832651820_0.882332067180599"},"_hasShrinkwrap":false},"1.0.6-1":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"type":"git","url":"git+https://github.com/fusionjs/fusion-plugin-csrf-protection.git"},"version":"1.0.6-1","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0","eslint-plugin-jest":"^21.22.0"},"devDependencies":{"@babel/preset-react":"7.0.0","babel-eslint":"^9.0.0","body-parser":"^1.18.3","create-universal-package":"^3.4.6","eslint":"^5.4.0","eslint-config-fusion":"^4.0.0","eslint-plugin-cup":"^2.0.0","eslint-plugin-flowtype":"^2.50.0","eslint-plugin-import":"^2.14.0","eslint-plugin-prettier":"2.6.2","eslint-plugin-react":"^7.11.1","express":"^4.16.3","flow-bin":"^0.80.0","fusion-core":"^1.5.0","fusion-test-utils":"^1.2.2","fusion-tokens":"^1.0.4","generic-session":"0.1.2","get-port":"4.0.0","nyc":"^13.0.1","prettier":"^1.14.2","sinon":"^6.1.5","tape-cup":"4.7.1","unitest":"2.1.1"},"peerDependencies":{"fusion-core":"^1.0.0","fusion-tokens":"^1.0.1"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","transpile":"npm run clean && cup build","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run transpile"},"engines":{"node":">= 8.9.0"},"gitHead":"d7536eb1b3a141978b98237ca7fa75067763d5a0","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/3fef89529147193838107b8bf6a5e0cb9f1dc8d11502461920.svg?branch=master)](https://buildkite.com/uberopensource/fusion-plugin-csrf-protection)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis plugin handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). It generates a csrf secret once per session based \non a combination of a timestamp and a server side stored secret and stores this using the provided session plugin \n(usually via an encrypted cookie). It uses this csrf secret to generate and validate csrf tokens per request.\n\nNOTE: If you're making requests to CSRF protected endpoints from React, you should use [fusion-plugin-csrf-protection-react](https://github.com/fusionjs/fusion-plugin-csrf-protection-react) instead of this package.\n\n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfExpireToken`](#csrfexpiretoken)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n    * [`FetchForCsrfToken`](#fetchforcsrftoken)\n    * [`SessionToken`](#sessiontoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken, SessionToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport Session from 'fusion-plugin-jwt';\nimport CsrfProtection, {\n  FetchForCsrfToken,\n  CsrfExpireToken,\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(SessionToken, Session);\n  app.register(FetchForCsrfToken, fetch);\n  app.register(FetchToken, CsrfProtection);\n  if (__BROWSER__) {\n    app.register(FetchForCsrfToken, fetch);\n    // see usage example above\n    app.register(someToken, pluginUsingFetch);\n  } \n  // optional\n  app.register(CsrfExpireToken, 60 * 60 * 24); \n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfExpireToken`\n\n```js\nimport {CsrfExpireToken} from 'fusion-plugin-csrf-protection';\n```\n\nThe number of seconds for csrf tokens to remain valid. Optional.\n\n**Types**\n\n```js\ntype CsrfExpire = number;\n```\n\n**Default value**\n\nThe default expire is `86400` seconds, or 24 hours.\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n##### `FetchForCsrfToken`\n\n```js\nimport {FetchForCsrfToken} from 'fusion-plugin-csrf-protection';\n```\n\nAn implementation of `fetch` to be used by the `fusion-plugin-csrf-protection`. Usually this is simply a\npolyfill of fetch, or can even be a reference to `window.fetch`. It is useful to exist in the DI system \nhowever for testing.\n\nFor type information, see the [`FetchToken`](https://github.com/fusionjs/fusion-tokens#fetchtoken) docs. Required.\n\n##### `SessionToken`\n\n```js\nimport {SessionToken} from 'fusion-tokens';\n```\n\nThe canonical token for an implementation of a session. For type information, \nsee the [`SessionToken`](https://github.com/fusionjs/fusion-tokens#sessiontoken) docs. Required.\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusion-plugin-csrf-protection/issues"},"homepage":"https://github.com/fusionjs/fusion-plugin-csrf-protection#readme","_id":"fusion-plugin-csrf-protection@1.0.6-1","_npmVersion":"5.6.0","_nodeVersion":"8.11.3","_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"dist":{"integrity":"sha512-sipvzAXtMyExWALR1YnFbgFfH18uMdErICK6Aj02LzuMpaM15XsSficHQ4UjIJ4oKK3L1AS2wj3oNJvxiXHsdg==","shasum":"518d72e9c309464eb37e72e9af5bca78852b08b6","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-1.0.6-1.tgz","fileCount":25,"unpackedSize":111962,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJbiho9CRA9TVsSAnZWagAAd7gP+QC0R1vCIMZPOChjPyni\nyK/MNI6v2mIHmPIET1L7Yi8dW/GSKG3EVUFO+FAxrXBx6wzEgwm8WUstOr/n\nh60rOGvfCakop5sC6Rb0WkfH1N8ilVRLJ8gYYarZyU59RPksSmNE7riR3B+d\n4t0nGDJn5GvVtCLpJTiOjLHXSJj3fNgiWfsiGk0vyNoDnHu32j1VC2gW5ktQ\nboWaP9VtSqZCPI+8e0d39ZhkHLqB6tFdnbR+Gs8asNQ13i5hZHvTr2q9SqUw\nRmT/nrneZk041/xcyRATNav3nFe9fk4+9rwFGKW+eOIg1mi9K65/J6GGOrJx\nhxM/0ittIV9VwSOxSFLymz/d7LskYFC5n41958g/aqL0/uem0BA9WHELESfB\nGkpHGbFIfP5rjmafvrQGIxRtiXhdAYJWgoxKHty+0cl2nApUHRtVx//eTnp5\nsotMaent9DzbAkLghpGBbAhgagjfceUzXncWvfQK9Zq2SSmmXsObPK3isEr4\nS6f+RZP6DT5wLV0jx6MIiB5wFeOe1zjdBCWteIQao/g9mTeg9nW1soUHjzcG\n5jVEpoOMQlZzl1YyW4H7y3cWZoBjHyHwumkyRP3hKJ4RYlU+85Q+uamcXniI\nF/pAaVO8pf2wJPbhtQzlJisRngYwuLX0Mx+3TPg2E6m3PPL+FOpAdMq6KLpM\ni/JD\r\n=++Ga\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIDoZenMVMQOi7wZnxpbE227uk+Pj6rrvARNtnTTI2y0OAiAIzyoEwddK8mYHWNV6KJ/y8LyBcVNX7U7rZrWqFLR3rA=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_1.0.6-1_1535777340276_0.5127437650245494"},"_hasShrinkwrap":false},"1.0.6":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"type":"git","url":"git+https://github.com/fusionjs/fusion-plugin-csrf-protection.git"},"version":"1.0.6","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0","eslint-plugin-jest":"^21.22.0"},"devDependencies":{"@babel/preset-react":"7.0.0","babel-eslint":"^9.0.0","body-parser":"^1.18.3","create-universal-package":"^3.4.6","eslint":"^5.4.0","eslint-config-fusion":"^4.0.0","eslint-plugin-cup":"^2.0.0","eslint-plugin-flowtype":"^2.50.0","eslint-plugin-import":"^2.14.0","eslint-plugin-prettier":"2.6.2","eslint-plugin-react":"^7.11.1","express":"^4.16.3","flow-bin":"^0.80.0","fusion-core":"^1.5.0","fusion-test-utils":"^1.2.2","fusion-tokens":"^1.0.4","generic-session":"0.1.2","get-port":"4.0.0","nyc":"^13.0.1","prettier":"^1.14.2","sinon":"^6.1.5","tape-cup":"4.7.1","unitest":"2.1.1"},"peerDependencies":{"fusion-core":"^1.0.0","fusion-tokens":"^1.0.1"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","transpile":"npm run clean && cup build","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run transpile"},"engines":{"node":">= 8.9.0"},"gitHead":"a9a62f94ca77c8de2f760af8c12f99f4ca9253c3","bugs":{"url":"https://github.com/fusionjs/fusion-plugin-csrf-protection/issues"},"homepage":"https://github.com/fusionjs/fusion-plugin-csrf-protection#readme","_id":"fusion-plugin-csrf-protection@1.0.6","_npmVersion":"5.6.0","_nodeVersion":"8.11.3","_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"dist":{"integrity":"sha512-dD7kMcHiBb59YRimmIgwnV1brb7+0WjeKU32srccotX3Z1AHFwghxb3+lu00fmFSz90MyvhMWXMl7RTQ4dFQ+w==","shasum":"9a51be9827773bfc74da32a710e51ad909943b50","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-1.0.6.tgz","fileCount":25,"unpackedSize":111960,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJbkwKqCRA9TVsSAnZWagAAja4P/AsMHxLlqEs9ndZzk8RU\n0OMYcXVGeqn7fp6RDJjozbAF/6WIiX7DcalqRwa43dq2Fvb9QAoWwh9uP86V\nkgQEPWvStpRsU/6oTSeoxlIBXVVpNXJLZ0/w8YDQcxelcMxlUXrpgjxbvCcd\nSw5PU7KF8sndeMrzaUoOr94WD7ChCuU1sAUts6MpOdMinGI0BOaRPy3wWu4y\nxyNiZl4hLVcibdznF77O4bvljGINimWOSmk8N1Dq/1A7sChKVW5bcRXEh0UR\n2Rq8nzG63aGlqBah1H8UTNpzjCVBpJHy8Re4ij1NKp+MpfKmG9D+vQcG0PM0\nza+beRz6CEvSfUDmJTnlMbYcX6+5X76yeUVmFPS30g4W9SiAHlBxvbygeGpw\nnuC2E+46Sa2JDySJ83uKQh5OFg7I/+jIOzk8r3BmEOiG6xpcynm0d2Tjd3+3\nbd2OvjWBbJIiF7yrbeA2tbjfZQEy9c+YqtQahDgaE++MmbPEb7OIKMiNm/C5\n/LLfEPjbePWsKfNBLjJRfby2nPK+NXQwxC7Q+Tanv8ucbdSvCJ5UXbnX0Cpl\nqsFTqvO7l8K7I83TeL0x3f7CIEei/uBh1xPF8N05FlI7OygFn/Whr9cUPs0C\n1LSl1Xvx63LtwmebjBltjLrsCH7nOi1COGf+IWmjhZhMQ8yCxMOFIniLAY+k\nNwEP\r\n=CZil\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQC+GLGZmHbliVv6g9HgQxHBv6q/GfDSoYLiQKt84C4NdQIge7ocyYFv71WguFU6D59BRaD1NdV2G+WmRF5pqcRLKS8="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_1.0.6_1536361129892_0.022069540621458827"},"_hasShrinkwrap":false},"1.0.7-0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"type":"git","url":"git+https://github.com/fusionjs/fusion-plugin-csrf-protection.git"},"version":"1.0.7-0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0","eslint-plugin-jest":"^21.22.0"},"devDependencies":{"@babel/preset-react":"7.0.0","babel-eslint":"^9.0.0","body-parser":"^1.18.3","create-universal-package":"^3.4.6","eslint":"^5.4.0","eslint-config-fusion":"^4.0.0","eslint-plugin-cup":"^2.0.0","eslint-plugin-flowtype":"^2.50.0","eslint-plugin-import":"^2.14.0","eslint-plugin-prettier":"2.6.2","eslint-plugin-react":"^7.11.1","express":"^4.16.3","flow-bin":"^0.80.0","fusion-core":"^1.5.0","fusion-test-utils":"^1.2.2","fusion-tokens":"^1.0.4","generic-session":"0.1.2","get-port":"4.0.0","nyc":"^13.0.1","prettier":"^1.14.2","sinon":"^6.1.5","tape-cup":"4.7.1","unitest":"2.1.1"},"peerDependencies":{"fusion-core":"^1.0.0","fusion-tokens":"^1.0.1"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","transpile":"npm run clean && cup build","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run transpile"},"engines":{"node":">= 8.9.0"},"gitHead":"83c229f0865763d9fc72d3270adda7795c36659f","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/3fef89529147193838107b8bf6a5e0cb9f1dc8d11502461920.svg?branch=master)](https://buildkite.com/uberopensource/fusion-plugin-csrf-protection)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis plugin handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). It generates a csrf secret once per session based \non a combination of a timestamp and a server side stored secret and stores this using the provided session plugin \n(usually via an encrypted cookie). It uses this csrf secret to generate and validate csrf tokens per request.\n\nNOTE: If you're making requests to CSRF protected endpoints from React, you should use [fusion-plugin-csrf-protection-react](https://github.com/fusionjs/fusion-plugin-csrf-protection-react) instead of this package.\n\n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfExpireToken`](#csrfexpiretoken)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n    * [`FetchForCsrfToken`](#fetchforcsrftoken)\n    * [`SessionToken`](#sessiontoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken, SessionToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport Session from 'fusion-plugin-jwt';\nimport CsrfProtection, {\n  FetchForCsrfToken,\n  CsrfExpireToken,\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(SessionToken, Session);\n  app.register(FetchForCsrfToken, fetch);\n  app.register(FetchToken, CsrfProtection);\n  if (__BROWSER__) {\n    app.register(FetchForCsrfToken, fetch);\n    // see usage example above\n    app.register(someToken, pluginUsingFetch);\n  } \n  // optional\n  app.register(CsrfExpireToken, 60 * 60 * 24); \n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfExpireToken`\n\n```js\nimport {CsrfExpireToken} from 'fusion-plugin-csrf-protection';\n```\n\nThe number of seconds for csrf tokens to remain valid. Optional.\n\n**Types**\n\n```js\ntype CsrfExpire = number;\n```\n\n**Default value**\n\nThe default expire is `86400` seconds, or 24 hours.\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n##### `FetchForCsrfToken`\n\n```js\nimport {FetchForCsrfToken} from 'fusion-plugin-csrf-protection';\n```\n\nAn implementation of `fetch` to be used by the `fusion-plugin-csrf-protection`. Usually this is simply a\npolyfill of fetch, or can even be a reference to `window.fetch`. It is useful to exist in the DI system \nhowever for testing.\n\nFor type information, see the [`FetchToken`](https://github.com/fusionjs/fusion-tokens#fetchtoken) docs. Required.\n\n##### `SessionToken`\n\n```js\nimport {SessionToken} from 'fusion-tokens';\n```\n\nThe canonical token for an implementation of a session. For type information, \nsee the [`SessionToken`](https://github.com/fusionjs/fusion-tokens#sessiontoken) docs. Required.\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusion-plugin-csrf-protection/issues"},"homepage":"https://github.com/fusionjs/fusion-plugin-csrf-protection#readme","_id":"fusion-plugin-csrf-protection@1.0.7-0","_npmVersion":"5.6.0","_nodeVersion":"8.11.3","_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"dist":{"integrity":"sha512-nD3EA+mLmmDsURagtd8JnLWMy4ri0Qw3HO6y/rdhMot1NALXULx6jHmEdAoBHv8U8oplqfPrX7ybcihyAVH6JQ==","shasum":"a4ee91c8969f950082684c1b13c7308297891ffa","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-1.0.7-0.tgz","fileCount":25,"unpackedSize":111969,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJbmXT6CRA9TVsSAnZWagAAgjsP/Apb8NbVdenSE1Q+Qbg9\nJMdZNBBxodGJcMthrv0O/l2IR/xPrHYSNj8DvFT2J2Gk/jEvgjCnuig5Area\nfl/vl8gr0akmBEiWGQI4jAbrajmjvN8ZnPMXLRvIrf6Qxy50GHTs7VMCmS5n\ncd9diYXnkLaS0S467j2pOUDHQT3sctzC1q/enTzcZVIU3eStskMeaLLcOZ2X\n0g/iwPkA4noSNbag4zPor7yjUS+oJT8dZBfA3F7LTvVs1XdACeGI4iY+yUU4\naJRPdehAhMcBQh9cFgiQ4aTNVVs6op082JoMzGSp+ZQCk7j2So94nxjrR2Qa\nsEenGKSZ7hCJvIpJT/ReExz2S9U2CP0yo9DwgGPnYQR6n+depRf/ZHVL2pcc\nThebFwKvjk+1eNSmaO3HOMGH0BGRWUxr0OcpxqYv4HWoM9lBKrNP4p1eAkS+\n+Y0SkVjvdD/AnVUJdnSePhRnBVxKFZ5dtuv1Pwte8ZufxKRd1rRfXofF22gl\nFPoDiwLqB+pQi8RGAeJfCyC7NA6DdfPuUkiPVN5qJbMy4pNuTZGEYVi9Qzcx\nZWkHYO3tcEWqAMDssLLKNKupSprC2TVpphPW1r8h25esioJaMyt0uRpNqwcB\nkKqppnB7MfG725TAET+XHP+7Edo5V1uJ+w85qsIpIydUhwHsGb4jTBmSWXdc\nzzZy\r\n=p8VW\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDmFr73qlH14GX5+XLYTh4SqC3CiCuAoaNBBR+AKMMZKgIgEA4uKDMVg3cINNBPe9QUQS0TGuWOt3NdDNp3Ttq9C4A="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_1.0.7-0_1536783609594_0.04138248775332998"},"_hasShrinkwrap":false},"1.0.7":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"type":"git","url":"git+https://github.com/fusionjs/fusion-plugin-csrf-protection.git"},"version":"1.0.7","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0","eslint-plugin-jest":"^21.22.0"},"devDependencies":{"@babel/preset-react":"7.0.0","babel-eslint":"^9.0.0","body-parser":"^1.18.3","create-universal-package":"^3.4.6","eslint":"^5.4.0","eslint-config-fusion":"^4.0.0","eslint-plugin-cup":"^2.0.0","eslint-plugin-flowtype":"^2.50.0","eslint-plugin-import":"^2.14.0","eslint-plugin-prettier":"2.6.2","eslint-plugin-react":"^7.11.1","express":"^4.16.3","flow-bin":"^0.80.0","fusion-core":"^1.5.0","fusion-test-utils":"^1.2.2","fusion-tokens":"^1.0.4","generic-session":"0.1.2","get-port":"4.0.0","nyc":"^13.0.1","prettier":"^1.14.2","sinon":"^6.1.5","tape-cup":"4.7.1","unitest":"2.1.1"},"peerDependencies":{"fusion-core":"^1.0.0","fusion-tokens":"^1.0.1"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","transpile":"npm run clean && cup build","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run transpile"},"engines":{"node":">= 8.9.0"},"gitHead":"e8ad075b190acaa454cab310e8409bf8e13fbcf6","bugs":{"url":"https://github.com/fusionjs/fusion-plugin-csrf-protection/issues"},"homepage":"https://github.com/fusionjs/fusion-plugin-csrf-protection#readme","_id":"fusion-plugin-csrf-protection@1.0.7","_npmVersion":"5.6.0","_nodeVersion":"8.11.3","_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"dist":{"integrity":"sha512-eDs5btD6z8E8HPJZ4MDdKdSyF4d/4Q3KmZFOIIQVZvGBCQxDW/Om9TwSUHPvIwGT+05u9FsOPPFvUJvTT7dnfw==","shasum":"ec4ae84c18a2c52e16609610d8db9796fdd3f011","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-1.0.7.tgz","fileCount":25,"unpackedSize":111967,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJboETqCRA9TVsSAnZWagAAbXsP/00IegwXPZs2Z/GBAz4M\nOJhG8NSts4Crej5ulcGzQ+A8cCRnya0NsiTsZwOXU6eJH9rCCL65Lj/AUrJY\n8eZC/50J/gVgASz0bzOOuOLGJD5y//8pUhSihcXqi6/v5KkjtAvAmYIyjnNP\nPVGi163ssOcCPooDNMJPcDbR+D7hi6Xx2QTboqA0aQLxbzN0VH8PBg0LkwST\nWWQzLPPCgC4Mp2kj5PSrDWvshdsETcPEspkWSm1UOrCi+sZXVLjYhXgjGgz+\nzzve2LX/QkGmY0GZ2yrW7uimPqvT/pzZNHIUfxDVcje0zPXyI4EF3bQC1qGg\nQdHbbsF2nov0PZoTsi76frtcTBVrFGAJO2xoQPZTIz6oUJayrIb/6Rh8ILCh\nSormtiFh5lOrV2K9OG/NvAyzi4tuEkq+YXUx3rEDH5I8l6TMDnwdT2DftRQ2\nja02SDgemIPz1pEsRre+Z+r3KfS+QwjRiwJiZ4K8nHyjbcoryyDFjl2Eq4cM\n933gXKOknaS4CxABSeD8whYxwM///vHJUd7iHx3fkhGZcrXrNCYP8euhfxFy\nJfS1pG6dPZDKP98gj8Q0xNhQgK5jIMOdoPS9LYvRo6iKayP9VSij2xeA7/Ef\nlIrMuLTM3nlNW3fwOaVHv1IOwYmp78gfjHT3dk++B0Kuxa+jFu5If6P1/H34\nrps4\r\n=un/n\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIBZpzpzTdJ6j1r/ztSvpBmOJE6/8WHAeGkEgsAc7jnx/AiEA+eMqKMcc+tQdCs+AxT1YisWLcxiVlgEMvHIgHdywUyw="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_1.0.7_1537230058169_0.8777524239555241"},"_hasShrinkwrap":false},"2.0.0-0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"type":"git","url":"git+https://github.com/fusionjs/fusion-plugin-csrf-protection.git"},"version":"2.0.0-0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0","eslint-plugin-jest":"^21.22.0"},"devDependencies":{"@babel/preset-react":"7.0.0","babel-eslint":"^10.0.0","body-parser":"^1.18.3","create-universal-package":"^3.4.6","eslint":"^5.4.0","eslint-config-fusion":"^4.0.0","eslint-plugin-cup":"^2.0.0","eslint-plugin-flowtype":"^3.0.0","eslint-plugin-import":"^2.14.0","eslint-plugin-prettier":"3.0.0","eslint-plugin-react":"^7.11.1","express":"^4.16.3","flow-bin":"^0.83.0","fusion-core":"1.9.0-0","fusion-test-utils":"^1.2.2","fusion-tokens":"^1.0.4","generic-session":"0.1.2","get-port":"4.0.0","nyc":"^13.0.1","prettier":"^1.14.2","sinon":"^6.1.5","tape-cup":"4.7.1","unitest":"2.1.1"},"peerDependencies":{"fusion-core":"^1.0.0","fusion-tokens":"^1.0.1"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","transpile":"npm run clean && cup build","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run transpile"},"engines":{"node":">= 8.9.0"},"gitHead":"71f1eac59d16569cb31a541ec2ce287acecaefe4","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/3fef89529147193838107b8bf6a5e0cb9f1dc8d11502461920.svg?branch=master)](https://buildkite.com/uberopensource/fusion-plugin-csrf-protection)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusion-plugin-csrf-protection/issues"},"homepage":"https://github.com/fusionjs/fusion-plugin-csrf-protection#readme","_id":"fusion-plugin-csrf-protection@2.0.0-0","_npmVersion":"5.6.0","_nodeVersion":"8.11.3","_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"dist":{"integrity":"sha512-uFK0Dg3c1C0nYwoly8K1S0sR3y0JZIPQl2zkJ3TwdblFe8eMpoJR5myrnbh4YGcX7+Nj1xMghuIM8fBfm3Ag+g==","shasum":"b4b5d245e4b882e4ff59109fd7f2d2d1160673b6","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-2.0.0-0.tgz","fileCount":24,"unpackedSize":60958,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJb27c4CRA9TVsSAnZWagAA2l4P/2hb+sTuv1oXVAdsZ1cI\nBg+NXZO/NLZwlNavnTJ3DiFe+43R4rnJAfKmXBm6Hw/jZI4+wEjKigNODz0c\nVzTZzHVgXfo6sW8cHc6zWncrtJ5LB1g/D2nA4muA3kdzYkHR45CSaUs7crid\nzXgySA/no2zDWpQGwP5ggyyfrg5NReBviUWGXBArW/1cgPsZb2MZfmIY2z50\nhw4FuGaXk1scDuH+QN9TT860YRjFt3RkgOIB5lVC7AuUM8hiMPihuPu0QGxy\nMbEEXZFbTIiQ5YGXQh6N6ph/HgbGs9pVmBQKkQDT/x8dT6bqWFnxfqXhU7b3\n7eivLjlGczdUw8ypUww9iD334ZlpIy3GGQUo+5aq+UPqugGI9UX6x8o9My6U\nf/Yx53+Q6xqoJm/cpmTWpeEwe9wdawKY473LJVcrMgqVZRPuHn/aLmx/I4pj\ngzWPTdgwkfY8VHO+prqL4Eo169c+qbQo8ReAg/dzWooMj4eoAAqD6ma53oKv\nw7O9rmAL98TBT7IAKBlVs+M86tedl0OBYLwNxYFDvtL/dhqrv+XmsqKDxlQ5\n9QKMEz/HOxHb9DPCh8RtybvIhUP/jbDUnmqLG5kAJ6vD0mOrtA12GWNVStcW\nOqcuTAfGRGNuE641yHv2r/wdW0ed7yvrX8Tf39Wm3CmBh582OXDOypGd4D5J\nImeu\r\n=f/3U\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDdRd8X5kOPwEis6/M4Gsz6qPtfqlafoQr37ARDWO+fBwIgO/ugKjNGZ0iUX/0nEoObQG0jSBMBKcMVjmgZq4jcuc4="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_2.0.0-0_1541125943081_0.15808710113325963"},"_hasShrinkwrap":false},"2.0.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"type":"git","url":"git+https://github.com/fusionjs/fusion-plugin-csrf-protection.git"},"version":"2.0.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0","eslint-plugin-jest":"^22.0.0"},"devDependencies":{"@babel/preset-react":"7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.6","eslint":"^5.9.0","eslint-config-fusion":"^4.0.0","eslint-plugin-cup":"^2.0.0","eslint-plugin-flowtype":"^3.2.0","eslint-plugin-import":"^2.14.0","eslint-plugin-prettier":"3.0.0","eslint-plugin-react":"^7.11.1","express":"^4.16.4","flow-bin":"^0.86.0","fusion-core":"^1.9.1-1","fusion-test-utils":"^1.2.3","fusion-tokens":"^1.1.0","generic-session":"0.1.2","get-port":"4.0.0","nyc":"^13.1.0","prettier":"^1.15.1","sinon":"^7.1.1","tape-cup":"4.7.1","unitest":"2.1.1"},"peerDependencies":{"fusion-core":"^1.0.0","fusion-tokens":"^1.0.1"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","transpile":"npm run clean && cup build","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run transpile"},"engines":{"node":">= 8.9.0"},"gitHead":"22a1ce636cb9e7fed623d3d64cc00c6ff3f6b63b","bugs":{"url":"https://github.com/fusionjs/fusion-plugin-csrf-protection/issues"},"homepage":"https://github.com/fusionjs/fusion-plugin-csrf-protection#readme","_id":"fusion-plugin-csrf-protection@2.0.0","_npmVersion":"5.6.0","_nodeVersion":"8.11.3","_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"dist":{"integrity":"sha512-phTBV+W/wQubeaMq917XrQrfmMjlWeTw903ZacCZAB6AYgeVOZKRgLTFDqsBHUp+ea6BxjAIW3pmgGD0c1IBgw==","shasum":"262ef19b2b57263261b2f86b87cbaedad2fb63a4","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-2.0.0.tgz","fileCount":24,"unpackedSize":62045,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJb6xNdCRA9TVsSAnZWagAA1GkQAIxN6Mqkf4obLjFQoirg\nycjFseEg8aXU9Ys3TaY8bKh/McNQ5swtYZV8FWLv9NLqOEEN5Zp0NQnuGyvX\n++VwRilti7k4+t7ulZi9Jkp0ywdvADmX5ljjpGmim8S6wvzBfJ9kPQyrr3OX\nfQv49VKkU4eBD1OTVehm27Ft6dAy7hC/lBNK+P0GDKoOpJ2bU1rS0h/Hlvm8\n3DiAr6y+lBadn4txb9UdPuBmja+64TVZcqU/A11tdhatpwGWXIhwU8Hd61SE\nibM8M0XgiXBQoD/G6KZGYuPReAKXaNHSvLL9T5xAWpKZioDeamKR1rnF9O2S\nO7QTvlpwxTzVqogZfZLP1ndVzYLhOIsUMgqm76Ks8+elCBbPpQm1k6u1+Olw\nIU0Ixdk57jgY7cVq8LHfxq8YCd57xg2iUM9injsDOqSr4T+lMJw411z7qBKO\nqdvM9uMa3FvYoUYwFzQnKgoiYkplvZZ4klpBdjFpb0he+QqlgcW55ga0xWgb\nijJYxulXj7DpoUrXaQH9Sew/JhmfVxmzj6iC66jtNFzGrIzMJlFwCDhf/rTt\nvcZVH/FOOIqGcawxN0cIuux/cBM419cn8ZaTaodxtIaAt1K1/JzIlbx0ewFa\n51CELa7TGGLu9/TXEu2p08ymReytLzJ/BIBbNTvoIzk2rl5wlVFNbZXgo11Y\nUp4C\r\n=NTNX\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCCf3gMEcN0vjBLjRcyRfdxqFTRdeKNsXcXLHB3NrB+5gIhAJOmNTfTmpfhe8AxN1y7WvJzeRcXswZupmI4Cxxk9fLK"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_2.0.0_1542132572817_0.9649802166510777"},"_hasShrinkwrap":false},"2.0.1-0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"type":"git","url":"git+https://github.com/fusionjs/fusion-plugin-csrf-protection.git"},"version":"2.0.1-0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.6","eslint":"^5.9.0","eslint-config-fusion":"^4.0.0","eslint-plugin-cup":"^2.0.0","eslint-plugin-flowtype":"^3.2.0","eslint-plugin-import":"^2.14.0","eslint-plugin-jest":"^22.1.0","eslint-plugin-prettier":"3.0.1","eslint-plugin-react":"^7.11.1","express":"^4.16.4","flow-bin":"^0.91.0","fusion-core":"^1.10.0","fusion-test-utils":"^1.3.0","fusion-tokens":"^1.1.1","generic-session":"0.1.2","get-port":"4.0.0","nyc":"^13.1.0","prettier":"^1.15.2","sinon":"^7.1.1","tape-cup":"4.7.1","unitest":"2.1.1"},"peerDependencies":{"fusion-core":"^1.10.2","fusion-tokens":"^1.0.1"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","transpile":"npm run clean && cup build","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run transpile"},"engines":{"node":">= 8.9.0"},"gitHead":"2f33e6eab3400e1603a41bbb2443ae589387e9f7","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/3fef89529147193838107b8bf6a5e0cb9f1dc8d11502461920.svg?branch=master)](https://buildkite.com/uberopensource/fusion-plugin-csrf-protection)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusion-plugin-csrf-protection/issues"},"homepage":"https://github.com/fusionjs/fusion-plugin-csrf-protection#readme","_id":"fusion-plugin-csrf-protection@2.0.1-0","_npmVersion":"6.4.1","_nodeVersion":"10.15.0","_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"dist":{"integrity":"sha512-CevNkuMgo1/K5FesJeVDs5mUcG+jBiPBqheD5Id6FhU2x4eS5ebaOYR+JZyHNsS5izrMdFnFjLyeqo4KuOJ1Sg==","shasum":"69b167bab3565bffbb0a0a68d85c00d0b1f94e96","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-2.0.1-0.tgz","fileCount":24,"unpackedSize":62047,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJckATbCRA9TVsSAnZWagAApfwQAJOu+UOhjAJY3GsYnnH1\ng+oFehcS5fwuV4g1fDrnvaJKesJDLIGgzzTXoCC3LtS+pHuKT9hSi6LtI4O6\nuLRVGJ+/kWy8T4dyCYWRhYxHjEUHrj2Jplz1t7S3OvoXuIEMdyZi0hPK7O6T\nvq9ahiSXBZR3AVe+jz0IUt6pl/DLSz5QNXgTJKtvH8jRKE3zlIIkS2D/PaTl\nzIoFIwksrQagYfsThf7XrMjgQ29Aigj6I2siMcoujEGocPeaJJWE7HXedjE5\nmlzy0XdFIF8n61fIxbVH0PEdK0RaVbspX12CfomJrtDSuqPR6UfsZwYqAYAQ\npHssX7sjSeDIYjjfaKFjDVS3J8cgBbbKH20KPM7WkQv0b2KpmgIsxbqO8dyJ\n2TZW7t3F7h227DBGq5M9dHrkzYLS+HbmIo5fEnoEcfKRUuzawVyojatGqAU+\nb3fDQapybn0jW3gApRE/LseUJ1Tw1o9JlipGd96EsqTjQe5LaSdCF5q/qvml\n1tsAfN6f6Ylz85YR++TfExn1OQEyq9fdY96E03kpfBqWsA/XWBIPstQsO4zs\nEHrb71unptNnSmjf8Zi1wcB2PR/JP8DsMTwjFJe5ih5tZ5E4VkEZXeaImO6T\nR5HHxId9Zq5jG0RL5405VnOpkqeYJhpj4PHvTtm2+GPGVHmBGwQWlYyHMuxI\n0H7s\r\n=wv+H\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIDXnsfkEMVvT1vXslctif6hckUdiKI0q9mFKysDa++LeAiEAqDFKn4m2RdpZ5kR8A5SnJaDcreC6dE6+9T6MjbuGfGQ="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_2.0.1-0_1552942298657_0.2923553767698406"},"_hasShrinkwrap":false},"2.0.1":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"type":"git","url":"git+https://github.com/fusionjs/fusion-plugin-csrf-protection.git"},"version":"2.0.1","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.6","eslint":"^5.9.0","eslint-config-fusion":"^4.0.0","eslint-plugin-cup":"^2.0.0","eslint-plugin-flowtype":"^3.2.0","eslint-plugin-import":"^2.14.0","eslint-plugin-jest":"^22.1.0","eslint-plugin-prettier":"3.0.1","eslint-plugin-react":"^7.11.1","express":"^4.16.4","flow-bin":"^0.91.0","fusion-core":"^1.10.0","fusion-test-utils":"^1.3.0","fusion-tokens":"^1.1.1","generic-session":"0.1.2","get-port":"4.0.0","nyc":"^13.1.0","prettier":"^1.15.2","sinon":"^7.1.1","tape-cup":"4.7.1","unitest":"2.1.1"},"peerDependencies":{"fusion-core":"^1.10.2","fusion-tokens":"^1.0.1"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","transpile":"npm run clean && cup build","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run transpile"},"engines":{"node":">= 8.9.0"},"gitHead":"a0246aab7067e2286bc7852b8ae474ed3de596d7","bugs":{"url":"https://github.com/fusionjs/fusion-plugin-csrf-protection/issues"},"homepage":"https://github.com/fusionjs/fusion-plugin-csrf-protection#readme","_id":"fusion-plugin-csrf-protection@2.0.1","_npmVersion":"6.4.1","_nodeVersion":"10.15.0","_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"dist":{"integrity":"sha512-43+WVCUZ9KcHHupG97HO6f7mfkItN67ZULUmXxva03twqinNVhM4+D/W51FxK+utUDU8oml034FNHGHF/mzhhA==","shasum":"6d04e4b9c1d5bdbbd83d8235eae01aed787a5cde","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-2.0.1.tgz","fileCount":24,"unpackedSize":62045,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJckC6dCRA9TVsSAnZWagAAJZQQAJ5CmqiYblJw7QS9MaQL\nyRIOXUhQx3rtWxYyn+PvO2Zda6mObpwPKuDoAfp5qrScwu9H8Yg660UbNmRa\nJ6YmM5WehNzCeqlWJUc9opuZ6LWVIJ9w++0iXbPgKEusZ75wzskJhaqclbBh\nyrnJyDOKhsa03QRAZldw4nMif9bnvrp9Xeiv9P9tgsnQ86hO5IJUsMMKL+o+\nwsvkQgjo9PPGZ20fZ1eKiqMmZ1YB+wqyUayZbpfOlo5Ur5maQheB1l27k38M\nnji7glEtSWeSENKi5FFasQPxdyFZWsaNhodxynlZCwwcN/glceO2vQraWI5D\nWaZNvM+l74kecejqZiiyYAcKOYfJeYsshAnc2elbf4oRFoLoM7OpIPyr204S\nhunvzT9P5KmbIaKW76x6Z9Q9cb4f9jQMDfHUx/ysMzPqHs4qA5tbGDHyOhSw\n3c10tXfSwfbWbdNtQ8Wprjw+vrKmEJMg84jU/uZGR22Anygs3MK3CcbyKc6U\ny45S6Z4JhX8kDXuPe2Vad5nPUMFIYnp8v6clj+CnJTDHsT9SirZCzyZxYh2G\n0P5FVNQQSfjasH9O7d+30jf+3YDdTzXXimp4q0u+FoR2teLQkY4celW6e6Qd\n8GiFMMHQ0+jWq5VTEKvG6fMmNnOtwgIex8yxo+opVjzp7aXXpd+TTO8PdOEO\ny1M8\r\n=TYoJ\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDr/D8ai5zC3HuCRIIPBvHvqyZf7mKz0WmK8zY+OXYpxAIge7iSYqx021q2LuLG0rmhpGo60Fl6yNlKAO7GgS4IEv8="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_2.0.1_1552952989150_0.893356946195148"},"_hasShrinkwrap":false},"0.0.0-canary.309a1d1.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.309a1d1.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"0.0.0-canary.309a1d1.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"0.0.0-canary.309a1d1.0","fusion-test-utils":"0.0.0-canary.309a1d1.0","fusion-tokens":"0.0.0-canary.309a1d1.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.309a1d1.0","fusion-tokens":"0.0.0-canary.309a1d1.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.309a1d1.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.309a1d1.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-n6DTwBimcp4xF6yloOkupoceTHq48/AS1WE0MxxxPjuzmSpI7y5LCwxvLvm9jk8Kw3DVPN7mpWsKIfKMCK4GQQ==","shasum":"845560753771cedc116ce2064cc608686ed581c2","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.309a1d1.0.tgz","fileCount":18,"unpackedSize":31291,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJc5e7LCRA9TVsSAnZWagAADOUQAJNdmLy2uzRiNIIe740N\nxSKJJ+UJMmj3O3fGErwg+aa25uTzT5LLmiMIV0gNs4o33H8r/OqaahcbX06A\nivCCafPojp+F7HJkQfQ8+hs06moUBirZbChm2MnEW4XSAwQ6S+JViiBwMhnf\nveL9AN6IAKM3FN158K/yvIrQPbR3atFd/C6JnyRgqAXxoa1dgMOycXdLpYJE\nxN8rkruBCQ6bIDq4q6JbaIZIrTTcz2US7H0pH6zXG2uF1OBDE8nFqQcgLEjK\nzAWQ2bbUn+aHZOJvdWyeI9JHZdUq6chmOu1C9arI5lqXIhtZ+Qa1iImM+PS4\nHdtd9z+1wQZkra5J3jSbBRi5p6GvRhNffRBNI6z8X5Yp0XanHDHgccC1BKRa\nWezr12DE5r1T3YK8FCyyIPP9r3/X4fJF6Bje9BIkv1Wx98ilDKLpTmy4lVYg\ntTcdcXeH45OoNWDgvcuIPoOq7V6rN16/T2B0fySGDNjLLPH/l7dmAf2KRJfS\nxgvIFWdjnq7Uu97DHPxdzcWBzV2vptcp6H2NsFbZvZTUGr8elhQw145sp+OL\neigqrCiUQMAnC+x9A+8zx6uERVLYDHvucUpymrEYSgvymgHQBUneOTdfjST/\nfDWjg3OP8sIFYHRVP7O4PYCyD06J+AuE+pyXKgY326KhZXBf4A2TE2kkTWS9\nhYiA\r\n=ahIS\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCIfQqJZJ930mAZ8CUubpFdhuZyx39MIsFQ/596mENlHAIhANvljWPRst6cLzhevZrYuNKjJx7q1dqUyJdMXa3keRad"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.309a1d1.0_1558572744530_0.46332216267281456"},"_hasShrinkwrap":false},"0.0.0-canary.309a1d1.1":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.309a1d1.1","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"0.0.0-canary.309a1d1.1","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"0.0.0-canary.309a1d1.1","fusion-test-utils":"0.0.0-canary.309a1d1.1","fusion-tokens":"0.0.0-canary.309a1d1.1","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.309a1d1.1","fusion-tokens":"0.0.0-canary.309a1d1.1"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.309a1d1.1.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.309a1d1.1","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-LjLMC6MwlpJ5O269e1NBawqr4vuEYU2/k95pSGemLxkU1nsk+36b2t1Ij8tVxFHQwJKGnpnLOIcTuhfGJydVbQ==","shasum":"e22f12bb00b95b3e8f78556aade41675487b648e","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.309a1d1.1.tgz","fileCount":18,"unpackedSize":31291,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJc5fgiCRA9TVsSAnZWagAAjxsP/13IR4sma6KLkQeM/rZk\n7w2f3AjCuPtDvA3NbhPsCS6fha4zG6A/zEQxgVOaA8OrE58g9OiutavG3wPt\nRpF2HU6l3NWxMV0rvqUKVvABicJg/kTaGBw6fkk1LoYOx9Ww2I43zftiijAQ\n+e2ohKd0RiACqhK+uuzcHyHjELgisapWiiGizAM3+G8EktpLp9Yieo6tkQh+\ndMeyKeCz1UntGLSqKXmtaaUGUPM9tD84BCkhbiusaNhhz3hzQ7c/u4eV3gip\nVimkYfND57D/4vRKnnt/Eu+e1Dr4Zkx5QE0sW4/5B8TmCBbgfKACFLNzo1o5\nlEkm054lXtCv+WVyr9KjUPAmn/C4deoX9ykr3aMm5TN6ju9auU0p8LzqsPij\nTs3kZOt1U0N6uxNX684E3PfX1HB0HrH+eTjtxTYJM6L4qqDE7uRPYy7pqHAc\nbAMJS9sk8P6MZPWBe1gkmAgquDFtTTKWkcGw++x4RoouXDQXOqPnMmTpSQnI\nR/ljVSOTzPk6f1yxdw8f4cvbNWLdJQQJMai0/3B5Q+Q0Qo735vty+2h+fQhC\nrPmoCYJgbetmK2784d3ZDxBCaChe08D9wwNsBYZHf792pQLtW1quflvBoDXk\nt1UjcKaWvOJfaFG5KpX5F1Usp66eTYTiRUjxsxdchXWp+1pPdczszPNereun\nps85\r\n=dsJy\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIERad5EJk7zlJ4b3BPIqg6x3dk4Q/cEGOksISs/1T9v5AiAicKcpviWMU8EM9qWtvW2xPJkuVXaahh6kM8rH0DwsNA=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.309a1d1.1_1558575137824_0.5407152150673142"},"_hasShrinkwrap":false},"0.0.0-canary.9941505.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.9941505.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"0.0.0-canary.9941505.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"0.0.0-canary.9941505.0","fusion-test-utils":"0.0.0-canary.9941505.0","fusion-tokens":"0.0.0-canary.9941505.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.9941505.0","fusion-tokens":"0.0.0-canary.9941505.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.9941505.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.9941505.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-K4g3cYdHMiMjJWst2vDqWhonLV37L79E7Uo6v23r1T79ctUEX9ZwED4JvGDfiKFk148kt7XDAJa5u4/VH2U50Q==","shasum":"7e848a3188a8c911a755d04f6afbd93f2863bf85","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.9941505.0.tgz","fileCount":18,"unpackedSize":31291,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJc5f0uCRA9TVsSAnZWagAAZDgP/R4E1sKTkrb0Vcvro/nl\ngVlASOft6giLzw1dL09MiM5TDtxYjJG+nsj48PC3HX8FUsSJiMni5rermoBT\noMIsh32SkfIYl/DdAzUJucC5WtQofEsLDfMcFXkjo5MEbidP2+ZF+x5oqVsy\nMUq/q8WQ/2wI8YoLad6BbB82FsAyVdvHct+okA48/00pqcH2FlNJ6uurXYKp\nI9PLSqmfeaZLh3a4M0lvS3MC0WqXfrw55GuPVXq9ZeV0bRmYgxlIb9qIc7kn\nSXZPyDiO75d/7nO0rGDiHnSK3lRfYT8jYk3GeGrdj+ioSiW4X4y1ki1TXbC6\nJCFnnYK9uR49lvT3fm3DaBOXCKIwi3YEV0hI6TsVIBLPN1SgJHu/RkTZnTEX\nZ/wa/Z3aOobk0uIReX9w0KFOAFTkQ9jaA+t4Aw8Wd7MBygpH8j040BCkyzhR\nFKpOHWrzFUOhy1uytmEifdaleRLy719lym9Qiq8qAO6/uPlUF5ZCFqb1AQZS\nwfXvzhuZioiVfAeuo8F+CAihiVMRIy/m7G8MxAb3f510TVj0p61l35FMK0EI\n1tf9RjudOW8lXpDGBsE7LcUvexdFn8e+p0si2drHsRFOZhP49/eheogjGB4J\ntU5h8hySMtdD3UcIOHfzGXhMw+Qo88zizwAk0kLqL9ERRuFVlfBreiO/oukW\n/AfJ\r\n=8rvx\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIAPmVkZx19u31rh+4VVX7nOXUzIfqfY7ng5y+SxkHbPUAiEA+pPxx4r2vwupZaGsXlj088ripnlXdG/REaqjhoR7wIo="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.9941505.0_1558576429577_0.5771072537215771"},"_hasShrinkwrap":false},"0.0.0-canary.3811188.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.3811188.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"0.0.0-canary.3811188.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"0.0.0-canary.3811188.0","fusion-test-utils":"0.0.0-canary.3811188.0","fusion-tokens":"0.0.0-canary.3811188.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.3811188.0","fusion-tokens":"0.0.0-canary.3811188.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.3811188.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.3811188.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-5Ul5L8XmafNaxhKS8LFCD8QNMt2B0q0Jhd320IIzZRnoeUcDWp3C/JGL4mO2RN9LpAqVPANKJO3UuxekiwhcHw==","shasum":"6866b61789274bee1155a1e6af8471e9a974b9d1","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.3811188.0.tgz","fileCount":18,"unpackedSize":31291,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJc5yLsCRA9TVsSAnZWagAAkJUP/i8Ep7G0AU/61m0WYbtY\n1nmR3cCJ1A1RTd4ENCB6q8joT3Sx4kJ5w9kFVkVIQ37Xa8bw7NFbV8UN1H/O\ntkTeDw7wbV3CIu8S5QWfdm7Ah1cn62Js431Whr3vNNKRjjQFjA0l2WFnWZ7o\nTdQaWJIcTLwRLSrYUpKotixFJ1+rUad0CnbPyvJPMQJzlpGcDfMSwQhfZiPJ\niffDxzECT/LD+gXpoV/mi0FIOfgvj1rn6W360733l446FYJoJHXkXD6ypVBs\nELQza1mXEyT3WTXWHX+9Z5L1wl4x7xIV72bVRi7Aemlk4IzlnWgRJ8Qgccp7\nCEzZSvQpat9RMw2lYXnlt44+Rw+yQ+NCH2k7MBx+xCitySZf9j1RyJ/0XIzL\neWruSHD89IrXLJgL+WI52hVfNouCzWPbrwfXhLGkq6MGGWk00rH57/Uf0VEv\niDTeh5GSuOQwVYaeYjqamCpZUouUMr20Bcs5XgnEe9txrwB/83ZqR8Uh+zgk\n8wEWkfphkevH8xtFyUsbHsCIXmSEGwzv0f53P4gIEc1M5RbOHLYyLYF0O3M5\nIazUDu8oXL7Tj/0lXAXBlgFgcuYmlAA4gqSQ/+p+i/WbbyVzUA2+OzpQUTXQ\nwbj4ZqniVimXxxU0qT0LjPuMxptMrWUkVqHPGZ56ugOBJlM7mJ9b/w7dxoez\nm9Mh\r\n=z/ud\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCkkkYb90GQrB4/TmHITjXpDqUlXLrfQpO9UrcSLae30wIhAJCWKjjF3REMqYYiEd7pWywBR9oHlYVfHGiEAvS/5GIX"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.3811188.0_1558651627847_0.6964308038681226"},"_hasShrinkwrap":false},"3.0.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"3.0.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"6.0.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"2.0.0","fusion-test-utils":"2.0.0","fusion-tokens":"2.0.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"2.0.0","fusion-tokens":"2.0.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-3.0.0.tgz","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@3.0.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-lmkx78g/R2Pt9voAsRS/f7jhh/3hLfrNDlue0sXnLlAcrwblv9DH1s0FYbV9C0foydOlcc+5SR0+Yo/lm+fenw==","shasum":"1f051a3fbb76c2b05ec6cbb02c4cd360ed1abda1","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-3.0.0.tgz","fileCount":18,"unpackedSize":31172,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJc5ybOCRA9TVsSAnZWagAAiekP/3SoRKyTg9CsfbY4KwW8\nr9vJIqwHp3ptieUaO3ZsZojRVUHYOevFrir565QxFxifMMLzwtyqbfKkf3b5\nivd0iTrlw3Oz3ZO40kwCou+HU0xPvMhelXvwGVqTW1/a0rLWQ47Gpwe1giTB\no1h0ZNIa1b1f2YoeMdI5eElyBr3Zx/yIrEY6oKjEPJIGi90Iv2MREaMS6q1A\ncIc1Z+0So14MkTbjUqacIoPinHK7GDURZzELOJT/qXUHYQ9yD+uGWyGnyvg7\n11U8d4IO5ddkRJxbFSKlafNBm9bh0fKjA2q/Y7z5wWYPVN57W0LafjwqmH+j\n4+9UzekB+GYjqWj5znu4Rlbl/umpd9SaEFl7A8n8jYlj1C46Rah5C+fAmJMe\nYViPVxYyOK1NSYWK1EZOVe76MvCpEdMLtapQAMT48JlZoY7lTfpDhA/lhdG9\nQueQYZYLjyLU/qUVYprre476POg+7+hUEOq4ssNE21v65Y2Ezbcttun2wHwx\nci9vO5gWNX4FNwn7tYfTCP29hMwNLkLFfCHTttVA3bJ731ouXZvB9mY5Zijr\ndGwLyJB/tcg/FMYxHW4+SjrKG6OgH8Zb+z1VVG+oGK4nn9mCKfAUJDk7Nwc2\nPyV2A2AoaD1D+ujsVYKxIqfnVHSk5IOSHv+ApN0AXyoGXbxYWihsD8YdJLw4\nvRBS\r\n=BXFQ\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIFNmjEp5Ebvpg2vEO1VqyBaAeCV1Fuy51fZWvmcHtvB8AiEAs0HKnZUbt5iyKyJAgXhxz0nt9i0ww3tTTC6NG8coo3U="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_3.0.0_1558652622049_0.6261013233849708"},"_hasShrinkwrap":false},"0.0.0-canary.872b547.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.872b547.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"0.0.0-canary.872b547.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"0.0.0-canary.872b547.0","fusion-test-utils":"0.0.0-canary.872b547.0","fusion-tokens":"0.0.0-canary.872b547.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.872b547.0","fusion-tokens":"0.0.0-canary.872b547.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.872b547.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.872b547.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-/cGbVUvkonxVy8QY8ZNM+iI0oDFOINHRwkwDV0Ia8ql5i0hBVDWaVi90tRtIT95Zz4wIH92/eiWrkhxYco5LwQ==","shasum":"727822c2ffba45a07b0cc7d43ac0b56883c2e4cd","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.872b547.0.tgz","fileCount":18,"unpackedSize":31291,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJc6CZICRA9TVsSAnZWagAAkzIP/3nNrW2KdvmyDB0rqaCU\nj8UR+nbUtATdxMVqluR1fOIqndAdb5j2leqG1/mT6YTnta/NNBNWx5pvfUcS\n0Ns0MeaO93ZQEf1p4JX06OCKEFIIyL62Pq+Ra+l8MubP3C+gQYL3hVH7Hpms\ndAINVgqcsIitS7zZHq/QxK5v9ibvfWnISS9UWIl+CLIazteiHFW2c7U6pGPf\na6dFe9r1e07Upgh05F4zSZr7h3g30zcipn/qH7b/Ks4WgpwAbrZT5kXZUDJI\n0l2xFKji1lJ6dJohBn5wKAZkogOeT/V0jry18V6eDI+4KmsrdaGjqIXer7Gg\nzwHpLunOeS6QVD24jPN0s4Fx24ytlCVR0K0riA+Dv4j+EX9tPohaU0Ajy/he\n1tXx0hPTaGV2RN1ErGket4B0e3bxjFGh33JDNrl5uuRriuwfPUJl5AEpzVSU\nx9V/yYzz2ElA5yg6rRAu2t24lr45qk8NTsnlawkTC3Z9A0g0AAmq7Qko4AXS\nGiKu1CjNAXtuGcXS4FLul1z3tb/EUa6wlXOG2Us+tRv42Khwu2d7FSXWKEtS\nAO56RYsI4E80eea1+biAJPVonSVq2RtzNpo4PUbc+DfXcYUaMJlYMHb9AzxO\ncbRsBI7NNvJl88Ge3uoaWiswN3jgZ/ZRIwIYny+S+Gnfq+uqq1kbVFF4mUXp\n2Sl8\r\n=GCLR\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIDX0XmdyIabgFsT2KoXMZhpMDgT3x2LOMSk5j5pboGiZAiEApOCX0iEya462/4kyZSlmfqqL5nlrUnxI8wRMcFT8N9E="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.872b547.0_1558718023612_0.8303258102407494"},"_hasShrinkwrap":false},"0.0.0-canary.fd5a750.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.fd5a750.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"6.0.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"0.0.0-canary.fd5a750.0","fusion-test-utils":"0.0.0-canary.fd5a750.0","fusion-tokens":"0.0.0-canary.fd5a750.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.fd5a750.0","fusion-tokens":"0.0.0-canary.fd5a750.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.fd5a750.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.fd5a750.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-S9wgjf2KxykscTOJ9EKCnBc4tJeurqZMTux+HQHeAdjx4IrxqAlhZmheUeGAj9TxQfACwTB4fN3aWAOOZ7V69w==","shasum":"ee795459044303a1bf03a1862c4fb9b0f30a29b1","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.fd5a750.0.tgz","fileCount":18,"unpackedSize":31274,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJc+V0hCRA9TVsSAnZWagAAx1cQAIbcFjxhnLuIA1TN9PPt\nJuX1vvP5mWsP/bLT+3VpXV+vRCf8bfxEBMcId3Dl/WniSnAtTFz3xjNcInRN\nzRNnOeHBCJIRkl8ebiABu9Mz5U1Ttm8ofT1Lh/DHOGnGf0BDThRYc7IZ/oTK\n6C1BjoS2I4M4hhompVEM51ME1Lpa/AjsmTMEzNqjEiIiPa2eLAgr+DWvYVjA\nIQMFhLq9tOB3kBYEo1BmeByzf9Zb5i+PzhTsXeLlU5bTYfuc32MxAUW2kkYI\nuczHcKHOCF+mUJ0hozBr/1eIqBWub6hhoa7l3YsVa3imc07G4s3DwS7BG+dq\nuCX2xp5aVconardbHZ3NK5QTnD1M958ZMC0t8BDdfWAZvVwAe+tFCeIVBakA\nWnqiFZZq9lojp1xHbZFqI/RGAHk1EEMQjx3X9fLdMcFl5bNRXkwfuI+9EW3e\ncbtk4g5HbkM/+rVK9jSq2RVFlNjczZqr3P44jjOKQNasoRPmZV52XB1CaBse\n0VG7IUl41HsiQzoyBPjdbFAA+61vI6vKTxBZekDxYqY3WiOdKTY/4Rj71eY1\ngE2N6VZYGkfkKYJgbyh5BT9qdPPOpvBaV5EX5NIw9463iVjVwsQzFb6nOgZJ\nFdFEw+y+mO6X/oVphS4u6oi/oUylLDqta+9A5IwPbVTCvUvdg3COV2x2ewVQ\nIlHp\r\n=+HCj\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDdPXQx5jtMpnx9XpC0Tfj2c7jhNPGrlifxWshKqzsxzAIhALSd2N2kwnJ4eHFizqvdqsd9lWhtdgadknsSEJExIaXI"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.fd5a750.0_1559846176507_0.17159458420616014"},"_hasShrinkwrap":false},"0.0.0-canary.4e310bc.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.4e310bc.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"6.0.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"0.0.0-canary.4e310bc.0","fusion-test-utils":"0.0.0-canary.4e310bc.0","fusion-tokens":"0.0.0-canary.4e310bc.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.4e310bc.0","fusion-tokens":"0.0.0-canary.4e310bc.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.4e310bc.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.4e310bc.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-/jFcuL6hrWWtoMJCUeECb9EJpFOSV7pVeZRcDIbOeD381aKSi1rzOUajSlOJIzbA9XkdGMsmTqfmKd1trdeFRw==","shasum":"452aa2c24540e440a2f65a4ba6c6c3927ffb2f4c","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.4e310bc.0.tgz","fileCount":18,"unpackedSize":31274,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJc+XKgCRA9TVsSAnZWagAA+8gP/j8FflTxFN4vf/olNpmm\ncHT5rxf8NcbIwlS11jKVsrDhKGBCo71z6LdM9jLJw0Us9t9S/VxPxeZ9DYKg\nRerSs6jsSZF5g/Gp1cuBxXLec4VsytI8n2h+ppTP9ucdxA3OUybDozfVRrKl\njwA7m+HnFHMW3RoYGYhWeQjMszAL6F467Na9Z2lefWgZj3wRSEAwDWytp06t\np6PetW2+30nhWKVYHNo3auGM+N3ok6U0TSkkafN0GRYbXAcjLO3qtkziL44H\nGVm88Gb12p/TXWiD273pohj+HJuI+bvBKowVS0aKnpd3pfxcN5gxJ9vxmGRa\nyGgXfWYx7s7LKadBelFq2puEDp76TerAaW3Uryo6zyzgoPSX0bex1M5uRCIM\nssDszPaXzyPbh3zKj565/8XjGvCtQfbp4/a1w3br3oSUY+DF3eTC5KbaR1/J\nr2IP3fWPIKo4qHBTAUYbMJkeigGdsiO3V6HL9n44+FNFExlY6MrzuHf75v7t\n7xFqK+yC0McRsPTkxmAiI3AhftUEJjahIzv2e5m2/D2fjimgipxeyTCrvNHF\nXzhgE0i7hK9xbZmdOo3RbN7SkVoQo+MHNqezmPShFlz2ncf8MvVYW5wapzne\n8WN6vDeGWEe8vfrDABXVMIxRX7pb+TEwyrO3odGLSjboqKqZXZryfG87IOx6\n0TlZ\r\n=GiQe\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDo3nx4MYOv4gfavRreVFSLJhsA72RfM8BTvWJ86l257AIgKW/rKqFlZJ/O2n+FDBvAaRTuwuXjpW8GrvNKbcqFVcI="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.4e310bc.0_1559851680150_0.10252785699685663"},"_hasShrinkwrap":false},"0.0.0-canary.5bf099f.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.5bf099f.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"6.0.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"0.0.0-canary.5bf099f.0","fusion-test-utils":"0.0.0-canary.5bf099f.0","fusion-tokens":"0.0.0-canary.5bf099f.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.5bf099f.0","fusion-tokens":"0.0.0-canary.5bf099f.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.5bf099f.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.5bf099f.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-aVT0nqLU+QdkhL0BQq6DDoLLHWC8/SrfHgQNY+t9vF0Uu1shfJtcEyynFskw1OChlxf7+V069T0FOSoMrWhCHA==","shasum":"59624c549eae669fec62115d6508b505987b140e","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.5bf099f.0.tgz","fileCount":18,"unpackedSize":31274,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJc+aNWCRA9TVsSAnZWagAAVQMP/idK9X1/razPoN6OD/Y+\njI2m3WKIZFOIw4IdWQ5kdqtm3oLRk9b2HfjMwRJic8YluynP2OAHD8BF1kM/\nxs2Ltp6uKVteSMTxRbwPak1D2FCl21QnpAFkmHPhDbbJZInVMB2rPMIXpEty\nQqpJLSGk88eqCX1U6rIV7ttPU9GSGMCPtMW8Nh8qR/RdhlWk42/H1vkUCLoz\nlyh3MYTa1q4ugqDkG9Va9CNkEcjeuYOW82WULWonIZvq1PUd5/qitfAJsL21\n9S7wNFW+jjW9/8vExG4Ha5i21WjUOEpZ3hTOoSWMFG8CYgLZbId6Zvugdxtr\nV3RylMgWKVqQCVnQ0Duu9y2vxGb3Ay6UDvuoqUN+7hcMtSW5NSK4d08ZuuNT\nKNKGbEMNvJ1mLdUkf6Lr9zyChsA/pshww7l7HNftgWtxDSWxubT+HCj0OnG0\njJASpkepjPAx2lvp5yOOxXNOFT0LuUDm+9Y0YO3YihnXgL3qe1BSOhYrqKnu\nq9uOtC5OkCZvYiA8AlXZjmK0qdY3sipj6nlTxNiEZkOpmQ/+2uckIxcGpJqP\nZRdcU7wTjrpN+jcKuwfFP1ZTY7FicC1W+zd4sqmGyAHrxF71XAjcCSjxKQ1S\nR9Db6t/UIKY470Wm7e1zXesdrr0BYWY5tSlJZurpWOJWHz8f7D35FLgwdhVd\nulfp\r\n=F9B4\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIC6ghVxEPsSHpRuK+03Xvq/mzojvwgTTTX3RCbAmJr7/AiAnoHtFjyeJmG+K4h6xZIjoLUo1fxoUAV8hJB7OqkSv/g=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.5bf099f.0_1559864150275_0.11573157406395818"},"_hasShrinkwrap":false},"0.0.0-canary.2fb1140.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.2fb1140.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"6.0.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"0.0.0-canary.2fb1140.0","fusion-test-utils":"0.0.0-canary.2fb1140.0","fusion-tokens":"0.0.0-canary.2fb1140.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.2fb1140.0","fusion-tokens":"0.0.0-canary.2fb1140.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.2fb1140.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.2fb1140.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-IXM8XDOz+Ak2T1J2jShiAk++Tma3Z/7m24MoKRcDV+CR4bY3iBbyEHgma7dW8RQDC7bO2elCRdfW+yOptW+GOw==","shasum":"92cbffcc04bc7b04f3646f330b793a65cf840265","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.2fb1140.0.tgz","fileCount":18,"unpackedSize":31274,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJc+qa6CRA9TVsSAnZWagAAJj0P/i/5aKKwVJL8hgsOgMBf\nu8H7/JA4tJ5/W4pNZKiD+io7Ofkc6NbIrtWZMai+oudettOxN8UUwwbQ0fyb\nBZuyyLAVn3U2Gh8QJmn+UkRii6kqGqfOFml5hJ6qi255pf7HLfP2CzsqFoJr\nkM7c86/vgTAadJbYMjACtMJuo+nDZ4KDmvH9a8Q5j2GsSIcBWUo7XFiCfH8B\nFmrluYu1rpOvDOTQSRPY+sjRkF4nv2mn28nJ5onC4IweIjTqmEpZpWhTsEuo\nu8svhVS0MAFAJ9KjR5X62v3Iq+EthnEOvogW3MoMfgRN4Cn+XdZPMhvXJlUY\nvni5s96jqaUQGAhrVcCxMW6uubDFaSux05ANkpjcwec5pV2UZHxocq4ZfUoh\nx1FfDVQ7huVGW7r5d48ABZ23qAxPc8Qb6Y+I9oVCFqR+h2dwuAPz/JxAHZVH\nbQuGZ2brQThJF2kFO+MQM1t+NnkwykCBz+EleFumqQ3XdQ3D+e/1soYEz7OW\nOiMBPG3YzRYPAb2CZ1DAxW5CqwZC2wd+9tGwpQtcqa+lXZlrtZH10JYU1g4a\np50iZUurffFuSsNpCxdTmIq9nggQXGme7cO2R9ZPD+bl6Vq5Y5veW6ZoYMKI\nuLocFzOdtIhcOhBBhM2ZR952YlKeOFyHy0j72M0Q8+L7hjwoHJ8gWDD/7mhn\n7gG+\r\n=QBJm\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDE3+6sKwlbjlDXNiLoarB1HteChHmKNZRl+fl1vF/ecQIhAK5Q5u5jdo0wx8i5dWfOflhn4DYeIdHH5JTNf3KnktI7"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.2fb1140.0_1559930553795_0.06402752704657"},"_hasShrinkwrap":false},"0.0.0-canary.d9a277c.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.d9a277c.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"6.0.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"0.0.0-canary.d9a277c.0","fusion-test-utils":"0.0.0-canary.d9a277c.0","fusion-tokens":"0.0.0-canary.d9a277c.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.d9a277c.0","fusion-tokens":"0.0.0-canary.d9a277c.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.d9a277c.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.d9a277c.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-swDv28g+LBzGu2zKo1oQOBb298ztzfMolQm/5bkW0cUSqSw7CC4yNqn2u6eAwvYQ9NmmQ+8e7P8CdEiRXstRMA==","shasum":"ea0960101b18fdd9792369178bcc842761bdaedb","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.d9a277c.0.tgz","fileCount":18,"unpackedSize":31274,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJc+qwGCRA9TVsSAnZWagAADaQP+wQXZnzFEboMolyoQlYm\n0IU5TbXz4gv3UmdQz4joc0p6k9j90+TTWEvbUc5fEZfjDc4QNqfvrvZWANlL\ndSqrqaJsOXWwYNTWTwsiwgTCVt9itwYdPjnuy45dFeR7Mb+T+Ahq4nGXE33C\nVlseCqvYxdh1VylDU4+IdVNzqkn/AjZr1R0meWrdoyuewL4yle3qJPwjbPhc\nDUFYMvo2Ysq1bT+eyV6LknCJoSO+Bsd+3m5eKW8CtABJVihYAwd2W/GqqSSP\n+J2p4y+lq3CF4OtUpH+2lcuz5R9IZGrHrIj5D3Oga6baxTeTEEURJ0hmRXpt\n4ATN0VdtRb4dCn4pBHYmHbn092Wrq+gzWms2MU998xt9OmyJ2tyZjvUrQOQp\nhwQ7lazREKET1tvLMyzHL7eHsQNiDboOypjqobi/vQlRRHly42dUe1mgmOu8\niX+WZaZ670V0fCJ0Ca6/Gt8Y29MHtOZJbrnQ/hp9j7ij4xEskUvYC+cSwZCm\nI4fOUdzDkIFwFpaKA+fSFGECvaifBPqHQY3QT0Yrf/rUuN/SKPL2+dRf1DZq\nzrGpba3BYiJydtZRK7ofoVlGNXySwdhRMRlrem5VcbFPgEVVpUjZkN/OtXew\njQ5eJnApIHqyzVt5AsR+PwijCPZ3Q+ijm/4QqUVtjiK780zo+qgAlgwI1Oac\nx/9d\r\n=i0L9\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIH0vTJDp/YGrJ554At618uDX8BiLnPVzk4tTp8u7VYZWAiAQ8IqYQ1UD8ETBJd8s3yqSpOwtczkv6FyuvaLBlC9jzQ=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.d9a277c.0_1559931909987_0.8991734049024085"},"_hasShrinkwrap":false},"0.0.0-canary.9b5e4cf.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.9b5e4cf.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"6.0.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"0.0.0-canary.9b5e4cf.0","fusion-test-utils":"0.0.0-canary.9b5e4cf.0","fusion-tokens":"0.0.0-canary.9b5e4cf.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.9b5e4cf.0","fusion-tokens":"0.0.0-canary.9b5e4cf.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.9b5e4cf.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.9b5e4cf.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-cvRcTlIVvVAslkMnyYtrnrPqufoNgp4UxmKeRdxeILgSGFHPQOzbWIPf5YTzl8g/O2f4m7nznFVfyMrVGf50lA==","shasum":"d5ed7bb2120973825c543a934062cdf3466baf6e","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.9b5e4cf.0.tgz","fileCount":18,"unpackedSize":31274,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJc+wSUCRA9TVsSAnZWagAAAjsQAJMPzti2LnyVMwQTeEVM\nzCi8jBUWC74Js2cnfQu83ZFpqF3Yil2R0uAY7j7W0X2TnRY3XmczvCwHrF8g\nbxeuVZ+gGYnTVwpOOYhKwotuEhQRBw57JLfIrum+vps1FzjX4hFOkdIUoWSA\nnhKppv7yo50jncmTEYTJPSFnXl8xVZo8T/Mb5+QMr8hXdV67f+ghOjcPzEM2\nYtEf55sAVeNQCj+xnCQ4204BpSZBGpLu81oqU1QSKd8qrght8PRCcIDgiJWW\n9CSDSD6zvYlmk53AdCG8R279dNjke2x8yK6gcsr9H35Alqd1bbeqV6uDylgL\n8p7dJii346uD9Lb5CecvmRDktorXxD/sECFeaXpBoVFwBDAAw2EvlmXASBmt\nSdTrGAxwN+r5EVPg6pSEa3go6MvAZcIybLIoLbIIs97waz4f8DVDqtcKbK6U\no0iqkIl0zco9TkXNqQQUvysQ0iPvhddJjzg3YovDkTeP6sup5Gg2PZi8dOJU\nU1Xe1dG/9jl2CwA8CVfpGPc5uKj8QMuqaxhgZ20rr7gpMvgPK4HTiVZiCeTq\nRc4Gm93HK5zCMJ3BJNbBuhJl+vHcGDR3BOm3hYB4M72AV3WHQ0cloY6Uw4ie\n+8HHvI/JVmaCbETTG6AYNGGYpvcDkGhcARmYtYFboi18+o+TnXfvLjrfjmiv\nUe6k\r\n=gLqp\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIEteJvkQEZIkxkFUIpfr4qazMcCbxd4MZQC8h+yewaBXAiEAmzAP6BYuuPIny8wE7b4wQXgW9CwHe2TZOEg3dCqOGIU="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.9b5e4cf.0_1559954580179_0.8303958653197998"},"_hasShrinkwrap":false},"0.0.0-canary.43352f4.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.43352f4.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"0.0.0-canary.43352f4.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"0.0.0-canary.43352f4.0","fusion-test-utils":"0.0.0-canary.43352f4.0","fusion-tokens":"0.0.0-canary.43352f4.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.43352f4.0","fusion-tokens":"0.0.0-canary.43352f4.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.43352f4.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.43352f4.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-0kyKNg/qRpv3Plhq5LzNuMVhnNu9HMznfA4I5MniwS50PcYN0lmOGX3Ck9bmbl8GLJBO1x/Gj90n+wsq2x96vw==","shasum":"d1e717b0d4b4289400d312ee5b3b2e2f2d26d161","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.43352f4.0.tgz","fileCount":18,"unpackedSize":31291,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJc/qe2CRA9TVsSAnZWagAAyZMP/RI3RYJf7UGGyjD2tYUU\nc4BN4vlyr+HL6zysbHcMFf3eTyu5rIzB1wZUc5a8RhbVmzZXFO5hlrDw5NTl\nm/HOTJobBKUB5xddru+8LUxDMaofzOh6R6AY+7+sNuPCih4kybukd17UNTSi\nms1a1s3CjC+VhgxgAKWeGrFTvHOkezO8lWL0+jNYpYB/i+p+66vfV7KZl5EL\nxUvPV+C/quuKd8Wx3krj35gkQqgDL7bk0EvgiGQU7j1FmDRj4b4WhI7u24Wr\n6TK4QZ/ZlS2ayZpfwgqRjraTLtZTmnnJKoayF1V/TAvPYISu2XX0MNdS5iZp\n+HIUz4WdlPhxp62cMXMChPcqUqEUHRwi2UncFKKmXNwxHQC+JlrMXrP1Jr25\nWSaWxgPiqdFJ2jFKwV18LxNjzq4bDVGVXRAHuLtErR5bQ4qHv1/9QYHiM5I8\nTtVTFOj6q8Vfw6tXmOrBduEZ8JHArBAg1EDteZ/T23IsEMj4hXb/L0KL4jT8\nA8wWBQqe74V3ZJSpm/bzY9hfGPTfvGZKA9k0voWMYVbFKhmHoke/GuhEzB6r\nOIwJo7aPa6uTi+otfUfudij0W5dgbazZ2e4g760dPQdG+8esB4gffmZCqccY\nzEehGx1zvMrBNd6YSchV85iFfERGJJ+y+fehsHeMEFhKvfFre+oqfRVc+moH\n5p2L\r\n=anpr\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCoaL7/cv6/legOI4HDbRi/eHr8d35kz5akauiIabCs0AIgfqQWGo5+F22443UYAY7fs/zSM0Ocqu65dubtsMEycQc="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.43352f4.0_1560192950285_0.2964474374613666"},"_hasShrinkwrap":false},"0.0.0-canary.43352f4.1":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.43352f4.1","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"0.0.0-canary.43352f4.1","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"0.0.0-canary.43352f4.1","fusion-test-utils":"0.0.0-canary.43352f4.1","fusion-tokens":"0.0.0-canary.43352f4.1","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.43352f4.1","fusion-tokens":"0.0.0-canary.43352f4.1"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.43352f4.1.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.43352f4.1","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-sclMIWSGoFo/ktSRkn5sgElRtLMta7mU72AsjjQOkndnY/TrG2qa908/dH2G5M9nS3UbTIGlu+VyvcTxmub/Jw==","shasum":"ad35874996e78137d77472c48b846c4a60f29fb1","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.43352f4.1.tgz","fileCount":18,"unpackedSize":31291,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJc/qgjCRA9TVsSAnZWagAA7UcP/3/jW4ASHvfGbkbSbxpM\nK6f+stOQ6HeTReuI14F1aIlP87bg0NYuH4ddx8gcxhd7R4LAmYbw4PRVAc7f\n0qkzrL1Ux6C+i4m7LcOvKhXETB5RzzJ6fXnFiDhNpXJ5OcysunJfp89e/yp5\nyXd/CojG4CYTgjMixsu2nJ69zxdBnh7CZOStDvD8yY/8iutTdxBQwRI0SDzy\n3gDjoqgg7FWgZlq7TAD7YpEjdsvltWzEBEK5Rxuw2o+uXXfOCw1f98Divyij\naKEa27hq92UHIOMjeVcsE/qmALnHI1Ns1RPLscQGfcBFLANEimiKg78UOZIn\nnfhyFGCWJhgG5U43mQYFReIhqjYld1t6l/jyteB7v5O3SCchKeRT1LGvNTF1\nu53kptVfS6rdxcaz2XDvpWP/xN/eKDGvlWO9G3z/XYDBTxVaTjQgkXuk6tEb\nmCCi7iQlX60d5CeiR4+KXH9S2lG+Ze+YjuDjwXxP7fyk7/K8M4bbxe8Sydl7\nLl5Fkfea4+FmyeHIKZEXKdZJjQtOidbPKb5CPBlh83K+QjF7so4xnlfKRmPZ\nZMOOSa7SbWlpnP+kdBj6gg+Chma7p2mqjTTAzQ6JH/T9VEsh+48zg94nd2A5\nfZOgfTgAzQD8ZM9w3ZupzC013YsU7vRDnTIPAzxC/nDMdfpSXYO3uxZotLbB\neBA6\r\n=jLFE\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIBd4JayTiyAzOASqkQFfwtX31LHUe/2Xlx41g+1uofReAiBCuMpH7Wb+H5or0WkLfHhbpNHHVQlcvtpXrlLn7f8aGw=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.43352f4.1_1560193058909_0.4350552996655863"},"_hasShrinkwrap":false},"0.0.0-canary.4fb3fa6.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.4fb3fa6.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"6.0.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"0.0.0-canary.4fb3fa6.0","fusion-test-utils":"0.0.0-canary.4fb3fa6.0","fusion-tokens":"0.0.0-canary.4fb3fa6.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.4fb3fa6.0","fusion-tokens":"0.0.0-canary.4fb3fa6.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.4fb3fa6.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.4fb3fa6.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-otlsOpFrdwd1AED7Y7ZJZPLEKVPWZTi2E/adcCLJhlo5eTQW35TNg87318MohxdR/arHvFxmRe7V1iIIcwIL7Q==","shasum":"646146078386d6e0cabde9b6f87d1592bafcdfde","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.4fb3fa6.0.tgz","fileCount":18,"unpackedSize":31274,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJc/qmwCRA9TVsSAnZWagAAJtAP/1RjgE6n6OhPRk0MRjhM\nrajFMdgR339TMXxFs/RZ8wbFczTq3qh53Jzotspuokefr/wbRpY8v4WpGrBo\n8cYfcrjlPlDAsoUtcvNWJgkoYj4ZBi5YJ1UV5/hCn1Ltt0/ic/9uxZQMzNtU\nby2/YgtvunWjMJNSDnV137LYG4E5BDYCcOXqmIBP+gZDlY0X+ONr/h1SuKCi\nIAV+3w5WwhVCa6izxz2cRK1ND22+GzR27OrACOFEqOw4fsg8t5g9zgKMhrSc\n7sMJV9vVYAgc8pG9tyQZxJGIorFSSPx0cmPU0bqRIjF/c3iQgfK24LPdtl4o\nEITN7GoGrzVRA7CF9uy3viR+BIp4EwSFJYvIGg0RDplfGw7OBS9Q4xUhox8s\njoGoSgElAajOVkb94LOZkGK0rB80x3lWx8RcrQJQAi66KTD6KglDHNYcOX5X\nV71CrI4/Bgiy+K4ETK3WmNeCViNW5wmWq2/9DFAOuYheDjuLZlsU/ZL8gkEy\nz5k1s/NVQ4JCUJUxEEjutBYjzmdjPOb4ogFWPXXkdGg1IhAoTsC0PDWLvDqC\nvvbGSMcYhs5JvRXb1SCbhBaF2bcSNXFIfhIMatVGHRyftIxghu+rzURGAqqV\nUMra7LlkN4OvtLGqpnmmIezIJQ2V8PLInNQMu/p0EBujiRy4AveaKXwRr1yR\nUT89\r\n=psgk\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDaEx40bMsmOTNuxICXch+3ph++SbP9R8F9KqShfJ+ELAIhAJUB1+2YMCemVYE87d2CWZRHRGrKeE7nfk2mD5JW9z3I"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.4fb3fa6.0_1560193455958_0.12266581211719285"},"_hasShrinkwrap":false},"0.0.0-canary.4fb3fa6.1":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.4fb3fa6.1","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"6.0.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"0.0.0-canary.4fb3fa6.1","fusion-test-utils":"0.0.0-canary.4fb3fa6.1","fusion-tokens":"0.0.0-canary.4fb3fa6.1","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.4fb3fa6.1","fusion-tokens":"0.0.0-canary.4fb3fa6.1"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.4fb3fa6.1.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.4fb3fa6.1","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-f5PRDOInSElVeL74Yq8zR2TBlZ/aQ+VzcbmRx8POAaDNguxtYQNP1J6Lqqx/nGH6cBD5EzZkZ1DeEcQAWSuxtQ==","shasum":"b3b893d40a6a18b17998c05851601276e8bb16c9","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.4fb3fa6.1.tgz","fileCount":18,"unpackedSize":31274,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJc/uhHCRA9TVsSAnZWagAAvrgP/ib7t3W/hzjTrXNFhItb\nFnblMt+ZMg3vKrm+DzSEeeEIQ2YN6tZVLCtwdoki8URdbJIw5163hCPwcNNU\ng21QoCbiP4jnTJuKfrp5GFwESEPdRJIXS0Z6l/gDsLa4cmObEynqZPFpnnzb\n8weOA86rl4S+P1OhYpr7Bgd8xXsw5EVNv+pDAas3zo4vUC4lgTwUs6d9MgYZ\niUe02QGmCMM1vqp1JxdT9t4qZYU+mTf7JdaMcJNDTvSWpIQNgulfkf4MbpYF\n7iaX2CkP+AAyQdu4psMWb90QQ0DC/B8XSl/Kqei55YP/WSn6ULPFPFtASWxC\n1nxeAaHTrSl4QGA8BiLUhc+ELZ+sSkj0z3P8WV1Em94fSRvYg+6nBktUC4Lk\nbOBk4b40E5GaU7cqcuR3zIK0PiFVIe7ez5WrwgpZ5kQ9yMejBlhG3Q19gPC6\n+iNQw04zL6Jpz9GO3OHzRWDsnsUNWOCnYQyXr48VJ5kPR6nbU+Cum3ps3NQt\nDgddqj4xiQTMN+v5Uhj0l1OOdQgvDVhKVDFOhiCxn+FwjiNHujQHuVsbpFY5\ndEyuJ6MY01rdZXZyUj9q9r3juqYh9AP0BUJDvfZbrxvXQRyuSMoQSq2cfM5Y\nf3ex79b7InIUg96ccqHepEl2AnEFqnX06nOfD0/9rh2k5GfXPuQgSod2C8V9\nic9i\r\n=eYqd\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCZUOIjqZpmlkizZba0c0e41faxBu4lt91Fvbelsp4MJQIhAP96MswMC7nx1+JoNrW6Wvy+ag4whhMSZhxEaX6oQhrJ"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.4fb3fa6.1_1560209479325_0.36811937305980313"},"_hasShrinkwrap":false},"0.0.0-canary.72a6835.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.72a6835.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"6.0.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"0.0.0-canary.72a6835.0","fusion-test-utils":"0.0.0-canary.72a6835.0","fusion-tokens":"0.0.0-canary.72a6835.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.72a6835.0","fusion-tokens":"0.0.0-canary.72a6835.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.72a6835.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.72a6835.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-PP1wKbUS8Ocywua4PvwXJZX7uh02o4NmIJmAiC15h9rfIb0cJ7w7IRL3jhO78E1KzcW8XhTMp95JhXN+ut2CMw==","shasum":"7d12a3753deed7de5d0faf22e030c05ef53d8682","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.72a6835.0.tgz","fileCount":18,"unpackedSize":31274,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJc/vU/CRA9TVsSAnZWagAArIYP/iwGnVstQpYwiBT2Gxqf\n2N3RYixuYxq+tpHYUm23wsXscRsTeGh5ktRXAq0XRtJ5fF5bm5zoyPeqkDTU\nrXc1dP2Q5pqCejcTys8Ddcgl2PnTMlaGY1aLCjgfY/wGuRtrAm9RJkzHPpvw\nmCMvqXdnn/0va0X7Xs371pmGUNPOq6gdcBTRdOxfeMivApI2dyLVaPc1TWV5\ns+Hcb98R97CXnuJPP9iHtMgq+cHs/hcJWoJTrFHklIWHMEmmEQLhTsuYZb+u\nzI3aOprUhr3WbRZy+JNp641HgyJ4p1u9gQri7ydUbmvfxQYsPD0W5tjvNHu5\nEcDROadjDvMA7YwYt795sYmSXO/SYxBxStL9FgBUOY2BCnlj+ThxfEnW7hhR\nf8vBrXPG06aZWOglOcKdQ9KEAFW8iggxHEBxFsysznjUednMksvBM2VrCIgE\nUM3bpD4SKok+H4OWWByXaryXs9crUXdBrNu8eF5y3Au6hRRmSmzauiD4HMPm\nbm7cx1nkK3+NTC5TcbkGbjmOF5n9iNibGLQFxh5on1ybTFrVbLGoet8EhNOR\nbSq4UN7zNvuDKLO84rkqRFyXAYRsIxk7X1uS6ZuvuBrAt6duH/92LJSs3+zP\nDkWB0XUCIkSO2m7FHkCv3WpcgFWFLuj75pv8lFgXBQ6TCiOaWgHDREyf87fg\nLGh4\r\n=rlnp\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIDKDideroHtaYfMuM5umLaSATC6Tjr8W+N9n/FHdwQpsAiAGo7Ts4RsFGRB8iZeTxkmUwhuyzmIi0NfCOReZORK1Tg=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.72a6835.0_1560212799069_0.8421090040697052"},"_hasShrinkwrap":false},"0.0.0-canary.af0fe55.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.af0fe55.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"0.0.0-canary.af0fe55.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"0.0.0-canary.af0fe55.0","fusion-test-utils":"0.0.0-canary.af0fe55.0","fusion-tokens":"0.0.0-canary.af0fe55.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.af0fe55.0","fusion-tokens":"0.0.0-canary.af0fe55.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.af0fe55.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.af0fe55.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-9SkbCQx+MLJZQMXoZGUnytPXAAfgB1517sN8RijoGJcfTuTtoWQ4KXPcrnH2FIDycEcFiBfgOJ1MRi3z2MJcYQ==","shasum":"445a471dff52b53969427a5665fda4beef907549","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.af0fe55.0.tgz","fileCount":18,"unpackedSize":31291,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJc/926CRA9TVsSAnZWagAA1qUP/iC0ZDUY1M9wTzSDf83R\ntHKjG/Rcrnxajncv4Frrv2wfz9AgBgnwYuuFZwnHMtlyZkuq3z8zBq5hLJUa\nuDwW2UX91c5Sd+sCzAWvR3t4GvtPkTKdaa/uClVmsVb+xJ6+2wRwEaGFZEBU\npP/YNNJxkkGVGwN27CyPpeeHR08jHfcm2Fr7TeEXKgfDHbcxjuhdkZDcjr4H\nMIj2F2IU/f9CEwOOu6o5ZqLX7ArQjGpeQzIsdaQjzKgjbCVt8J8fYkW6F2ai\n7iOyEMl1gckRDRmdMgQRf3btfvv7R2cucucyO864bJSHn9U35MqTQPlTrOWM\nkKfq1/FxmFpsWY5vcDP1/09HuN+wv26JUUnJxaMybGhfo/DXAucwT7I7XAsa\ndiI4IaSVdKZXrChfYuw98qotm86MoTpR5hRWYCWOFgQZlyd1Hd/l8+KkAmj7\n8YxUAd4betAxhooSW4iL3m+gyvBLyzIGHHXQRKI1077I2NxI5obbpjRRgCng\nMngfmGNOietXTPwxajlxWiUvMGfM2TNwu3gNHHj6uJUtITR340g44sLtOVwM\nqagyji+//d51clFtoRtJnob16XSTWCqKZ4tTZE+Zp2J01rRUyxKxTknpOynJ\nSdMTSrtGn2GB9hyhGFJ6QfSoGA2HxL48qCkPS++sAS9B/nUuPoLHhcFgDLu5\nWmdZ\r\n=pWm6\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCICHAupsxygzP2phaE1DS3883Ro64gKiAwp22Q0r61Ag6AiB+dE9Bgg3Nk3DA79vdNdhxvTdMg/1DNLUHYhdAPFyPAA=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.af0fe55.0_1560272314216_0.9581730436946139"},"_hasShrinkwrap":false},"0.0.0-canary.af0fe55.1":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.af0fe55.1","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"0.0.0-canary.af0fe55.1","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"0.0.0-canary.af0fe55.1","fusion-test-utils":"0.0.0-canary.af0fe55.1","fusion-tokens":"0.0.0-canary.af0fe55.1","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.af0fe55.1","fusion-tokens":"0.0.0-canary.af0fe55.1"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.af0fe55.1.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.af0fe55.1","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-DOMEav9M1Um4+V/gfPr7BffNsuqthfC6v4T6EovLbvT0dhaA9JviByB2qrsWYkDgZcYlQLDtqbGxuZBRhn111w==","shasum":"91fa05739570d9e51cb29b4c49759447e0fac2c6","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.af0fe55.1.tgz","fileCount":18,"unpackedSize":31291,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJc//EgCRA9TVsSAnZWagAAAbwP/3SRq3COHwea4NRyK+X5\nE4Vfw5eIF+RwwR8+6qvmBj78fQKZRK8s3CbmdkCzNYv9hY/IKngjrrOJ/oDn\nkw/0AZy91K9Dm3kCAFUtvxh/jD9FicGbU7JCg0ffS6AL5I69+ROkuGwKysp4\nmiHYjPlWvf5xSdDVgWefbNA1KYZsF7uO+w6xwG0iT0BdwwcP84GeWFIrb20/\niukLtK4Ixq3bjabjDNRbB3DzPDcK2NfwwhyDsTl8IQb7Ec3u7fXXy2lCMX4j\nHNhTo9Z2z2/gAwpyclm72PbWY7yflWkMYV8DWRi0fkcvpH9zUtWG8z1teaQk\nq6Bq/1NuAfm7HWMVX62XYcM1QHhW+bD/rb1CnEEvLBGyqyhPCMKg9lGYCCHI\nmavQ9JutfjAnn2jmkahdfIRdScEkbASI0LzUmtyLYHwCr8/FEQNvjSdScyxl\n1+4CE1eqBo/hPXEG6INk2RhSvmKCWx9fGkT6gfAPKg9l0Afu2ph8V0yo+83f\no/p4QQr/etQBygrRvbV2a5WTnADAMmsYqdHG/2K0zvEkgsc1K9oaM0OKrSSy\nMfgiIaBn4gKt1re/rIzjUvgGlxVEE980PIAJvUT2iJfCJcQRrbXE4aMMP5RA\nvhWkzTkVSBufW8BdFiXVun3tKGh56G4zjHaYCAmPln8QhIvrUeosgwqtd9KA\nQlGI\r\n=pIEF\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIBh1aB1CbyTa0nzBxC8b8WXrFjXeavOQ8BycafjOrbF5AiBCkO4odJzCChySU3wdOU1sIU1kce9aN3M8F3IoJKA8iQ=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.af0fe55.1_1560277279652_0.9863878700595468"},"_hasShrinkwrap":false},"0.0.0-canary.1131efb.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.1131efb.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"0.0.0-canary.1131efb.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"0.0.0-canary.1131efb.0","fusion-test-utils":"0.0.0-canary.1131efb.0","fusion-tokens":"0.0.0-canary.1131efb.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.1131efb.0","fusion-tokens":"0.0.0-canary.1131efb.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.1131efb.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.1131efb.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-azf1lq+hsD84Tjsrfq67dngSdIzfv3KMji2IgcdG0L1EBUtX4jP4AN8CVKfzAcC/63YwrE5GLocsVjasqRkBOQ==","shasum":"400e8275fa6f83d8eee09637a39db5d7879e10b3","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.1131efb.0.tgz","fileCount":18,"unpackedSize":31291,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJc//WUCRA9TVsSAnZWagAAVxkQAJENp1xXGotWabp9yUvq\nwxREBNQEOiEnaJqMKW6TUns3GjHlWb5H3wyl/gw2AxqOFO/9dBzQsUzxXH9+\nKrXF7cxwdklIqkj8QEy1KW2rLJS2DeZidOdosmreGboxnJ8YMIS3/xgww0ZS\nW5uRtQ6eg4ILv6yWCgi3YOdwzVh/buDT9CeFXsmYzAMgRCF6laccYT9GOc0M\nFS2EsdUFok2Cmgk3BU9qHCv+JefJjptVUFzRKbdp5uVnuygIzC/ErtWuPc1k\ndKmfEC4L76YXdb1TO8wqqrTVzJkTh7M9OyLF0ahItIQzh3k001M+T7El49aa\nahIkecr6e3GEzEJsiOsvwyagigrMj8KhqmwNze1jmuAGY8DhjQD6VuaRymhF\n914PGqbiZkWCZZwNQCOKZ6YVWd4THKPe9am+94iMvkk5J67m16Eep3zA5Wva\nf2yL8CTjTbST2XLsnq6QrQbUomS48xAO1BI4fSJFtStWoiXmvfKAuRYHmE0J\nUD0OHwWUIHpF74YWZrkPrvEYBpxe3+KPxzXzpC7WP3D+RJ0e38zZwpYDS40D\n72WK0rpGq2IaFZbXAGJAy6cLDAEPrfnbbY1BdTBEXJfPunc7h7kMHcrc1vut\nx+zUPjBa7ajtaObnot4ZDptIBMPohWq3NSlLPekir4gs7cQ6ppdQtrkpaYQk\nFszV\r\n=akCL\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDzle28bokfm83U+8o/LJm6ZiUECELivb4jUtSi5ot3bgIhAJwKfoLadx7Zmrk3aByqv4or31xdAl6kakKu776Db3PL"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.1131efb.0_1560278420042_0.7831463767682989"},"_hasShrinkwrap":false},"0.0.0-canary.2fcf0b5.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.2fcf0b5.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"0.0.0-canary.2fcf0b5.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"0.0.0-canary.2fcf0b5.0","fusion-test-utils":"0.0.0-canary.2fcf0b5.0","fusion-tokens":"0.0.0-canary.2fcf0b5.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.2fcf0b5.0","fusion-tokens":"0.0.0-canary.2fcf0b5.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.2fcf0b5.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.2fcf0b5.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-KTwpm2QNqt79lNje9demRwCWlycbD+XIklhSKDdfxSeEyKIOcB9uKzbpqjAjks/Dyf8p/VdvgHMCHR2PkvKMGw==","shasum":"a60e09fcc824587160f7fd75308784b509fd435c","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.2fcf0b5.0.tgz","fileCount":18,"unpackedSize":31291,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdAAyMCRA9TVsSAnZWagAATwIP/ioVVvDGtbthSIToB/uS\nlaIKkcwh8Lh6Ussb0oC4eGu2rGN+atJMsClazKPzxmKYYnNAuB/Qzd91ux6a\n/0h6G+9dxxioiDX24ZcSnH3VheGYNGbroS613tFkunzic8JubQs2VbYHoQWy\nM2DmDb+AqNW7oY73XspgBVMu2hq+CUc9PcwUw9JVHsXH7pj3TSu6rAlusUH5\ny/1We9DliN5t0QERfmInlp8bzzvD5uAWObp0XwvQ2k5kBq5YjOk8wWrScK7c\n8XW2VrBuWu5HKUwCetyfSyR6eH6TWcbtzkFM8qqRbYvb4g2Jcp69dB2i99do\nt0YKL9ZclnJ3lgPSXYBGuofCkHkB4U0QcJ6dd/4IEvKZp0XHRO8cHRYWtqeP\n7kKJdDv8fCEd0Z83TJfy+TkLqga4CEZVap/G/1elwqF0b+wTsjGai1zR3Fzu\nTQ2sa4vsT3Xe3EeC4mOw5/9nRni2QYXCgnrCa+ivKslCKm5T+DR2WJgmc4DJ\nEQO3HNxDJF+B073AJlL0Mi9xxMtfh9cDYo/N1hAYuT1dF/ZETsHiSQIktr7m\n+48xndru+kKNgSZfH9y6qeIuTnTduC5YQf9I8S8donGqT7ntilHRCgWexLuK\nvlrMEgWoeCc9YD50+I02hHhS0TRE8UjODBV3RvVNjNwke0sfKLZP3YngLE8i\nzf7P\r\n=rUnJ\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIEy/Jp06sUs+p2nM8XRi0LbuBUhm0cSsGFESfDo4KPYpAiBF7o+/DrpagcgIG3b5nZnGIQ3lLnzUAXvMBFjWAUGrKw=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.2fcf0b5.0_1560284300196_0.6595624485371865"},"_hasShrinkwrap":false},"0.0.0-canary.2fcf0b5.1":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.2fcf0b5.1","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"0.0.0-canary.2fcf0b5.1","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"0.0.0-canary.2fcf0b5.1","fusion-test-utils":"0.0.0-canary.2fcf0b5.1","fusion-tokens":"0.0.0-canary.2fcf0b5.1","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.2fcf0b5.1","fusion-tokens":"0.0.0-canary.2fcf0b5.1"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.2fcf0b5.1.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.2fcf0b5.1","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-fF0odjqdSVHkWRnxfLIYaWw7A+68gIYj/kC8umAdAIMMj/rk+oW4OTRt8IYNZym1BIqRGqFgtt4mdAJOVkeVDA==","shasum":"bb1794f1bbcaaf6fa9fa70279633346b519fabc6","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.2fcf0b5.1.tgz","fileCount":18,"unpackedSize":31291,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdAA2xCRA9TVsSAnZWagAAjtMP/1pIm7GfOL26rfL0n1oe\nZWdktxaYRRHiBfQpu3WaUPnUyjodPlkHqwBLsgLyNjWjr9zpDF2JVpUUT5/o\n7oOqqLEbaOblwgdgvpo5DfRlb8HK+D23d4R6U0PO9c0zq/fBw7JJlTOa/gY4\nV6Z3oXGpT+7Ns6sdnYNP5ErWdHgHDODx/tk3iwarZUcWjJ4TpmU9DT3RQch7\nLdxeZwsNeuiVfSgd9u/5IVxUGEvaCq+xGflXPc9O906cqSURPQBeC3CyI0iR\nQ8TF6JjEGrG+4MCIO5ptfN3Pvu6Ecfo/NtQuJTb3AfHPnJzO7rNIaZSxCLAB\nMgtuPyPmY2NrGA8WboBhZnxq2y0NZ2ijORKDylKKWjNN7TXjmeOGDg93bP5m\n2heyx+UKR1VMQHjTGNJUs1OkB259ETrOQlxvsj3r1ox1NrBmddIdBsq2K8QT\n5xZ4PONK0W8UuPUabNk2gw6evUHdjdpN+QSjZx6AD/Bop2m4z5WbrZFm/A9o\nX6slmCXZACCsIXmeLJKxDSOoT5TQoEY9AE+eLoEu4tv6n2V08LhFCptxvk9O\nCQHQUJZhQJUZ9U1ad78585RdSqKN/Hik6ZPR5Ibe/RGx0XWNPHauQMu0aUc/\nJddp7WWLZptXyGeuvNL0h3ZOVYbyHmGa81YgXsZPoA87RsHGwizLJSsmldaJ\nRv72\r\n=Pkox\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIA15CoomfqzG0Hcrd8LeGim547BBeiSD+05MpYYq4XccAiEAmiang0wwGZn0j2gy90TeY8fwPj93aYqf6+UgHglGYyg="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.2fcf0b5.1_1560284592593_0.7510931968352179"},"_hasShrinkwrap":false},"0.0.0-canary.c237758.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.c237758.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"0.0.0-canary.c237758.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"0.0.0-canary.c237758.0","fusion-test-utils":"0.0.0-canary.c237758.0","fusion-tokens":"0.0.0-canary.c237758.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.c237758.0","fusion-tokens":"0.0.0-canary.c237758.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.c237758.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.c237758.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-ebC7ofyV4eiOnY2xFO+AkAiTTaMbHsO0YrnTsIVjvQtuuqY7/3eTclKjUfP2cL0NyJRA0wgnCOt8wrPriUi2BQ==","shasum":"b5d9384415602bfcbe25c923fe0473ed4496a704","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.c237758.0.tgz","fileCount":18,"unpackedSize":31291,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdAET1CRA9TVsSAnZWagAAc1wQAIKsWc3I4meqdR4T0BhE\nd8qq2rujvz7bhX5FsO6L+AVZ7HmxFyYsM8Bv+IxhydAAmgpPF4Po9YNwX1De\nDr80Qge57brdqcTbNuPAIjfvZ0bQMVEnK0Rw/DXLx/7bUhmBf5D/GpCy/f7b\nMHOww+Q5oJNSURr4KkSCpTIJRnLBbOUD4sX2qJ5g3vhR3cwBP8NC5xhbo/5+\nKtvbp7zOfOzBX6IOwdxLrbxtQDq1DoYLpNlLZV306EfbtiVBUS+CJ+ZFIPeG\nDT6Ac16CLmuHZZfGkRa1YOtdjPTGXVS0Dvy87nAd+hmqsV+ZRoPxN76UthJ0\n2lyDZ7AqeOpeFrliZBdwCs8rHl2Tm6dB7iNi87Pg9YwHXlCv156KHxCa2e0o\nn5BYXR5+8MAUyujFtSauivFaUiXHDnDI10hrAGbOd1hKSFuEHL+bWQQW0oC2\nd7obRCtAP0bvHtEMQMZNEpD+/9ynrJreqL2M91g+9ba8q9ycxMqHb3JZln3G\ny/UKOMwazBfycFwg8wwSiMxiasZzdpZBbCeJ5VBDGRtgJgz2gSCyZXUgqh+s\nLPNAl9CfYEebUCiYh0LxJFIlowUVxE/e71G8uFE09zHQqegFq7JmGtYBqb8i\nTnBrgL/xhmiser+8dXnyzrkCmK5jZPYxyBm3FZ5T9Z/QXu4wRXgUQMkvIoov\nxA+s\r\n=fJ3G\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIGQDWMhgdt9XH3Pe7oe0oQlZeZXrHXlKobnLzXUeY8z9AiAvG9IAdnNaccjcr5z59A9JwysL/srCWoAdTBCF3ib2vQ=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.c237758.0_1560298741196_0.2015246666574202"},"_hasShrinkwrap":false},"0.0.0-canary.8c0849b.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.8c0849b.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"0.0.0-canary.8c0849b.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"0.0.0-canary.8c0849b.0","fusion-test-utils":"0.0.0-canary.8c0849b.0","fusion-tokens":"0.0.0-canary.8c0849b.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.8c0849b.0","fusion-tokens":"0.0.0-canary.8c0849b.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.8c0849b.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.8c0849b.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-YU5GDiRVWa26mexWLdMq5AsALaXKvpDR/gtRmPloJwzny//VannDCT4sKkdfp9561oGmMTuPWu2KcW+9f5VGiw==","shasum":"fe50a3d6e045cfab36c08822ffe8a64e9af24d12","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.8c0849b.0.tgz","fileCount":18,"unpackedSize":31291,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdAHBlCRA9TVsSAnZWagAAMBQP+wRBFqtJjH2QSirQhFaY\nqi1PXcamqDR9pct7qqnyBfdJOYIqcO4aX0VPQHWFOAqew0NSujZboOu4bgut\nzw+KtJkcDKqQOKf9r4reediQ3nDTp6eEvus8OmVFOo9+mGSwdsD827dWev1/\nBBxxxTwHZObwPW7VBxKXOa3Cgf9m30672yULCnt01tarGonrnY9zLK+9PK9d\nPG1D3v//PmL0yDwirkVK3ARdThFJZho8cQQ2CoNw5h/zhTxTJVMIcNHJqgsk\nOKATmmgTtXfsrmYrfd4XXhD3QYa/wQ7HwxcdLyt+covmln+M9HUPpX2Z2o28\nlsFIqL7ab9twgZBL+uwIpYx256LkkUb7t65DE+Mzca/xtwyJyGPCDSzR0vIu\n2TC4ErckyYbwh0J1kvyb4Z/jXl7XD4tqT+8Kp2S9FNsLGBOS6lZxlDSN1qIR\nsNeRPBbWPkKKHbvCKkqjx29BOqlAGvZIaQI/m6yMoMZawMQ3hczM4zhdYGoq\nHjMcZnfbvDdVC+atUhSFEpso6Gpu4EUaFOLA3w885s542g0FpJWR/QQMKSXr\nyxSg8YSqq6oyTlH7skzo1knOqJfUGnj50Ct0y5g6mXIeqW0O8C/e8O7prZem\nCASOWA0IFGA7/lkdpvkq1YwhRqs5woarVt0Nf1s1gObGcFe8cDbYcdaOH9EO\nal2q\r\n=fQRc\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDtiFJ2ZyLMJ425LFM0MK1dUfGG7i6uqUVZ2/JFonKbkQIhAPaXj9rSO9B7YOH3fxRP1nBzG/y3wxYGxIYLQCKKwld3"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.8c0849b.0_1560309860742_0.2872530134324327"},"_hasShrinkwrap":false},"0.0.0-canary.0b1303b.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.0b1303b.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"0.0.0-canary.0b1303b.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"0.0.0-canary.0b1303b.0","fusion-test-utils":"0.0.0-canary.0b1303b.0","fusion-tokens":"0.0.0-canary.0b1303b.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.0b1303b.0","fusion-tokens":"0.0.0-canary.0b1303b.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.0b1303b.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.0b1303b.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-YszP1w4oWjZgmSk+QbfacKGbz9Hh9Tu2hwHVbmhyJbx16c+zQ29ZXnlrrYeZUEkaRaaUWYEIfWB8Mu2OS+g9KA==","shasum":"77c8d3cd8f406ef054b840397d3250daea45acf4","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.0b1303b.0.tgz","fileCount":18,"unpackedSize":31291,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdAS04CRA9TVsSAnZWagAAXTUP+wQl8rLc2UL950DmQ8uF\n+QRNtA0YmcQh8G03HNdm7h6vB9yGUIlBpJ1cp9i7yX7YAcWuYS5Rf3QB4Zbb\nQdFt7GNJVYKonK27FU0a1XC0HhcjT00jmV4Y+4KNbJow76rUrokld9ZYGlct\ncm0UMH94cflDBzA0CrdIDtcAfQUHUtbrdGbFA5E/qe93250A4i8BEuRVrpzV\njwk1egzzgkO+hA1n7VDSh+nqJuUMJFok4lbQ3yfT0KD6GK4kfK7wKIasZRAW\nk3IFdhSg/FZx2xor2bc+L8oqhcSzf697OEx2QYzvNw6FwM0KEPuc058hdBIs\n45N1fKNkxwEkAPGu14QwoUD82Hq7ZJCyShgMYbvcIqOJyiX+2vK5QTV/lnVX\nDo+0hvdtwO66VxlyZAawTnANk0usxQ04g28OCDawTf9MXvXw6nDGd5ypYc1n\nbpkPDQmaszRHqfURi+OyDahvXCiF1nLG1im1j0DwN1cy+r1blmugB5cq6GPP\nGrSpM/zURy+cmASX8Q2rV3o1XpSSXByA+I4AQdhB6X/nnNu3qX3vSCN7O15e\nHzRmyLf0wFQD3qUWuPCHfdEQXxmLhGP/vuaLx6JAGFWGB2G2rQ7N4cAAY0PQ\n7LgodF4dPe46kiDI7N5ahNW7l730s8IegUZrK/twP3oeP7CO0ACCFdPCttML\ncnUD\r\n=JQ2b\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCID+UVrFlJ12vMNrK23w7ncxupbOeKTT6CNkKSH/JjE6HAiAshBynhiKqBTG02wJK7TWIPmifU7z779EE36hWHLXTPg=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.0b1303b.0_1560358198930_0.9103459734013255"},"_hasShrinkwrap":false},"0.0.0-canary.7cfc88b.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.7cfc88b.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"0.0.0-canary.7cfc88b.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"0.0.0-canary.7cfc88b.0","fusion-test-utils":"0.0.0-canary.7cfc88b.0","fusion-tokens":"0.0.0-canary.7cfc88b.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.7cfc88b.0","fusion-tokens":"0.0.0-canary.7cfc88b.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.7cfc88b.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.7cfc88b.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-FIY/oC4u9ll2d6zycAZSJ/mt6xc3u+gN8JoC8zq7yQDj5gkMGx1TJ+/igN7ePGTJ0Hu0xgXp9CuTAJMEV8JZsw==","shasum":"885e1cfa2e933c2b5279371c09966ebfbd951583","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.7cfc88b.0.tgz","fileCount":18,"unpackedSize":31291,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdATBcCRA9TVsSAnZWagAAnd8P/2QPIMBgw+k3Kvtoii6D\nWRJg06PfnVsx2iJtcTTOElD3qTO+KLkoyoc+3Qdj+MmiWtcRVbgpjxCwnbs1\nsXbv1f2n/5MSkM3661kwtsv+Puh0sgDotWm769e605x6Om+POqjBffWwWMZJ\n0yxp0FzttSeej/PfXCFlMsguInW6XJQWNM8ysLkAc4Vb5DHx9x8PDzqdH0Od\nGUT74pRwZdHDZX+lUibMlt6M+It5yWfTCP2i0N1uKlPOGLFofOss2zIG3SG+\nDv2EzwiDI93UFJYZXphTVYK4U2gNhR6VZYwQ/gdvpZ8R+RAXCZQoHf6Bc4zm\nni5XoKdbzzgSgCVIUoXjcjWSjS/H6W8s19R6E7X4S9FEPbqiCVnUg0OxbiEv\nD/1hH7xvypGINoLNQsYbhRaa6qViFbmgS/GDinO++2XsxD16bxD5bw3CEGu1\nN8m+NOrD0rk2TUbLnnUot7ICEoPBxalfMmM6pRJuGpxvTeMzWm2ZO5/eklRC\nIOW2QIuLlqT8I3odVT1eoA+MfU92ilYq9XxdJnM24SMihD+QzO2XJF5EczFj\nD4h4RQA6V/k7+dAvrIo3EbkpX4pk+3mfP8lv0B/1iCJkJXcokY0LouOu2DGD\nZTWorA13xtbj7HF/f9h0SOyuPuqvPZn606ft8qA/sRaGAmeMZ2CI+2+qBYiU\n5Zng\r\n=EApr\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDMvYXInfgFGedm30NIIghyzKVK5c/AmDYXDR4YP11sSAIhAMWqPLIDeTLsh7c2lwS6s2rMO/A7EZQJoS7ZE+bsjsja"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.7cfc88b.0_1560359003644_0.49253376886960964"},"_hasShrinkwrap":false},"0.0.0-canary.b7caf15.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.b7caf15.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"0.0.0-canary.b7caf15.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"0.0.0-canary.b7caf15.0","fusion-test-utils":"0.0.0-canary.b7caf15.0","fusion-tokens":"0.0.0-canary.b7caf15.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.b7caf15.0","fusion-tokens":"0.0.0-canary.b7caf15.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.b7caf15.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.b7caf15.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-G0CqMD1sxADk3nqZvfKUAGBZm8AJ4HMCWSSp/RXcPahUr8rrpWdthSvWmUEittAnIkPDu+Y6TkDyBunELLICRw==","shasum":"9b8d20b252fd8b8e992023a5afc7aad75a5ef694","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.b7caf15.0.tgz","fileCount":18,"unpackedSize":31291,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdAWk/CRA9TVsSAnZWagAAeH8QAIpPc5yTc+2OMyaKeUhL\nYpjkbarc6I9CVUBnqrLJz3191kLCPE9UyamJfjYRFuSxfl84UdtFKkOnF2Es\nsZIWepjo/L0xQO7jievUiOLnAuU3iCoSpkHcO2KH2KT+EXfgCSrGkLe7BQO2\n9LO4K/KHjjwPLv4PNMB3GD7EA4+vtsGekGXHX2DNaFEN6sBUdzqh/ZbR9b4e\nRD+zr3/TxKLuwdfaoUTihSASi7ZdSrQ00rnLP38EaIVSydYWCBT1sl0+i4ns\niA36OZi1ySqfT7xfCeJf/CiQrJ+LMUPrrTbHVP8bnpvuoNcWcWRG9h9KZE5Y\nS9B5NhTvJx7P9LGMUmsFboEP+kASoL1+P44sW7VlL3Jad10mwNMv/X7yZ2SK\nWSQkbadyMJ7NLvtmyaTsgKYadJwCoGT0u64vfGzJx6sVL3DLHJfZ96Hxanzo\nNDRXx0OWvL9DgH3s277mq0cmnkETL6LeSo50v7E0EFnkjAMBq6qtjCDMooj8\n375Y1XGqNVclij8MGjKXasDRBpaWrlW88znX5wyu8d5M5wtGjYJyMRiogZu9\nXIKbOsygt1cmpKWCX5A5Gpdtsuhxj8Tm13/TJcvWLY47ZP2/h+/eEBw0wFXF\ngUJQNy5VS0XSJJDpvwjiMHoPaeYQC40ILvHKCzCi5iAjOR8ENSP1lWmtcVjo\n0fem\r\n=A68+\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIFlaraI+pJGuIjcA24IRYpK2/dWnSHyU1x/sOToikfngAiEAqSJBCMnb3NDxNy7HzXx4PE+shL89YJB4nZaxCKut6Mg="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.b7caf15.0_1560373567062_0.12576275972524442"},"_hasShrinkwrap":false},"0.0.0-canary.b7caf15.1":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.b7caf15.1","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"0.0.0-canary.b7caf15.1","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"0.0.0-canary.b7caf15.1","fusion-test-utils":"0.0.0-canary.b7caf15.1","fusion-tokens":"0.0.0-canary.b7caf15.1","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.b7caf15.1","fusion-tokens":"0.0.0-canary.b7caf15.1"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.b7caf15.1.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.b7caf15.1","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-fgOAjJ87ZMGX5i3R/1ci7bqWkcSwAmiIyShpTjAtxWhRoMQ3jojr04NFW99Q40Mna2veeKbFAQD73F1ia6jc2A==","shasum":"b32cdac753e79f69127575eda39eb58c78207e1b","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.b7caf15.1.tgz","fileCount":18,"unpackedSize":31291,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdAW3jCRA9TVsSAnZWagAAUf8P/REeZoF4pVGIGvzPW5hh\n0s1cAPfGzP0VZD8YKnTazecgcn7wwSaPz3StDzZmckQ7u+yTi/FSCC0fYXTY\nqTSoClYKdcFPgJIuKZVU7ys/SSU4eIs37rIhDZ0ZLJjJ8Inn2FgLVvxJsrS5\nRUnaQERwImd/fetQu6S1Skpx8Ezzx3zPLBi8TGQ7WAT/u/1yAFuAk1+lbyoH\nQfWeVmJVCI1/DFoxD9VurTrOrqA3UG5yXks6SNGw+7HQNtEltZ+o7xm7h5Nh\nMxT5+u409rHHRy83QYfjFKiKYxKMCCkD8DGSpfaNh2ObpSEb/wWNcdJJGqKV\niBYDd1iGp3u4zgxUHxA9WFaLIL8DDw4u0m0l9ZKi9qgkWIYvUR3q4/PcemAG\nrbe+46EQzPxF4H6gBdLycsbVhPfL0eCTdzEJArAlZF78ZMZeWyLWlU0h6zML\n7muvry0gbbmmSAl1HlORZc1bxZPCE8Xwja+eXec4X2csKIuL6ikG9L03WfXw\nWRSHMD4kI57Kg2FXaps4xsPuK9H88s++5gsd8mfF+s9lexBIxkfvr6VU76qN\nbttbMs9X6zyAEfDruTXAH190qZt6BFw+aYNmvoRLxXw+/SF6nGpqVI4S+RGP\ntcypE25se7FALS1NGJEd3csx9jLW87e6egjKliqXvETkGeu2Mb1ec5oaq2S4\ntsgl\r\n=/wN9\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDE5xENos/+iTRgu59ytluaVJk7Jsc5UQU/cVht5CteqwIhALQAt1Cvvi+1D0rISx6g3War9Cf+ly5+dWjYhr0AoyC5"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.b7caf15.1_1560374754793_0.3007085160016263"},"_hasShrinkwrap":false},"0.0.0-canary.8ae44a5.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.8ae44a5.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"0.0.0-canary.8ae44a5.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"0.0.0-canary.8ae44a5.0","fusion-test-utils":"0.0.0-canary.8ae44a5.0","fusion-tokens":"0.0.0-canary.8ae44a5.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.8ae44a5.0","fusion-tokens":"0.0.0-canary.8ae44a5.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.8ae44a5.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.8ae44a5.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-5RBavgXzJl6uXAKgNCbSGS4T7XvJeV7vbPZ/qMxxgfPQN+mQgrzXIW9eOp9SuOYVNgNbhDAd2Qvjo8Xt4SS66A==","shasum":"d79ba34dfe140160ad3e63cdd70827180038121d","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.8ae44a5.0.tgz","fileCount":18,"unpackedSize":31291,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdAXqMCRA9TVsSAnZWagAArbwP/jmeI/Wzgu3rH4h5Z5yV\nturlmRwc+JKO1flwqxb89Pk/klqs3273hrMA5z/4UeSP9X38xETBZ06tRjXy\ngXX7Wkzn+ePVOH+rFwyztkyrTT+fkJO7C78t4CKO56Hf8uJxcbRb5Te+0crq\nZwtsfh0LJTFBPmzJms0clrQSsrAZm/IwFh7ZU0TyS8Cs7lgJzFc6Vsfm79wc\n0MKe9mZImZIMDVJLOGKiZWT8EN4GP85KPPy0bq6Af/bbcf5jT9sYbnMcP7Dq\n47lzC6jUXul0NqCckIckAJMBRXZJKAJM4Z5Lsrw98ggaz8alwP+ph4KM2LGT\noc422zFPp9PzBMIHaY+va1GEhl68H8wiU1YcEGfX6OCPo2epAqFju6eIJaAg\nIBz2iKwAOQKT2C/1asCWQBwPVxWAyNVsUfVIIn6kaEfD2y2qrB2vKxs6i9xC\nz2kdxC50zBnbxnmDcxmOkMSfB8dh4LuRs2+gidZl0PrtJLzMkrJSsSV38c9T\nuO8NXMc9cvT1nx+JT3l3eSnemgrXD7KDjtFR3U/i7GDkk98KjripW6NxMTLV\nXacZ68F672lc5sen5QrHgmORw9yg7FZ0A7nt4Ekw9NPhvVvqAt2KJwn2Lfki\nDy7BKNBtuUUl9rBrEjJJuIquwmcJf147NKPzpx8DnbTyl/Vgx23Nx/lnNTVY\nYrLP\r\n=PKRq\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCYNseNp95yoIwf9L9a8V5BS5oy2izmTkRK4otPuul8vgIgAQes70GkQMJC78yTDRmIcfSWWGzEOfTaVKlywAr1qUY="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.8ae44a5.0_1560377996266_0.9920516851411161"},"_hasShrinkwrap":false},"0.0.0-canary.8ae44a5.1":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.8ae44a5.1","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"0.0.0-canary.8ae44a5.1","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"0.0.0-canary.8ae44a5.1","fusion-test-utils":"0.0.0-canary.8ae44a5.1","fusion-tokens":"0.0.0-canary.8ae44a5.1","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.8ae44a5.1","fusion-tokens":"0.0.0-canary.8ae44a5.1"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.8ae44a5.1.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.8ae44a5.1","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-2hSr/Q/hz/O/EKVarAFgYVqLOvXGXrjwsm+zZrsPIhLKjEjtjlXtUTjcOjuNeLsDzXh81qdAF/x2sno+FZUZMw==","shasum":"13a26ba928bf4016431cb538ce9762002d69e4f6","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.8ae44a5.1.tgz","fileCount":18,"unpackedSize":31291,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdAXvzCRA9TVsSAnZWagAAk3EP/3mGEAX02hPtqvtpCu0m\nPeOcFBJOZPzAFwC9JjBGA6xQ7LjcAzF//OI9ccIITCN6ZsY+6GDKgMHa5GcB\nkC4W7zf8qWEIKkQeLMeSjzQAAg5X3lASop8/6eUwhcdBFrOINTppnhMrWnqq\nBe9bjq58FnvAVrb7CLcBW03dft1CGjOHI1VsK3j9NPOey8gSb+0eprm3XGhB\n7uRJTTSmhJzhpC2ql/00D5mEgclu60vRxLIaSMlob9vxjX38qoS82e7Xg8PN\nNJk/g/3o+0VTMXPXg+v0XhRcm+3i3zivRY8D8LGNixqiPGsyT4Su3h1qzu/Q\nDa0TwwhyeABxChIr1IK24ZHHQHaviQCi5tDuOSGvDVJHFrGdx5tE/39/v6Q0\n0DOQhy550Q6UrbLcoamJFW9gQ54CvaBYeJ5fcSBtgh74dinyD3to9UAhCSvJ\nEL0DjS81rQ1x1r5eM3qw2Sg8xOOsMKz10pGyQczlPyMZHNUZPivhzEdiw9EI\nA1Ej/fC2PJHhfM68neq77ASpDkkGCiXMnNUreqX3596XUpgZt6GBg6E9bRXg\nZNvEvMagICeBKZ42Z8dueQHySZ31QOASkGOHSZR6IniExf4otkORKKH6xnrT\nhAJq6Kp19NtFba0SypIA0S30UbqxtpJRlwhwM9Bbdn8ckjxim2pllIKAnHry\nBQOd\r\n=rpQB\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIBHxVCZStNC3U8hEIp426ywPnBO3pxXtm9fixoKitLg6AiEAkpum0YnlErhaTO2dRvD1V3Wtig0JgzC7tJ0V7+AfI+E="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.8ae44a5.1_1560378354721_0.6015449283035708"},"_hasShrinkwrap":false},"0.0.0-canary.51752cd.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.51752cd.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"0.0.0-canary.51752cd.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"0.0.0-canary.51752cd.0","fusion-test-utils":"0.0.0-canary.51752cd.0","fusion-tokens":"0.0.0-canary.51752cd.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.51752cd.0","fusion-tokens":"0.0.0-canary.51752cd.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.51752cd.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.51752cd.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-S9ORTiwnWEHT4KwhM/WlBLQfUJoGnEBGtuldIAAgs7dUM9X+h0p3cSQ0yhqg2TySM0b5rPh1Yl51y9w6RBo2bw==","shasum":"3c1be57fba63d91b650d052cd0ae600b2c095404","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.51752cd.0.tgz","fileCount":18,"unpackedSize":31291,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdAZTxCRA9TVsSAnZWagAAYhAP/jPLrvKi8MSDirTGd6/9\nHeIk+ZzKMMYbfwrvxV+6l143TUCSV+kjhmJYGZf3vJDJbZKc0hauQ0osHrKY\nQkiAsxd0nwLDeqaFcO2gxYxNKzFh3fN+v8lFyeE7Hj2cQI6x69o/CDjPslZF\n1vdjGyzLMhfBBw/zm8vvkGv0GN5DXYTN/5F11EJBjsOXZmrw5xvU1sRDZvP5\nuETTmWL68iwp5jS2DROWIGhLRKUmNZ8H3bqopeCID4aXOdsL6O+q8g8IyHGU\nACf4mxgz59rfhGP8C1wUYz+6oil5PqB84igSOCMdUBGsO6DjaChBmnDETvhi\nKKZL26oDL8P3jrMoF99h0H347ipVV2zrfT8IdLiASBeJ7sreO106I9BI61MJ\ny87HyZV92lVQHmyOldXY0365lPvOBzJoepe5zJWH/RECs39inGhTMwqUObgf\nOQcgw7C2LsKAq193tCmYFHv9hztEplbJyx9mDMDMKnxdCFlVmcy4ZkVxkcVY\n8sXBYpabg89uhwwkaenCOUJ8dPwJVQaB289d1QQDj92U94XbRZBey+dQ3cbu\nxdZ1hiqueNSOwzqr+E7Lb7x8F0c5BWJGW/dbZGbfHJX4s+d/HLzqKxAfqAin\nrvRx6qMnkWfauFA6Iye6rCqQXb5Ksm5pyRJay5EL3QAmib9b1QluhftYG8IK\nVRwl\r\n=daac\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIHKKWpV2O8wgWSEaKZSqVy1ZjRQyz9uCETiAR7AIjk4jAiBD1fQcdkVEG7F7CezY8Up6qlIhs3HkoGypF29jaozcog=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.51752cd.0_1560384752611_0.016897665058673628"},"_hasShrinkwrap":false},"0.0.0-canary.27245f3.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.27245f3.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"0.0.0-canary.27245f3.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"0.0.0-canary.27245f3.0","fusion-test-utils":"0.0.0-canary.27245f3.0","fusion-tokens":"0.0.0-canary.27245f3.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.27245f3.0","fusion-tokens":"0.0.0-canary.27245f3.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.27245f3.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.27245f3.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-/ppuYyYy3FRMiolthdyOLpmjWbQr9yV/RvrOw4Pej1t2gW0+rPP3elNZiEaw3qV9p2x2HK4TAxLaKOGRR2hjHA==","shasum":"ea2bb90372e1bf78d3fc521e90b5985382402ab0","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.27245f3.0.tgz","fileCount":18,"unpackedSize":31291,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdAorMCRA9TVsSAnZWagAAQh8P/2qFek8oapKBCl0AvBQH\nOiRdHxvkWfS9g70RI+NARie2OnDoXE76VN2LprIuJHP4XvKKE+0RTZSWiu+s\nYevaweVP5omvfE05hSWYNLTMzyUx2BT+0pxqrIkYldLIkSdTfJy6iUG+PJ8j\na+/zvPAW4S7rKHGMQRHU4R1qg8ALTWPaIuRTIChIO0BKIyxEW9XfUgOZ25Ls\nqqSdTrCzStdut1RRzaWCTMeilUt+DM+z6WNTpPk0zn35Fu2voraWXj7ZxM23\nNO4wFjWukqrEoh3XIj3PB0lVRIx6JsM1CvqwCXzGcahTzsRy4ggKGxHfQFYc\nghIXh5Zz1O0oyBufe3jtORyFGPk34byIYBT9QYgTBpFN1DIXITz01mz/H7Il\niK0kfI7JSNYwlLrGyKkAFcQd0IDZv2q1+q62UvfogS0ThR/x77cf8PbbEDzD\nYf0xFCnWvE/K/JIKnBqNwS25SkquTTiNPlRLVyd7axVVo9CE0n3mcE0WkbuU\ns5Q3Vh2Q/bR0TagWJhvsqeXzELde6UmIjY9dZfAZNZ9WBrpwEDbfBGuWfmj8\na1MSld9IEEe+4MuwWYHQ+4F5oJo10rIRw2ozGA7QmWvZ2QGosaK35U9cqR68\nfK8Fr+DYZw35sL6qFBoDuubgs820cS5dQcdbCaztVCqQ5nTgjsAMCs6rogtx\nSPsy\r\n=/LRd\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIFIQqEcM+7MBAgcMj0Y18CZR3rK59B5RlrOVEE4wohJ0AiEA5UH6PbvQEqmStT4GromyfkbieEYuq3zX8wSGuG/d0Sc="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.27245f3.0_1560447691398_0.4543209237920045"},"_hasShrinkwrap":false},"0.0.0-canary.3703af8.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.3703af8.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"0.0.0-canary.3703af8.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"0.0.0-canary.3703af8.0","fusion-test-utils":"0.0.0-canary.3703af8.0","fusion-tokens":"0.0.0-canary.3703af8.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.3703af8.0","fusion-tokens":"0.0.0-canary.3703af8.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.3703af8.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.3703af8.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-37HuxAaCe1eueTStDrhzkuBdzVBDqrin0LTsDR0Q0HR5QDLujwxQCCeuPdDNaTeendfo1lUUBuH161Liamx2rw==","shasum":"aac5ef5753f0b3f086e651aa0709f32bb1043c30","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.3703af8.0.tgz","fileCount":18,"unpackedSize":31289,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdAw6zCRA9TVsSAnZWagAAS1YP/0nT9huRdmZYsqjtosk4\nNvl7S8yrMvmdY57sjXtCs/iQ5sEiXh9MdoLmiJbsNI3O0YIJse463Vg8XOZa\nSNV5wWuhoEuFHis9+XwXlu9otu86rkEwQQcg0Z72xhePUYUuTo9WqiikHhX7\nBh12C1kuQXa6kY69DVn8gwCppTYML5AhSWGI8CjZ+zPKPndmzdPN32Ci63wM\n8SVa55AyMghKeeUrNewQq+l6mY9UqLjc23sPIQxiU3mnBjjYfVvN4FkndvC2\noYRj6gLW10xcm8kBAe/0lOWoL2vdl+r9yklu4szjF0LFHKdYIdvzXdo0hKnr\n55immuXp1Wbguv0Rkvo1tKTdl1Hoipx6yuJgiccurhNchAnkmGarb4j63Un7\nqKpgTgJHlKHJix3KQZdFU3sgoUjheMlVSHopJ8PQbYDVL3xh/kbV4fjVwjkK\nER1grwff+j/bgZzmYnAhnTacMp5LOPsf5phNYyZh7cq/Dr/01SJWXUxvDHb2\npZpatEj6ECJmZYZ3HYvV0jEH7P8AwKsrryfUs8xq/0wNZXX1igHkGphQH05J\n6ZbonUVQsukDNKcRBbQGRDtuBgiFJF8tIfwYsMAuEmPMl4GZ5mRYwmEZf4l4\n3MIVt0cu6MHRDVlvQrVAsdRR6+cmy0RqEE6WLm1lFFjrBpKqgOVxHQNw1B6B\nTlYy\r\n=hfQo\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIFlfR2iugwt+2qpZjsshoZA+SVFVgTyvjnDuwXO1W7TVAiBFwGjpx0u6AVX6YyP6TMQ8JmOKLm1LF8Iz9bKkZevHSQ=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.3703af8.0_1560481458823_0.3656959836153004"},"_hasShrinkwrap":false},"0.0.0-canary.3703af8.1":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.3703af8.1","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"0.0.0-canary.3703af8.1","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"0.0.0-canary.3703af8.1","fusion-test-utils":"0.0.0-canary.3703af8.1","fusion-tokens":"0.0.0-canary.3703af8.1","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.3703af8.1","fusion-tokens":"0.0.0-canary.3703af8.1"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.3703af8.1.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.3703af8.1","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-nb+cg1p+6uAaMEPWSdxEUDBsFN+uuP+lyem2ZipsXifJQXyCyWmxs8SjmQ6F9It4b6EPBm2edULY4r55uonKYQ==","shasum":"7d7281f9dd798031896ae958511d49734acd5ca8","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.3703af8.1.tgz","fileCount":18,"unpackedSize":31289,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdA7phCRA9TVsSAnZWagAAPEcQAIcFJ8cpi3ydaoN6eE2X\n9b/HwtZDpYICvP76iaajB6+wBoklbJ4Kd8D9ijp0ybUmQ+0t5osgHQFwZD7t\nQCssRYs0qd6n38YmgKPmicKk2B4tjFzpz99AMDe1naTGC4HqEIzCTtPhJD7h\n2+5FecVMs9kKJyKgBe5tNdolWijhrpBpGlCBtsy9eYzyxWUJ3uBeDuZrqeoe\nZohnjMvIS9xEpej1dW6uRBChnEEpq45ajCG1PXQThD81s9xfcDLrK8WuT4Qu\nS8Mq6J+lgF2j6Pqe0nmxDkpJmg/8ANEDXZSKtC7aXGxWJUmKvkdtJcnw1vrA\niha66uGv2yMWbHT9aDMwAyJ4lUa9eArIpxRQiqmshAtvQR66kccwZnkV31Vb\nb9SravwFMXc5k3FRwauy4t2yo4Wcz3OKFdP7i5DVz+g0H5QSX1FCFbTb8e8L\nbypTOvpcJUCxciesCHEZicaO+a1VR9Dyz2ZWLDVCY7L3s6Kll0Kl9cJTpRN0\nIix1T34xwoT8H8XPwXj1OCBV6foJIM7hs05aaCP1mRvrILkrW71PHTKzWBEP\ngF+qGws85lpwrQ7+5YgRr0Hg+338J7LoU+OvCp/wuvoM+XmgSF8KsTCYZqyK\nV0hXtKgDUSmzq5l3Nte5y+C1w4q2Bdc/uZmMvlcBxl3OJSdqTW7m+SznvaU3\nXCPD\r\n=4sdz\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDkqtxUX9VgmpRV4h1AIhLdjlntJps+BQGauLIIMhlwfwIhAK+zPF+ciCoPJK11uVgIGJX3eC3u5R1RALXjCGhMa1zr"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.3703af8.1_1560525408596_0.4789416923484171"},"_hasShrinkwrap":false},"0.0.0-canary.d93b398.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.d93b398.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"0.0.0-canary.d93b398.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"0.0.0-canary.d93b398.0","fusion-test-utils":"0.0.0-canary.d93b398.0","fusion-tokens":"0.0.0-canary.d93b398.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.d93b398.0","fusion-tokens":"0.0.0-canary.d93b398.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.d93b398.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.d93b398.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-jxtoBm2MijxU/jtutIbnDk/yIM3SylGpXdw7SJ8YTdd2Ud0z45VDq/3jY4ZSye69Se5M4pge4DFyPkJpiJCurg==","shasum":"77ca712feb5385dfcc7a1b5f39336543e3278b14","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.d93b398.0.tgz","fileCount":18,"unpackedSize":31289,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdA80QCRA9TVsSAnZWagAAh7oQAJfutDAnyu4B1QIcsxCf\nnedRp4xETVbgiECRlX1YOg3zGQ4FrfuF0fKVlZ+a2heRi5VHVBh4AZFPpD16\ngs0s6gGxWmwQio/lcLfOjitFS5hBajRqzgglm4T4guaTShS5gTsuoOZpfqV8\nb1eK96bjy+QZuAhFZfL7z19NiEAU+ITXmWHSEAqOqnDoboT9k9ypTM7cq64r\nZ4lHdhI1/j5nLrncXxaUs4usgPnl4jYnsxoQNiCSphSfAKHeMQjoPNcw8FPJ\nRicwA67xkfPsDnkOVFLEdMEbEQsf5ocj2OsUFaMIxqi8zn3/1Rrqyq+laOIz\nM2aRAKBviNo6thGwaZguQb5V1soZUlWZXvgomiOIIb0487rAf6iSpzLjjPP3\n9wz8/4JImcWdmZiqT+mNpd7c8YIlqMWRmYtr2N+tFGUWT+6Nhyd7TYVlk/6j\n17eNKTEABME1xt5W/z3TmEFN3/ooEQtbTJwisfAIcGI1T2bLeRC8nEHbgsxQ\n1wC3FRJQzmHu1qLe+fpHkhhrhVOVr2w/jPKUsqcWlnIkMNIGtfL3XWYRl9tW\nJG9wfsMTaskwcC+JkmQiAL9zT8TDXsKPp2omnDHPnpXYFL/oD2WQeOlHb7NJ\n8+uvzKPJr8RKQDAmcL0CSBhyynhAWi5iqhOmVVClUxCd2zgMb6vbQTUgiB05\nAc8Q\r\n=+mPm\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDd7BQNvjUtjVEs/6KxXqqwjYKD1dmZNmg548uPhG71JAIgLOBMU6Z2DkQ4dYAp8KQS9XjnF3kqMloXnoD65wbVtU4="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.d93b398.0_1560530190385_0.36117549547975925"},"_hasShrinkwrap":false},"0.0.0-canary.d0b5703.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.d0b5703.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"0.0.0-canary.d0b5703.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"0.0.0-canary.d0b5703.0","fusion-test-utils":"0.0.0-canary.d0b5703.0","fusion-tokens":"0.0.0-canary.d0b5703.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.d0b5703.0","fusion-tokens":"0.0.0-canary.d0b5703.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.d0b5703.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.d0b5703.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-Xyuw6qSjGPR0BjSdUm4XTt8lRNeMkKAsCJgJ1K2VljxNprI6Q3aN7E3vjvN3HnXzEgNyZ+NGkPz95GB1ndeO3g==","shasum":"3cd34ea327a3148bb9c16b93befc451fe5a98035","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.d0b5703.0.tgz","fileCount":18,"unpackedSize":31289,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdBBYeCRA9TVsSAnZWagAAlA4QAIQylMFi9NL1xRI+9W7R\nb5jRQ5O4VSRd23EffoJB0T3q3o9ktTNGXUxe7ef7tZHo6vM1UC+7B9d1tZkq\n2AZFF7O9Olw5GkyYw4vDAJxYv8TWtF+t7uiiaem44Zz7DGntO9ANCY4Xej+v\n2+eULpZDWIiVEM5frsV3/hn0QCL+KgiDZnL778I/p2Habyge5eAA8qDbJ5Qi\nwQ61Zdx6DenAAA2aly6HjutBrLHBRG6DXqCmNTLUMLZV5/8zuy+dmlXsIfZ7\no6XxXDMuub5XdJbg4nr2tFT0e6xxLt69ZYMiO8sO3ekEe+3AmZEovYPQZ1lC\ntm1TRrRB5Yxu+rUdyW1aVNSqN2PpP/zRPngNXwSINjIupOOKMgzTc48KP8HG\ni7PnsSA0rk3SrA8w0Maye4T0flW/rR1wk7cZpEXOXXcm3M2TB1Wga4gRyQPr\nGxN1NwkBX1vbblheUr/cOYOy2C4MQVIx7tgT3aWkStcLWTA2P8g1AhmbN7Mw\nqTZ+c5ihIeq7YPrGlLdB/Z2D0NbpG5omNTFyG/ZSYzzgqUKl22zmBClmzIS1\n1krhNKsKhxFblkNxUhyJbtPUXjOBgf/4bxKyu30A4D0qaMxwik1yt5RX6q0i\n+aeUH9GBc2lDiTEMmho3NhcTv0MQO0nfhFWqJGKJrj9hi2Xc3dyn2T3o+vQ9\nBB+v\r\n=q4/Q\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDvsIiJx+jTSgdNw7H9CYBP81Yesdz0o3ytG3jpyZRwSgIgVxWZdbwxidd5hQTxKZVML4LBxBd6yodpJpmgPf+Ra1g="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.d0b5703.0_1560548893935_0.48700021035510477"},"_hasShrinkwrap":false},"0.0.0-canary.801e47f.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.801e47f.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"0.0.0-canary.801e47f.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"0.0.0-canary.801e47f.0","fusion-test-utils":"0.0.0-canary.801e47f.0","fusion-tokens":"0.0.0-canary.801e47f.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.801e47f.0","fusion-tokens":"0.0.0-canary.801e47f.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.801e47f.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.801e47f.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-97pYOpXK0AV72pGuVlchn36ZOKlSco6xz0Vp1Z+6I+r14uJvre0JJ7YRqHg77ICWq3T+9ZmxLjb6PnILwCnGog==","shasum":"2359ca61c5cc8a1cd93d8f238214bd738be2d568","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.801e47f.0.tgz","fileCount":18,"unpackedSize":31289,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdB78nCRA9TVsSAnZWagAAepAP/AnCHwrk46ymWunnlsPu\naKyLXLPe/QLxRqrOaU4kEznwUZQ7kyvVDpG2XzV9hZfraB7tMOVGWpTSI1Kx\n/175GemTo6WuYLGpqmOxr+yqkAXPCY7p/ZZ+PCNeSnW1hYsqCaQYIjZQqbzN\n16sVnvwrvIV6Nyg7j486S3bA7Qs+pi2aEristSrtSqcJ5UdI94hrOCd4tKES\nyYOcdVJq/4J5/5EeK6QLbOIkOFQpjo6fxj0ElhZmelL6o5r3mrfYNNL62e15\n5WS4a/6rpfBOEROaKxu5c4VkOLYe5zSQsdQINEwjtW67iRG3krQ+NNOuuYFI\nfLoFWKPldHkbsnWqJYpiAD7KABgNogxmB9OTrv4/UrEfQylOOLyWGz8wJE6p\nZY8ft89WOU7HhPnKqhrV5ZLr9VmaTKsylj8rTOxPzV3N2SF/+ONinpkq3n3C\nemHJqsW4tpVzagcSy9QwQhD6fVvy3pc0f9BxqXzeGYxXrrwT+PfWJ01vBvIb\nyKkEVR4DgEhdGthcrQa5qBlIpvi4nalMx9L9tt8Rd3FWKZQnBZ/K0XzwOGJm\nHDrm0pBGapbZARpKQDo4s1B7Cx0/uiVHXDY7RZJ+DVwKOzGVupSjwOR2UG8e\nKyJBWi7W9HmJAl3xf951ESJE76InP8snHZ70uvTg1wyZUvXegW2Vaq2vajA9\naHIr\r\n=cp2j\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDaRw/5rDm4natB9ncXitJlhuFrBLbg9telX4YMuwbjKQIgB+7tN40XVoWVHXXC9yO6FBXlfMYoUJ/EIN7eVNJYfJg="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.801e47f.0_1560788775116_0.07252055348031172"},"_hasShrinkwrap":false},"0.0.0-canary.63145f9.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.63145f9.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"0.0.0-canary.63145f9.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"0.0.0-canary.63145f9.0","fusion-test-utils":"0.0.0-canary.63145f9.0","fusion-tokens":"0.0.0-canary.63145f9.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.63145f9.0","fusion-tokens":"0.0.0-canary.63145f9.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.63145f9.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.63145f9.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-L+YCF0k31k5lX6cH+iY3YqJXnFFMoappRSmV0mp0EWGfVb7BJNCX9gLg65/V2ZYp1jCmxaf9vNthyzPzWe0QRg==","shasum":"9a87fe2ae366559437be7ceac4561e2ed7dd211f","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.63145f9.0.tgz","fileCount":18,"unpackedSize":31289,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdCC2GCRA9TVsSAnZWagAAYNcP/0jWqGGCV/5V1G57qi1o\nPBHOIjSq3Jtirqc99tiYc0gFSWiaRp0mcMEaxCEwh2rU47k9eh47sur7ajYf\nAbRPZjZUMZv4FJPxbQ75tXj/7zDw2TinPTHnEMYTfr6dkNnSZ0Dx9TAX+O9n\nvi2W3Cfise/Ua97MCpYV8R0uRc6QfqNDLz9puFGNPRm0Hn7uXmOTT/I19yzj\nPWVPk2TncwtBmVQPgaXp+7XAzsfDbW9JoiUXV+T7v72R3an1njJHdXcbr2fl\nJYtV/zEDSY4mpR7S1MDrKRSABeI9K4gIFdyUzFVutuC35PFy3uMhg0wDctSj\nk9v8C613OJq3Ei0TnEMqauQtOj3ewib4/G5DnTqKpc/T01vhNBDluTNkVZL8\npEE/XimAVi5P0A1gySY/OXO7Z9XGpvzHryWd/0hWFgWp3WyBl0Rs1l9uXdN1\nQBKT/bEPeTASyUXTufTH+9ZWzWUCMDwcf/NKkKXh7wjFYKeccQgMAsoJCKzk\nxi4G+hEVTgJa5nXOZeqrYGO91cOFdtD8QBl2M5/vQEq15MT1YNfPPXG7uY6V\noSriDaq2afEQueG7dOOuFW4qT4I+dGq6AnvwPociAe7BRtq4jEtExWYcX0+M\nrTegVIMGLARBZfbgM3a+VLNKXymxhpdy8I3KYgb5xSXPi7f0NomuvCWIirrC\nzdmh\r\n=D0JI\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIDE/qcgHM7N6hR2yhBEwU9oF/Sfw6sUWaLh/KQY4v2OfAiEA+fPRfRfhI5ppXl5VvqEsgaBNMjx+TY7O1n8zN2jkRVs="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.63145f9.0_1560817029647_0.29658016051712965"},"_hasShrinkwrap":false},"3.0.1":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"3.0.1","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"6.0.1","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"2.0.1","fusion-test-utils":"2.0.1","fusion-tokens":"2.0.1","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"2.0.1","fusion-tokens":"2.0.1"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-3.0.1.tgz","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@3.0.1","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-9nzAfvYohfK33rbQ0lkYOweOBNkoGbp0+Q9SZK0psKgoYdCPgeuKggqbo7SDAvNcOh1DjaC+ZQUM7RywKwOEkA==","shasum":"21b9455d8c8b69dabbea2dc73f9ef8a241afb54a","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-3.0.1.tgz","fileCount":18,"unpackedSize":31170,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdCDI1CRA9TVsSAnZWagAA6HkQAIWyHHN7/OIdwMEBUblt\n5/4Nntu04PUjfSO33poWk5vpYVX1I/7zTQ3Y1RXD4pcQkic3u1FQ0UiUsYFg\nEzgA1e2nVLcfojokHuUORNkGHqAv7t5+4vxBHgbXk7+Mp/llvYV7XRYEJjAK\nDsMW8fihwhwjNF4OY/8sfZrmaq4kIY17py27TRWTX4zQ95946W2ef/2pSc/x\nVwvP5O7HGaleY2c7cGs+fZWiZ0MDYClJT/4UXp+p3dHk++sIKqSSA7l4gO7E\nmqjpjkvioNXf1BE3sD62mZEbbn0TtmogesggdKDmh6ftF6D0HWmswrJKPwL7\njvsis3hT3XEbjJn1eSjqWtmgnKOVWf8CuiNYMZ/OzFPeiDwsghxjBvlxZYtY\ncv5X6MEggrMps0nM4bkl0ZKCaEapTArppz65NZrK3R6eSeB20br4rL2Kg/Z6\nAivh7BEsP/0UbUnLuUJMV+XYRBxYWuqTPd+gb+DKqURYhArSZw5nvs+HPOOA\nUYJnsigeiWwzTi/vdQ133oDx22oEsqxMYjL/qfeJt97rpP9uLy/BLtVqQeji\nREd8ro1bnmK+lZ7ywwbVbhCaWpj/DcgPOFLyK3dCzbBCfLdU5eh4sZPUE1DI\nSgrxn5bvZbsqyiGLMSY7WHqdRQYBkhLd0fvHNpbOqzHZjV8+XDOgcxDJmu7K\nuCRp\r\n=9iq8\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIFFWAR0nCfPB6Ilb77wykiq+PJPMx41j+bYoJAZ2Q/R1AiEA+bqlayOhhv+4dm1cp27v7L6bZucMT7ORn9iLcnwWiPE="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_3.0.1_1560818228992_0.13633542218494177"},"_hasShrinkwrap":false},"0.0.0-canary.407b8e4.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.407b8e4.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"6.0.1","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"0.0.0-canary.407b8e4.0","fusion-test-utils":"0.0.0-canary.407b8e4.0","fusion-tokens":"0.0.0-canary.407b8e4.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.407b8e4.0","fusion-tokens":"0.0.0-canary.407b8e4.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.407b8e4.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.407b8e4.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-/t/j9lBqwP9Mo71nc4H4jqRsUGAQcl8F7cH1E4OBgNYke4ExLZTWBZSYXWLu3Lr6S2sHdQ4UOsLbTWga06n3Cw==","shasum":"e638736e8f502ae47b795183308be05d9017a912","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.407b8e4.0.tgz","fileCount":18,"unpackedSize":31272,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdE9XVCRA9TVsSAnZWagAAqqUQAJKTudljXSMNQnn4G9qw\ni7X37XirhShmqq7Axuaxl1xveEPs3cANeR4H8DFQ1Po4VuIiWD4tv5Kqan+H\n+Mq85TqUsaymHnAmsMLBt5ISd8km0QqKo5pbm727LuzUthCuTcmnVIHVIXgc\nLEhCZ3DSVrtL63zCSI+YOExdpzhg/JhPgS0/iQma+jI8heyFWiDDFJ+fB3Wx\nKNjXUKuEixgWr2FYA7HkdNqTZ5rRPNFuRp4xZsUGbmywd4/K0EYC5oED1uYn\nYgbgyy/GpjWU8DrcLOW/QQ146ymVsxBOCGBSnz3Hc8k/BAVsiKk3hhD4q/e8\nrEZ3eC9si829KxMKi1eGY0DVQfVH5uzj2Dl8pN3BzZdWuR/AkhZvj9Am+ver\nBluOevXQmlhwYipUYGFWgljORF76iTocJk0CBpSCJTC75baOwt+1zy0BVpv5\nwaJVzuj3QY1wpy4bbkm9mN0fI9V2MrvkniwSUcyQ52DZxqdiylvbxZP8jyrO\nlN60qsL5x6wJnTpRS2tP5Znavy4n0FJ/OUoo/wNW28039kjLIDxbt+SGbkqL\ngdt7vivYBuzO+1KTLlcC/IIprhcFUQpAo5ExDtkMLp84vvyiRtP5RoyKyOPG\ndSahKgKBOnbozxRpc3pBcd/K+TKhdugOdB2lCcyFxB3US5vqeQ+QjdabExT8\n7En/\r\n=XOqD\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDZZvX/ZV/nb0ggmdGAwz2SK11oicfNXOnuLfJ4RuGavQIhAK1lR+2zcMn0CS8y7qufNKp9uLWwmFD6o3tArsPNmTz/"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.407b8e4.0_1561581013037_0.1855042647095988"},"_hasShrinkwrap":false},"0.0.0-canary.ed79452.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.ed79452.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"6.0.1","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"0.0.0-canary.ed79452.0","fusion-test-utils":"0.0.0-canary.ed79452.0","fusion-tokens":"0.0.0-canary.ed79452.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.ed79452.0","fusion-tokens":"0.0.0-canary.ed79452.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.ed79452.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.ed79452.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-TMBo9CqCvlmTxhAJ63l6ncLIsxAHHTvn+Q9nRLG19G2Onp1acNWRhM8nupzhDpOwSIYfPT+S0/8MRoh49tyijQ==","shasum":"cd28944c657ab6d904863424cd44f167a2dbf17d","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.ed79452.0.tgz","fileCount":18,"unpackedSize":31272,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdFRDWCRA9TVsSAnZWagAAkcgP/0BzM5OlLZ/59iIgdmo/\nTg1s03aHIgSi6d13UYWFxtmXPSA3TDewk32WBGRrti6qQdUgPJEIAnCN5nec\nMBuNDWbB0GQu9iZC/uGyLhWPCvWnDSWIxlCUDsNiCjKzJQlH7J/cA1uw6tnL\nPGRZM1J2UH16aFSkN67yWsHmDnaL4jPkvqkWPPgtu3yAA1gS7kxr4rjDakKn\n3HsQPKGK+RGRabX09vxS9stMf4sWYN5a4YHahvOqOFWPSi0kXr0mkZRodfmH\n/9zGVOkU0SY2knAs3C3xGokk0+uoB4/U39tMRtCvPhzq7/sZFqyVwou/THqw\njDIO/mZ/Bvg3Aj/qEiShZPBFCGmSlPDofsGZz34ugsJxd0+J0/Wst/eRs02X\nOAfPxKuz4A74B2VKYeKwR0EEri8vShPmnh6TUGFXEW/gQlxVlSMGLa8cVmYr\nRTo2Qc3rDRgFwr7sppT2np8NUGXWXUpBGJfQ1Dqkt12r57OfAnC39qRdqDNn\nsRb1eU41jYxQbZ5mdj76vN+xYZHljk3AMdDAp5dQS3HzWXV0B6uT5Qil6k0g\nJPgMf5iPdc5fOFY2cIKAIJVCLyO86XnMdY26hquQ7fdby6i4UsZBnbD7AbPP\nB1S2+UJg8Bxcc3bSdWffBBHjKerhUdZA0LrVgAtZI+lsj7SZmoLPcxxmDiow\n6rQx\r\n=ACbK\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCc6pw9a6oFbxgPOU6mshPj/EeoLD/ouU+3tQcGYFiQ/gIgcs1BcYswtFbtq8ChlwMjNKcaXTt2BvoaWe1OKIggavw="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.ed79452.0_1561661653373_0.4358472877397028"},"_hasShrinkwrap":false},"0.0.0-canary.3e2cc31.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.3e2cc31.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"6.0.1","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"0.0.0-canary.3e2cc31.0","fusion-test-utils":"0.0.0-canary.3e2cc31.0","fusion-tokens":"0.0.0-canary.3e2cc31.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.3e2cc31.0","fusion-tokens":"0.0.0-canary.3e2cc31.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.3e2cc31.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.3e2cc31.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-4yH9/LN4Q5bgt1eykBs9mhmb8DVwfP9NQeAuTkG1wL4PcMex5WJuE7JhfJU0a5S06H6gozxfn7Lo+s/ETjI//w==","shasum":"9217f4b206e6a4512ceb77e2b336477c2a6714b9","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.3e2cc31.0.tgz","fileCount":18,"unpackedSize":31272,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdFlLvCRA9TVsSAnZWagAArGkP/3bo/A9+OVN5X6qH2bS1\n1IkbTKAgJGBjIGTnHeoCzyDv7YjaFAi7AkXMShN4fLXweu4XR/L4Pp6R/t+i\nDX0rO3Yd8qh5iw/qZtEQoalHelHKuoXvKEpJVbiGYEI135kO1S74d12/HIxL\nVzeorLUZBsWJRYwJf/GMGiwbv+02sTmPW7e6/npIS1geGP1EqP1mXnJ0Hqg8\nvpPO+ZdnQ10o8Q7/GrGWGuYt9E1ZfhDswZRYkuD3n/BeTLp4QDD7cqOOORHw\n1mV3z1UhJrS4tkqZ2GabrUzW1umKZyFwGqEgcbbn4ACLDfHIZl/N6VpXdMid\nAUM95y0ekgIJHgwzDzut3hr6BKGggrNvrF503df1qoNDnEFyfTtsTKIDtpur\nT881Fdhf84CMLtulfHoDaFZ1jpFMzUtJVB4cb+Z3NaG/fkMHrC5djD/Pbdjg\nlHGnm/xVfMQN7semrND0jU3ak+9OiVgspNr+xhelvfHc0RlZ8O+fDbR8asyb\n1GAXpIqhxXotpo7mtcqXUFZcuvWp8BG6a6r9kwF48cgn5zQn+TByqJIUi9GF\nl8mjXfu3QwkuwjFX2Iu5bWexmZXecaWLQhm4vJ2ISsCfv8Pi8skVwQOXSBu6\nOTpnmmSIZbf87yKiFTSEJqc5dHUT3rtmqTh7QGxzRC1a7u4HrJ/70EaodGBH\nWjXS\r\n=zjh9\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIDktBmkhzK3qZTyqDQErW0v490+9cUg2CBprJaWHY59OAiEAyzvy/+S0nsRl3tsl/IUNokcDOJPozRjSZvu2vkIlx68="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.3e2cc31.0_1561744110712_0.595898947506931"},"_hasShrinkwrap":false},"0.0.0-canary.5c3b351.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.5c3b351.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"6.0.1","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"0.0.0-canary.5c3b351.0","fusion-test-utils":"0.0.0-canary.5c3b351.0","fusion-tokens":"0.0.0-canary.5c3b351.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.5c3b351.0","fusion-tokens":"0.0.0-canary.5c3b351.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.5c3b351.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.5c3b351.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-yBR5oiIlDUaD/cW0K2Hnu1utr4S5n/tMI4FXlrNj0pXC6QRkYg7muxTJyvB8HTCAAtcWVO1z2uU2R+qRVJovzw==","shasum":"b5cf53667888b9a70b1d8120e116d48aefbd85d0","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.5c3b351.0.tgz","fileCount":18,"unpackedSize":31272,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdGn2ICRA9TVsSAnZWagAA9DYP+QAx+vJSQRdiP5y5mLL9\ntS1Lo9GJviRLdg1FTU0BK2tZBI6wutQ+RGdmWP5k9T87SqL1YkRr3na13nxd\nf2yT3l7jnaofx/XTyUhRgTgvAGWOCBGB3Ru7x+4WGHiA4I7koRpdyLk9JbKp\nCGuoA6fBVLLVcSM8sKsqY0gZZi8DA0DJ7Y8qyZo5uvFlanaj1lh99s9mwxwC\nTiWt7a45uuVE6VT77bm0YbnYaGHV+y4rNMF9X9+J+nxaUKNI7YcjhBH3i8Ky\nnZRvmSDZECjo3V6SD9HFeniWJYIdAJsCjAo/cKr40HyJ4zoDbOqyvAkjPHnv\nPI9RnU7njKPXYVh+C9WHSG7TwkgZi2q4PNAvJpIRxpRunHRfffA/aPLIld4N\nJvyJ0UPx2K7jUOVE8H0a5pbgLfCjmAghbyw8gpTZRBDWAWOamLeSiQgtrlF9\nK2y3UGheR+hjJYE6OJ15uPY/XBh/tsljlVq/H/kHreRXF+9pvt40S81HgMnn\nVFTS1POilRoIdCaaOnLjFiPum6Dor8P2JaiTzrXzabC3i1h4S8oOPq2wOnOL\n+2B9xhbG2GyEdBkr4Wn0LBh5e2+EnG+yiKkXIRL7VIZYmzqN1KrSm/QPrpCS\nwVv1Ju9LrOQcStOX+SPvBSfVlZKyEPvaCk0yDnvqvWIpiNMFNhWsCs3FguQH\nCADa\r\n=kjjg\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCICTHWOMYnSnXVsgyWAH8S20ril8XocP22dP9VaiANphnAiEAkX+nAGix6BYwz0rPx9Ech/Kt3fDY5njY25f9KpRIYlQ="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.5c3b351.0_1562017159481_0.7316212236293451"},"_hasShrinkwrap":false},"0.0.0-canary.16ee004.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.16ee004.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"6.0.1","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"0.0.0-canary.16ee004.0","fusion-test-utils":"0.0.0-canary.16ee004.0","fusion-tokens":"0.0.0-canary.16ee004.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.16ee004.0","fusion-tokens":"0.0.0-canary.16ee004.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.16ee004.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.16ee004.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-Zz4IO2oNWtEF5cDJ68Q7mQ2gCbilOW7aKSN0f//BPOlDbkOWX9CYQPm993F6nzDjutmDzT8Re3bblvWuVlReag==","shasum":"653cb49a4e7185e3d885965ee62c6d425cca9a97","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.16ee004.0.tgz","fileCount":18,"unpackedSize":31272,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdGpQ1CRA9TVsSAnZWagAAV6wP/0a5Wrn7pa5VHGvdtxCr\nBjSYHNkgmgKr7qDQwz4INaMPp3c9YeoPrjUOWPhj1KC8tgXwBBjPCKApbls8\n9tvjBOOj7olmph5Opbz9+NIay/3e25l1CqZFd6GCfWCeStClTT1lSQy9KGOd\nmmmODzbk8224VmoBcm+jSrkQC5wKmbK09Kg03dRvWrOKSc86tinD66+I8ylQ\nQXmLvOmx+h2qYv9DQlt3z3j9GDzOAMvJzCqk2nGcH74Gfahn9Mip95XVGFQb\n6vTSGrsx9T4hus+rEw4H6qJ5Cy7x/OjD3llq0qVmGiPaDBzQf9ByBqNt8lY1\nO9Nt3igrwxgUqx30GIkBl5k4bOEnK8NBHHJeO4Jb9aE1/Tif7UaLffJjSweY\nS41jxzbHvWB32F07cebSUTnTfvVlzqc2vxUxob6tBx8R9GRnwkd63yS4xmap\nu0BEdBPdUoFxtn3HWoAc0ixsyHg+LjLLPc8iiedUEeDcSJqFxBYLFZsfvnrP\n70bPzMl9TBX5W0g8GFArE4agExv/q35QYygZoRfAQ2kvrGsky+osvZapREeL\nTe/SlL4MMxzcCJKI5gQ7mDMsADw0IUPkNqPhXOo4fkSiHMDpbFe8T9UxZqIi\n4qDe9aHAeUigFfSaxTyOIgPU+8YjaB4rsltyJTLp9VGiKdfFF/Joqh5Ub+g+\nqlCn\r\n=8bap\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDQii1Rqm+nunx0OoK5RHlj0rL8lRt5Z1bVsURGwmaWewIgYrbRR3uO+M1UliyD3X06AwreYJVDYt5T7uBOyfW8An0="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.16ee004.0_1562022964294_0.2235339881014169"},"_hasShrinkwrap":false},"0.0.0-canary.69d2497.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.69d2497.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"6.0.1","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"0.0.0-canary.69d2497.0","fusion-test-utils":"0.0.0-canary.69d2497.0","fusion-tokens":"0.0.0-canary.69d2497.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.69d2497.0","fusion-tokens":"0.0.0-canary.69d2497.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.69d2497.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.69d2497.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-uk+OkwvJXNVboazY7lQPNJVPGo2UciK4N20uh0+P9DCjnvkhNi6gYDf7Ig+mOJybgixv8AHhNka4LyEQL/x43A==","shasum":"f27965cc832ed877155afed9154c8ebd205c2357","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.69d2497.0.tgz","fileCount":18,"unpackedSize":31272,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdHPAcCRA9TVsSAnZWagAAEakP/2ybpBg+Ii+qr+GXFd55\npeB7PTM8TvU4QcvJP/5cg6VRP5DrOuvEDpqF2vgALBxbzfwjrmkjvFNe7V9V\nHAQrgM+89cHYshkml6Ut1KzVDm/8SD747HxLosYpnTzXGszb8CjOjaJHnl8L\nJX92ADPAAs5IW1hRl6CA/+8uFRq+smUSz452/mSSHUCetYLrXnNzc7oBeXzp\nritea2w6GgU63vTE0fYCAODbAFlZG6tHr+IvsHV0peHpg/Eh3XfeYddRS3Kt\nqN27+GwuCKIldXF5qt74fp8aJILS2WcnSee1YkQzFkAtSxNbJvcnvVH8wXth\nBYNNQ2f+xYcOe8NK0jOUinIw9fL4A6JEX7y3GBvHdt93rTpVtDVKlUp94cUd\ne0dfm00/+PabbqxyobjEfyw5zyprkfVSBKx4QA5OuMQwT+cL7948e4PNY45Z\nlTsx+KhymKO4n46fDhPwqs6NI9BcyxhXBVihVL/4QTuJVl7IREi6hBEsPCEZ\nH4Id+osRCFu7+v7wNC4E+b2n5eK1OzJgVVRCEcxFavwx0RFUFFRTze9j24dK\noGE0JRTuP+s9kmqx1ys8vY46stgQAIdTtf0UNTjFrSrCxKqfgXkiWhcFjmSn\n4oUlDCv4zTLz3WzF59VuZgp5zuwIOoDoJaWCS4rUTTFZHD8T/J0hxt255l8/\n3/Fk\r\n=eAX7\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDcuIgIEH47PDnjbRBhbhia4ZbHjvAJBORFi+SD5XzRNAIgB/TnCYryclvJrDRbvPXgmNYqnivKJLYxzGZKmdthWeg="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.69d2497.0_1562177563471_0.2501793402475403"},"_hasShrinkwrap":false},"0.0.0-canary.69d2497.1":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.69d2497.1","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"6.0.1","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"0.0.0-canary.69d2497.1","fusion-test-utils":"0.0.0-canary.69d2497.1","fusion-tokens":"0.0.0-canary.69d2497.1","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.69d2497.1","fusion-tokens":"0.0.0-canary.69d2497.1"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.69d2497.1.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.69d2497.1","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-cgkkBhuZjMD3PpxOjskzF0Q+h8g9kXR8/rHrzF78lDuOh8LzTrCkuSUU9+IO+zp1/zgVKkkKMJT+Fy8YfQGIAw==","shasum":"f26329d75d936cfac243dc3615e88797fa62ee76","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.69d2497.1.tgz","fileCount":18,"unpackedSize":31272,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdHPENCRA9TVsSAnZWagAAAh4P/18qTZTaeukBrZ032rF3\nDeF7gT3ViuvP+hc6vhjE2YvDpE3eXG7upnJXlyNQpBFf1/dBZYrrT/xAxPsv\nLh1iaEmiGYZn5fFGNdiD3rOZfPgiubZTAYPIUgMqv0UzSDm4qSgMUxKovWUL\nPryuf2lOIhkAUEF6jiZV/MBNnKDtu0xd698pJHD7Bn2fKtEL4AKfoG5ivM6b\nTrHczgORwENaz5q823RbS3jva9VJR7AxJ28uNVKZmDDVsl+uQFqB1gLcKu5F\ngxMhxltKn6LOXq+A1TS0D2Nyi/AxUKN3Nsrd59ZLedA6hzY4TY+Xcro+oyPK\nlvR2+DsJRzoYK0kOWYwLU7RYC6CUqtTWVXRgHcQgZOglM6C5LzE4YZ+rv1TK\nUvoVlmbGMbIUScLoqqWldHoWdahPuddaqb/XqCHzciyrWJ3vNnRnDdrZ7o5T\nAaNj1aO7oX2VCN5K3RbWLk/4ZmkiPMnvH/KKdjXz0r6AnLypZam/DFJaEQLo\nmgp0XxDFLhJOv2AKb12fHcnN6mj4uwv4E2ELKEWs4dv+ZjB2eFr1cFKCR6tS\n96MNQxgzX4oY8XR/nTI5gO9pHduOwc2lw/JDyzNNHIoMVJZDdgVcQTvpTEhP\nX8ZWnIIxbO4zOyvGeC/t7YaC0gu/5IvPwPfxteQzilxbaNubisUGlPZUkQ3J\naNm2\r\n=GIzY\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIFAww52XaZJ0GHaqZzXTk8ky9aEiqF6rKrWjfMmZJWIZAiAZ3De+u4Yq72+ItP0aECy4mZy4nbwNYcQvd8vJBpUL5w=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.69d2497.1_1562177805291_0.5602725061554557"},"_hasShrinkwrap":false},"3.0.2":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"3.0.2","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"6.0.1","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"2.0.2","fusion-test-utils":"2.0.2","fusion-tokens":"2.0.2","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"2.0.2","fusion-tokens":"2.0.2"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-3.0.2.tgz","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@3.0.2","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-wP350j7EAbrzo7PNdsqIH4Xxil+KtOtn9DNuMN0qFsVOQ4J82i+tZKnLZ3JPw8AyBnlrS1e+N1m4B7LdHplj7w==","shasum":"0e14da92ee012249ca9c4eda0015ccaa894d6855","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-3.0.2.tgz","fileCount":18,"unpackedSize":31170,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdHSnICRA9TVsSAnZWagAAjNkP/2cd4DgA7GE+CHoKeLij\n2a0aLps0uvsy9GhwPsJfuo+AD0xoao4LQW7RCHzi3q5GxTSxBe3t3ieAECP2\nhMszjP2q2zcHh45/jua4HuGjUSXhcApAudEkxOAAOOkPa7XazWKyBbTHdQiR\nD2yzk/LIIk/j7a6YR2uRF/XrpXYLeNIz97+IMDMsClAoM1CgM4RXGJHPAG0U\nRaclWNknhjn/celjfXYUW+4caBq8iopBTEN680Xpuz5yP3iDT0acI/jfp9Lk\ne5XAp+ka5nznfv5jk9EB0o7oqUiW00GjBm/ps+X3sWpNOnpW1CI9eXLo2DwN\n/bB8Oh80sMbVICuuElxPl+PqmL283n/ODNeEpbRGwJw6kQKSaHI6nkA0KEhP\nCwzipdKAlynm3A7lNeFcezDCHanAdLIWn6ESU6rvwvZigdZy3DSdjGfYSlCB\nqYrMapYDbPVdtApVicsTsQeZaSUQ9n9KfV9oVxuOPHEgu9m6sy7x+BYEnj5N\n1pK332V93TPFtuTLxCUKnWYjEqisYBHP15ptG/CvHB+ZTZNNGLpy1/a/jlxB\nW8dhAqb9IkPB4cN1dJb8+R1Z2JyZa4WQStHtZq9Y2qdXUMOzcF/SULucsjkp\ne76rObYWSmrT++EgUDBND9yEHxhSMB/KwuYmo+CLIHhSm401GIfjPZnIskGB\nRRNZ\r\n=7KPR\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQC3k707E2R41O5RLx1mCYV41Lxat3NBgqfont1QBzcSkAIhAJrSzBPV0EDHw+MTfG7hM09ddOvuaqUiK3tiMMfckH7E"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_3.0.2_1562192327415_0.1707306690467436"},"_hasShrinkwrap":false},"0.0.0-canary.98adb08.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.98adb08.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"0.0.0-canary.98adb08.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"0.0.0-canary.98adb08.0","fusion-test-utils":"0.0.0-canary.98adb08.0","fusion-tokens":"0.0.0-canary.98adb08.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.98adb08.0","fusion-tokens":"0.0.0-canary.98adb08.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.98adb08.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.98adb08.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-qOwaP/5rFrlQJuwHQQvilR0wKm+mWcyxyMWbDDENxxFtEtuTG7pxQlBCU0Ns9BPNEdBXvrGvaKCgWb3I0CFG0w==","shasum":"e4afd129d19f4bce282d5564301a56bf4a182fa8","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.98adb08.0.tgz","fileCount":18,"unpackedSize":32741,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdI73rCRA9TVsSAnZWagAA3esP/iXZol5dPtiqgCHqcw9D\n/1rwdw1053edU2UCe3nWbYlo47ySLGBoXXr5eJ2q1/ydm38YPDotN77Qma7I\ntSaBbndXgzqXTFmddBAkOcQw7CMPhxUlqxKg8A0MtfE1SNwOala0T3tvQpMn\nKYRZt/V8u8SeRayrTdAzKN32KGJLYRSvIFd/jy5oYzUXrgIWv03vEGBgT2wO\nnMxX0nZm6Q3cPWn25aLHbJ9zuWNeZ35y96ZDKVj6raRv27R2DFM0jG/nhZ1z\n5c7h1ccf+Zss111hGqzJqj8sJX5iSxJWYDaqgPnmS/wFpOSw1b08/IerjYV/\ncLtQoG5EKCl6oIwe0Nkc91n2mr7elP/8SO0sZW+fRtKR8bYkkkLOSJ8DGNO5\nAqkr3WPgGgPqvEHNdl3z36YpmO1MpsVLWfeRZ8UiDWfdo28LW+FiEdAElKrB\nfjL+TN7dUqRid1Zs6L/vG5UI9Yb3IwbGsVQEe1chQxGTdeJI3Y0hxB0GI6gA\nZxBoa/hfosZ5UdWx3sxx7x+7nH31jYYu57G4OyFGmJBs/qxf+dFwl7CyhKmV\nXOUJ9dji2PTJ+yKkUY1NDusF2mqi8MTLkT3AiGH2nPZP5OpN7bADwFN5u2lI\nWmsJ63Auf1BtxUUr+fcHHjnPWqfOWcKobkeq9kObaEMi5G9hwGCcx8X1OKFD\ns9xU\r\n=iYfS\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCICxaAy2B7lqq5t0P6vFC/sdo5ZtqXRxuArt/7B6Q1v3GAiAQjNtTlg5lkkkJkLFrw6X45WWFtFO53XoPJu/MDYkfgA=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.98adb08.0_1562623466689_0.6536697005196417"},"_hasShrinkwrap":false},"0.0.0-canary.016f954.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.016f954.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"6.0.1","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"0.0.0-canary.016f954.0","fusion-test-utils":"0.0.0-canary.016f954.0","fusion-tokens":"0.0.0-canary.016f954.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.016f954.0","fusion-tokens":"0.0.0-canary.016f954.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.016f954.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.016f954.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-t4ORZwFb0aXwhVo7y8t12MS3BQikePMBtooou17mhKpE7xCt0/rUViBbRscneviWP8Bq69zKC76KuSXJQN81ig==","shasum":"77cdf6566ddc185c21527ffd0d67de149a8f63d7","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.016f954.0.tgz","fileCount":18,"unpackedSize":32724,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdI+EVCRA9TVsSAnZWagAAlhcP/3Mz/sqmL09pBUl88vDB\nhW8Nb9sduptKUg9NtWudLYv28+BxsKct1hNz8w5lIm1xAYNtTlNHfL/8t12i\nLH/sE2GAK4UE7+yhwl45MkrU++4eYq0+556MfPkIftPakfkwB31a7IuJf5yD\nCV4x31CeFi+wPbAEu9gOpB1D28ONDfETLosHc5QIHfHv9bJgXgOo7BAz9SYe\nPy00rUDgVs6bwFvXjbHnIj2d/zVrZEVzlSdPH0xBZuOX/i5GhOBILzqgFEgT\nQw827TVp8XAlEJswSvSgbAcJ4tlBYoVNdT+6uPfen47UND6b7DHOnBGfdv7t\n0ugjbmZDwdkdRH9t9gOBsjYSQCFxRGVSWij5PxzGCVbVYjwSIUELXpsu7Ymr\nam1YuXQoUtVuiX72YxfrvHfh8+XP36RObVjWF7US4vtntutaK0Hj8BlxmyZS\nfpw/ZtSZYTBtQZJstCkreGhxsLCz8Rgk1yan9r8yVmDG1Y+lN1n4zjOSJ88A\nGcn2Mcu6hE8AZsFiAZC/cvXgx7OOv7bApl3P7NVPAXc2K4dducMDkq+vTkD+\n9YYdO5iXh/JyCiqgrEeDHkpc06gi3Qqm9u3tnsjH2I+FCAHtWdZsk+6VgIwf\n7KKibH4TZDNokM0tc7kXdOxZQG/BfI9pn6nI7tN0cp+MWMdccgeN9FxvVrr8\n0caF\r\n=koep\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIGIRF7MZntbxzjIc5ZRR31VjTIpHZ/rLcsi/+riKzHndAiEAv5CfY7K/n0gJENSN0/usbguE/760CDqIelSg21aUVMc="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.016f954.0_1562632469079_0.15851458135477814"},"_hasShrinkwrap":false},"0.0.0-canary.1ddabc1.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.1ddabc1.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"0.0.0-canary.1ddabc1.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"0.0.0-canary.1ddabc1.0","fusion-test-utils":"0.0.0-canary.1ddabc1.0","fusion-tokens":"0.0.0-canary.1ddabc1.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.1ddabc1.0","fusion-tokens":"0.0.0-canary.1ddabc1.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.1ddabc1.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.1ddabc1.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-kMS0jwTS+zrmLHRcde727ijp7UIB+CJ6GICC5en9dMala1G7bS96Av3x/KD7hRvx8Ynr0odGBgI6RtcIOpo1sA==","shasum":"0eab0f93a38bb9afb9e8c77b24781aa1bdee068b","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.1ddabc1.0.tgz","fileCount":18,"unpackedSize":32741,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdJNtgCRA9TVsSAnZWagAAOnoP+wb8UW+HzWY4O6ylkDZH\n9xDBkShs+pnLx7Y3CEOQgqG+ELXZdYSqPUjPBTPnb44/AnEuVZi36It6nKx3\nbKHirQRjzTcoxq/mC9mMOqduNvRhEPc6xQP1paZz62itUPeCLZABywYOlVYy\nPtD30+ladk6IhFi+8ap02gRXH4I1M3DqxRoFSPqa/GXF5NekijKJKOTdomWI\nvPdScIv0BUIkYvNe9YfpK5+uZNzPYLmnM3uQpxYAsm4eWJwlamQvK33bNcEI\nWr/7PGUC0LxHiNzM24oEiOzDfzb6+k4c2rnYrej2UOa0nWvalrW0WQN2TCE4\n7rAjZ+P/9O/G3ZetjM/KT/a5wejrRxKy0+kzwSzC0Xh6MR39BmiXC1Oz9DHR\n5DiqdlR1S21qchxV6Mhs3uGsUw9uARwcO7/uJtWwJSEVkbH9C9+I0g/lYkaw\n5VO7YnnZjBwGYUjQq/qb0g94EdAtsSBe3oWs+sntsCaq4jYZ3olMSXipNwzJ\ntfChrdMrucD1QIQo4NOw+I/v6AAq+7JQw8eNwEmG5E9Wb49jyqxFDlIh3rC3\nV9u+X8HQZKiWRdT0u6BHsQVmrMNSoeIEroed/onqMCDBxwNYEj+cPnxL65rQ\n73+pNhkHcBuAI/EwcoGsx7DHJz/acbEeQL6+JXjeS5p0dutCtUAgUqUec1cS\nmY4b\r\n=H4Pa\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQC6rqMvXPrf8G4EXnvJGjeCyWsxd/KXhqkufIPK0mr7nAIgDHhd49mxvQH/Db5kv+ZcfhTjBz+feLMF9uOJSIBM95Y="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.1ddabc1.0_1562696544195_0.7571106886683843"},"_hasShrinkwrap":false},"0.0.0-canary.1ddabc1.1":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.1ddabc1.1","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"0.0.0-canary.1ddabc1.1","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"0.0.0-canary.1ddabc1.1","fusion-test-utils":"0.0.0-canary.1ddabc1.1","fusion-tokens":"0.0.0-canary.1ddabc1.1","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.1ddabc1.1","fusion-tokens":"0.0.0-canary.1ddabc1.1"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.1ddabc1.1.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.1ddabc1.1","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-0r39KvpJiJF8Wypq79yssOOD5UUGNtPFnumYEqLOcuR9UKzobQbTzaH50Zf4Rc0WuzJOt36D/Sp4V1/7e8oYEQ==","shasum":"bffaf89fba31a3c521e912360ca6ba06159da5f8","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.1ddabc1.1.tgz","fileCount":18,"unpackedSize":32741,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdJNwxCRA9TVsSAnZWagAACbIP/Rxu9wdrCLYufmdXTaoy\noVr9sGUYpq4/zn1na7tQZG2litZSucXKIuS2oD4T7PenR9O8iMpn/QYcxqcX\nwq0eocvF3TmSQuym2rkhW/c8OBDESB0u7d0RSDywWgBhye4vOUnHLyBLiAFg\nL95k/MWq17v8XceGgQ2Cm/NaNY8scuH3V4drdxihzHd0wMMQwVsM+y9IKmjS\nDKRUWd0KRh16plsqjgra7ZkCoEhUvXACkohASFxHq1T8FH1VsK9wGTKeTxyl\nvqAT2FZkc9Aek/9HDVwBR4ofY3Xki9BoGXWL9PW2egV6HeWGlyUAAtGxDhs0\nR8BjbqMngl+AsSadjDWKwq3nt81auYYDzLpdh1L0UmZC6j+RryABjzdUlnGE\nLt2wLRuBgPgF6hN3r/giHYTJXxuHPfOsSFZqg3WSX+MW+Wxt9GnW5PL0vbTD\ns+knhSwo0vO6LDpTW10eal2N+PySD1gHOhyPEt1/AM5OE7H2hjuPz2ULCwI8\nuX+KhmRK6mnzmxm08IppZZvcPIVZV1Q7Hst/cAOJr1wXZ/selkDMsEJ81DH5\nyASKevFZTV4J68Dh+ho7ms0xioZtikQGdEnaGy1QgKc828xkGPBVZyivApnL\naHwrkTsqNAbKpBuASs55WK0cH/uoAUmtmsHnjrLwS0doLv/d7ghhoOmgVsqX\nE7ho\r\n=F8rC\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIFSwpgoMYTTHl+g+LUs++Td/0ktOy/qKk60ifhC7hJ9oAiEAw+el+t2iDY/p6hdMN89elfL2iqNM/XjJl/LmTnxR8aU="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.1ddabc1.1_1562696753220_0.6711447736448133"},"_hasShrinkwrap":false},"0.0.0-canary.40eb0a5.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.40eb0a5.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"0.0.0-canary.40eb0a5.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"0.0.0-canary.40eb0a5.0","fusion-test-utils":"0.0.0-canary.40eb0a5.0","fusion-tokens":"0.0.0-canary.40eb0a5.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.40eb0a5.0","fusion-tokens":"0.0.0-canary.40eb0a5.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.40eb0a5.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.40eb0a5.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-hgbGnil0e3YTdIXZVbVSYbHYfZH40mp/nxx+cAYguaJM8UIdoH3z/mdpa4YD/i5g9/FBktT9Lmmk41jqqvSwYw==","shasum":"c9ccc8e5db8728f8128240bd1bcb3c9e63b5190e","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.40eb0a5.0.tgz","fileCount":18,"unpackedSize":32741,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdJPM5CRA9TVsSAnZWagAAgbAP/iykTo1h7hf4v85GeWuU\nFVPWxk0pu3we/DmR/+4mLp5m63dEPNb9GRF9oDNZxjFjyTLwrv8rqONELoct\nXTHOArCP/I2a0kdSJ9hP/Jc5yfadIuzMU3G5U9eiId+1VLjbwybTjYIBCWfM\nVBwV0uSn4VULibEaZVi9RS/YCqVyAaShinCbrDgSDu6bkPbVA7dNAv/efm/z\nBUyxb9wkQAZt7EOhO+149C1yADJaMeNVWOAwfQA2IcVGGjahHECcMgnUZ9ZI\n0MCkdfM+qR0KSnUjatTXXio4eLcrsIa4X+yJb+DJsccqUK6/rKhhdexl9sUf\nnr+U5dHSYg8KeDe26Tu6WR+jD2bZ9BkR+edKnkpOv3Pjl1Zm+e4px69ivhfE\n8zksw/qPFdOTKLmXPbIkHdb0py+1tx+Ew/qAhCxNW6MVCzOYHj43ghYEHRs5\nqbYcsL0JqVtT6sZAQ3GDsNbv5vnNFe6CowMkimbFss/W3REGkDKIqGJLE8Fc\n+Flohvv34Pcc2+Qn30iQZhs2TWPxB6vjYotlNKNxs3a44dXzIrcMRDTao4eg\nok41DrjE+qCcohkmDPwYEq6DXZpUn1Q9zetwI18g0J61iIq5nPwC1RsK8SaO\n/CG2wEH1dMhCMxU1O5UwoRowwvhwu46axAHm7o+hGIUlMzLuxqbm0savOEd8\n+eo8\r\n=yosH\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCvUUcU9mVtgkcO8i+2JsTpjv7k5IDaj8P28huWmYCJnAIgYy6Ni1zKBgdbC6SGztctHQGvGZ7UdT8xzYVMEPqRtzk="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.40eb0a5.0_1562702648601_0.15708458384504742"},"_hasShrinkwrap":false},"0.0.0-canary.40eb0a5.1":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.40eb0a5.1","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"0.0.0-canary.40eb0a5.1","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"0.0.0-canary.40eb0a5.1","fusion-test-utils":"0.0.0-canary.40eb0a5.1","fusion-tokens":"0.0.0-canary.40eb0a5.1","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.40eb0a5.1","fusion-tokens":"0.0.0-canary.40eb0a5.1"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.40eb0a5.1.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.40eb0a5.1","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-A1jNhOC/vPcYCkso02hHrUhbaiAvD2ewAADm451B6gwIpz67Nfj3BLWIzOYDzohZmFBlsU01LCh/lYOjMRKY9Q==","shasum":"2a8c4c99b0128aa613e444ac25c276980cf45d18","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.40eb0a5.1.tgz","fileCount":18,"unpackedSize":32741,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdJPQWCRA9TVsSAnZWagAAm3MP/3n3moAEZSsnaMBBWWrZ\nRXISdFZucHPLywXfBVwikPsxv2OPejBEb3L4MnbC/g6wvlO+S3shuoPxwwnu\nH9nLR7HY9aMS9SYYS53CBq3VC/CnXt2b3s1Llsl5UGUaBGvxZoUT+MYrwwa/\n8aJoQH99aCeZPrN29RQy/7DLAw9rnuYZLm+hGzmIQPeTFhynVE6xV29KngnF\n4JuzKphz3FCLfiD+6RiZ8bGFsHZ+3BDzDyQFP8+Gw5I+Ipky0YV0n2DKvR0Z\nH5RlVyvuknNwXKCxj9h6nPa8MDeb9GAb1nncE4ws/KeCINGSJ+QL5mdVhxXf\nB1Nd0+xYO8oNrG8TOh9TJChZ+9Y2MXv14DtqfVnOlEI965wUSpiGwOs00SDH\n/g8YCea9yQ7CD582quf7mFiJWWn2Nt+eO0iFVYMELSWCuJl6liMw3rAFBwvt\n++LBf4yZzkmPduGuvq6Rxg1JStwoegn7Zj1gopJCl58pQ4ScAtHwaBhHH+uK\n3Vu7Mx7W+2Dl2jlrT5gMDJOTolP6T8BanP8Ve6IWh59pBZvtfswi1+n57OFt\nDFVlqm7ZsW2NoSAQAFJxjD0hhENSwdKQWW7LtGSsVXXlz5CLliRVz7R16TJj\nFWfL7qbuF6qwYHVb7c5BPam9ge5IF7fBDbmZG7Xj1hjXVaHJ/m6NgZK2hdxg\nN0dv\r\n=n8Rg\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQD4RDxAZ0pkK8KseeUMtKBI4x0VknbepMVYwuD3mCuYaQIhAJWY47oUTeJaP7NlEVL8YVqB2SHbrdMhjJ+Wja3CAZl+"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.40eb0a5.1_1562702869812_0.22719296699139324"},"_hasShrinkwrap":false},"0.0.0-canary.fbfd207.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.fbfd207.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"6.0.1","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.98.1","fusion-core":"0.0.0-canary.fbfd207.0","fusion-test-utils":"0.0.0-canary.fbfd207.0","fusion-tokens":"0.0.0-canary.fbfd207.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.fbfd207.0","fusion-tokens":"0.0.0-canary.fbfd207.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.fbfd207.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.fbfd207.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-RY4ReVm1KUlBI63uK6sB/RXM43hzh1t4mX+08O3C1l2/hBlfoqePtENwzyllcGClJdm/HH16007lILZJVuQzdQ==","shasum":"e7b127c54e58ad4636969425f4860d255e37253c","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.fbfd207.0.tgz","fileCount":18,"unpackedSize":32724,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdJi3aCRA9TVsSAnZWagAAMMsQAKJMbmvSS02mvsFuXihs\nDiNlymVi1PS/8Z90dx/QdXmX5ASwz8KVAytrS7G6nIPKE7xW+oSWIqRjwUTZ\n+k7x1SFUxpp9SWb35bGjMNBKdvkVGrkpFIPr+wliRwt8WoOnKIHqyQ3Sa5Px\ny4iw25HwBy7iYamzSAxOLbZBleCwK1zFuppHu+/dxS4qHK6UW8oN+athZyQw\nJMim1WjmdDvG3HcYrY5DBmiB4VDJlfqi8mDaosSbyUKLNqU8Ux8FxEI2b87G\nQm8hVDW8VDPOHT46XDvvq2DGJmf7wXIf6x3gkpoEXcVkSUuoH+46ddoEgEPm\nkqNzaIxdSz8ndtC5ErEGNHAKPXJa1NKzJDSea+JRqy3aqyP9QoIrtr8pISli\n+aMauyKFYAAfYcJEqb420sEyUXmvEt+IaLi4eZEElNBZEbohj5EQ5pVRPG29\nHqGjutBQrdcBoYh3LgtISZ4B0bHI0q2YzEgaxyyIonk/ekB/+TIxAmONEUOC\n+efJZ+dbx7Ct+4lG7mrevRLxmsoQsUa9hpGDck8nzqDxufiZxIKFKOfoefCS\n2/o2dyWd51DJiPpJ9ugSsG6pemn4+TQrHVvsxrqk0VcH+WTr5huCGNgjfHiZ\nm06uMJXRoJITATLw98x8BTqBWoX2B83oYj7+Hce1LlGPPS6K03I5HOSdMVyB\nPUd8\r\n=rzWh\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIF4uYtsuLKX4Tz4lnoIwWF2aD4ro8zMAUHBIGodmjdZ4AiB6rQIGLlRk9zri28IqKoPnhIf4VUGpJ18fK3G/N/g2nw=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.fbfd207.0_1562783193860_0.9535138990819376"},"_hasShrinkwrap":false},"0.0.0-canary.4c30d33.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.4c30d33.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"0.0.0-canary.4c30d33.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.4c30d33.0","fusion-test-utils":"0.0.0-canary.4c30d33.0","fusion-tokens":"0.0.0-canary.4c30d33.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.4c30d33.0","fusion-tokens":"0.0.0-canary.4c30d33.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.4c30d33.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.4c30d33.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-8Nl+tLpb1oKgYsSQDynnDfGCVlBonWHMLmX1+02Zy2XfGS70W/WPWGrPjKO8wkEFuDxTX808hHOwrrZPBOQeew==","shasum":"993718ea99e2459560849d1f19d5da6157d31864","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.4c30d33.0.tgz","fileCount":18,"unpackedSize":32694,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdJlPwCRA9TVsSAnZWagAAEI0P/iaivOvbMxFOm2i2B5Lj\nGeqbnjHVeOHVygmWjqdlrNoynYdmYmSOXe8F6giTWUoBHzYkwO2YU8aI02Q4\nvYu4Ux0XEBE+8AOs9jlqr66Qkd5LVIkvT1oXXdCSPGbSyluDeI7ViwbptV5z\nVYV6rSomF8DdnRckdvLYGFuqnCgAQsZfpz5bB1QHVVkOofB8vMd2cwiXkmOQ\ngdaS/vMJfhsgGF9wJ71xN4WFMVqSIS12dNwBrykvcdH45ZX7SqtEfvixViN6\n1OMiVfEWV1LpAAyeMTzTRMiG+6jxq4letJ0TvUn1vnOywEFfasnqjDiZkT0D\nMOYvBbxfGpM7CpUTQcY7+zZya7lZqB0xsLZ7n0Pt2M84lA5YHXKn+YyZ7M6m\nA83vdQ7Z2fukW88oPlqYnp0YgrW3My9vRhD4DkordvCKqXS+eWcy0BLcUJ+c\nSQlmBFWAxKB9hVFGkXJesSOayjToC1Z6S9kj8hzBNUH854PhSDZvm+gzf8Jy\noI8PbYQskiElpId1b32up6oucTO4F9BQZsoNx5wEQxxql6KYuyWsBwxFtRf1\nDzdLjyAmcjuMqCuQAapCEeIM1R6DE/BFXyNg07m/ArzD4jpkDvZMrXPWWDcE\n5W0XhGjQWrdbjvv+ytuZYubYaf+MTpCBo8x4nC3UWW7c/g79sSL43ofIu7O4\nX3dw\r\n=3lc3\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDYVUTX+jEu/sPW1PTpA78iE/GZLTnDBhErlqB2yPKx+AIhAL9UfK+7c+bglb1k0cQVblkzs4U47ExSXnG0hsxbHzJl"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.4c30d33.0_1562792944292_0.7363566868692044"},"_hasShrinkwrap":false},"0.0.0-canary.4cb9c2b.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.4cb9c2b.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"0.0.0-canary.4cb9c2b.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.4cb9c2b.0","fusion-test-utils":"0.0.0-canary.4cb9c2b.0","fusion-tokens":"0.0.0-canary.4cb9c2b.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.4cb9c2b.0","fusion-tokens":"0.0.0-canary.4cb9c2b.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.4cb9c2b.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.4cb9c2b.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-0Ud7igFIEvHA9S3DO9k3AQwTzKwpp+V2j4C3dE0jJz1X/1ICmUeiCTyK2hTqnwI6Q/WmQTqJeYJOWpFr/YreLw==","shasum":"dbc927734a98ce70607872cbf5de87d07f5f4adf","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.4cb9c2b.0.tgz","fileCount":18,"unpackedSize":32694,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdJ241CRA9TVsSAnZWagAAHa4P/3eJllxsxMY/2mBsI9+R\nLhBUiZCdm40zl5fHdYYBnjngncP9HYz9CGS2cc0Gc5/k3dL70MtemT5CkEmY\nlNeypZiaiS6Bp0mD0Ei4J2sCSEGXItLHRCQlL0Og9sbdCYmEqpIYq9S3CQB5\nzs2EhzlWCoCUDpNJDsy3Sjjfc/eTPzVpcNy3cVT+83xUuXVioONl6E3p3ujI\nV+VRZEA8nWKBpvuc40uYQz06OCOuTH9xe8lBqlMr9T6pCbEYaa0z6sv/Jol4\nCUAhjjsOrKXTLp12rcWOJA2PxJ0fHTBTkMN/K3Kwp9EhUoy7JUusVVBG/W0u\nJ23IjmsNt1PlBoYAIvXhYIOQgIuxBz4x0Mpc4FcTEc6U1ygTABN9ukQ6scZk\nlz1+PY7OaeB5ZxhlV3I53/JIAdqf9wKXhF+HmSDyXyjd17CKUSYQgEY548dl\nW9FZLyzmiHUgsAd7EFLMNxd8vUG1QKGLF5E2uxqzZ8kQapxvR3Eybv/qdLjM\njB/ie5a1/VkVWpIGVgNA+KpI2+AiunaujgSCpotG9NcMlHmpwpz2Ltq4spoo\ncucNGA5hCRpvQf+ykRE8dE1cxqBGqIXTLv8qMSJMuyNIaNDWpiMtNjzrW2E5\nSutapXkVHQ2Y7JKpfvfYyQhqyLng7XWrOgw2CGQ02pA4Lkky201OlXYD15+K\nVElE\r\n=CmFX\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDm0DAKfx6RokkQt0PrkIZPihhVKNX/GHKO/4I3Kdr7UQIgJyDKZFPVOlioD/3hT158MlGm2SZxdLf/+/qUmfVcDf0="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.4cb9c2b.0_1562865205280_0.3544148292508138"},"_hasShrinkwrap":false},"0.0.0-canary.b0e5994.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.b0e5994.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.b0e5994.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.b0e5994.0","fusion-test-utils":"0.0.0-canary.b0e5994.0","fusion-tokens":"0.0.0-canary.b0e5994.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.b0e5994.0","fusion-tokens":"0.0.0-canary.b0e5994.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.b0e5994.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.b0e5994.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-yJ/cxbNFKObvxJmzDAMguSH+cK6O1/xMzNtZr2yovzkQpsSyg+KSOCE/9lhzmJEep1Xc2hQIIyEnY5XWoFA6PA==","shasum":"cdf6a431801d6fd97145fcfdd8235b27e6037e86","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.b0e5994.0.tgz","fileCount":18,"unpackedSize":32737,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdJ8UyCRA9TVsSAnZWagAA/a8QAJSFRz2A7HGxt3GR8HTi\nQj9jIxopZ/2gu2N8QlECb2/PEWu/pXi8EFjH3iDi7azzP4jMHTAWiU627ikZ\nXvSt5YhqdrI1ZYCj0d6X4YlR/N8FMM+/wlMPbE0AD/O8cG4xTPkIIdkCNm2i\nfEpmnEMI0x99GphkKrEAqZyd7Y+1yklUJI3LK4CNlQiZ2alUA+jAiUQCqd+f\nimMNEIiotW8fgPDpdScR2Y51vvDP80yn/s5rxSb2/2SSqA/BRPHBJQynWbHi\n/y3RmDaWqm54txNOI+VhKTB2SDcVxjHhJaIz38djSn+p/RpTo224HcQQdL3i\nZu7k2Of1n8REBGM2Co7uE9v7wP6NXolan85fnjKlhRbqPrKN2AxK0MsOcZzA\njQSWT/J8vA+nOF6j35TAGub0sgaB8AXvM+NGidItaaqesrzLe/D+CDPB6HVq\ndAVorXKhsPVtpZnNwuzLGmQ0VuTf6B2nZ04DFTLGbLEBzj89YNVA28nvdiWT\nh7BCsRObwL3qNykR6WpWLNZGkXKZo1+UKtvqPGt26xFVnBHuJxfpKQNm7JX4\nNun2u8h9syq3yAuT2clxY11GXe0LgkaN40bBWLWxn0gBa2BCFAHz5r9EZWXb\nwYhH+0vZsK9+vJhLelOm6sRaSuMJv0RnhIQpEcfoI4GzGZTOrOavWaCj8FMx\nEQxC\r\n=lEn8\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDHWsU7czf++J7NekYtrfjjAcpMBuB8MHmkb/XJx/7fWgIhANJEyjKvOZCBXh4ItdU6IPPsszZTcniqdb05beVc5WZs"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.b0e5994.0_1562887473514_0.22625104779479455"},"_hasShrinkwrap":false},"0.0.0-canary.50aa07c.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.50aa07c.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"0.0.0-canary.50aa07c.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.50aa07c.0","fusion-test-utils":"0.0.0-canary.50aa07c.0","fusion-tokens":"0.0.0-canary.50aa07c.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.50aa07c.0","fusion-tokens":"0.0.0-canary.50aa07c.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.50aa07c.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.50aa07c.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-BTFZZPt6rXTXe49wcaNb2/DP2G+blsexTDOQKiPmEooAO9a77N41ZSZTGsUpouexuAXE63bKb0+B/xQYCzqYTA==","shasum":"881dc8c9ebbfece6f0f643c74565fe6260d6b394","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.50aa07c.0.tgz","fileCount":18,"unpackedSize":32694,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdKLLPCRA9TVsSAnZWagAAKgIP/1VC4xsAVt6JveM8HtTm\nM+JK/GNC01nhihIB4v+DlCYDUs8edJLgyDqfXpsR6PIt0/wsSdJBCggVaflx\naqblLD3GYvzT8oKxmWeK4oqwb417IY8mIPBLDE8Kc0ChLvYVEdw2R6eV+fuh\n0wD34a83Pp1gKLLJpBn5gvMNxSu3kcaXBNS6ijrdEdAjXgN8fk2ucZhre6hz\nU6fKHnbs//Dgvy6gqpMvRP3+920XYsSZNOL+TENLViBcFlxnrvzZ3hW1Pr5D\n7+c+l1zHDxsEruWaRoXK9u5JAGqXaPuTfdK1holswdaIlRjdQ0xCoIx9FMHX\nad63Mq7x3xTrvJrcxNL9fektwZaujctCY+lGgaQO+0Y2D/bfx192mHjxFukk\nKMTk7E9AJxjNsQiwXWFjgVYPwJ4VBEGC9bQXZT6YfSa/dI/4054stX+LDOSO\ntrsU6HsY8jo3gOO5jiJ3EKpkuXg4IK5S76z+znZEsQGNsnFT5REvWqX22X5E\nuvaA0GK9NW0+CzNYSDYB4JG8zX+hfnMiPhlWeE+X3Lct7ULWenlBgeWhHmqt\nq6NaT1/uDpC92P2WO4+Pz3t4n8qnIteqn7QIgosAihvOuYijODXByRBfaXCo\ntKy38Dxhb24p+tv+6xqPjn75L3vZ5C6RIZ6VaVmampnRwb8ThJsa6dj3KrNc\nWnkB\r\n=lX2q\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDzKIHXGTdaaDAo5XdnDRE4l09ENfPClTsSnGlxJGk/jgIhANYDZbeLv6584O7StsangPwEialJYEmHNmQ3sjtKTqVE"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.50aa07c.0_1562948302839_0.7906496845251108"},"_hasShrinkwrap":false},"0.0.0-canary.0a4669b.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.0a4669b.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"0.0.0-canary.0a4669b.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.0a4669b.0","fusion-test-utils":"0.0.0-canary.0a4669b.0","fusion-tokens":"0.0.0-canary.0a4669b.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.0a4669b.0","fusion-tokens":"0.0.0-canary.0a4669b.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.0a4669b.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.0a4669b.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-hpw6Vi3K9ynKcJz+2Ef8wDidng+qOP6GuVkC04gk/naPXsab0tUwowJLpT+LM+2UjrunOt9Jb55dmXSue4nsSQ==","shasum":"6e5a7d541b0add428fdbbdf3d6d074a858f0d3ac","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.0a4669b.0.tgz","fileCount":18,"unpackedSize":32694,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdKOVHCRA9TVsSAnZWagAAbmAQAIxE+cqdYxKfRUxfLKbA\nvMDzCwHxzGigGH6noxppekaI5SRsG7PFCjUEc3Pa9vCs3zD9JLjlXSSA4cIX\nuDy538461qSfXazUbl0akC1Pvf8i6l8m4VSLmGqp+1jMp6tEgT5Z0X0xBajV\nxj7agPP8KUF+0NXEWs8HJeOsNPHqJZr84fsAlOB32U6jmp75qhcUekaPM4Ry\n4v9Sm+lc8f4JI5EFpekZXj8sK+bqbmFJKpTBnBdzw0JLs8aGoZiN/NhrgZvP\nyNU2kaK8ZBEPOym/A18dNUwwAKxWSI6Nq29rXpCc9JjVuwoKPCmzxv6/xkoH\nr4qBYWn222jc2PFhcrqiGjpg29bYRjBBfG/UgGv5IzSsQD3Nfbw81cfbtnWq\nGnstosA+Tqb6YXsYKpSduvRFEqIHB3RQyk8BWKzvA07fsgg8sCHDrCyriRru\n+XjgWSyWN+CPWWMi1HElYMZ8Uk38N5mFpCgAxHb3Ctn7ZzoBmGsNG4DSp+wZ\nOMrC4p8WAC62YAfkeCv8A1LFy3qwTM32HX3sv1pxpynOVzrkEED8Sf9SEGff\npYbkYUzi5TJMzlDcRhqYgUhMTlPJVRL9j4qObsbCPYpXzEdSerXAyM8Oh7RH\nDIQwBm32nXYpdMUFFWyIlb77oRWMUnIkwsUlpA+qu/BhRpLg6Yl1h1NJneqs\n2K9p\r\n=qhrL\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIA4ei8MsBJ+/FAI58n+99REVAyjtsAZNIxbns2YfhuZGAiBWud6YjsgMHXx4RatbsXsDqlk0UtFg7UO3HZdXfC7+VA=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.0a4669b.0_1562961222848_0.6175976599181792"},"_hasShrinkwrap":false},"0.0.0-canary.0a4669b.1":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.0a4669b.1","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"0.0.0-canary.0a4669b.1","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.0a4669b.1","fusion-test-utils":"0.0.0-canary.0a4669b.1","fusion-tokens":"0.0.0-canary.0a4669b.1","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.0a4669b.1","fusion-tokens":"0.0.0-canary.0a4669b.1"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.0a4669b.1.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.0a4669b.1","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-o1F/aLr5nqS2KjaksxpAnlcDSiK1bwkORPILaoOG/QVuhlxJevxEtJnvzpCaGsXM7cEu4Db/LNS8oZ/wFR/9Tg==","shasum":"2f4b41e3d9b1855f0f0ffecf9687edde651600c4","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.0a4669b.1.tgz","fileCount":18,"unpackedSize":32694,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdKOpeCRA9TVsSAnZWagAAQEsP/3TqvVvVuELNeodDJE4j\nn898C0oPekqYusOEhxTyKb+jcSs4fedFQeuGuEuhE3ufGo6Z8+/BU1VpYQWb\nKcZBBi7fwulEixSh4UbQ7jHeEmz4sVHA94BPPIlxYNVlyHlaN+lowzZ3o3fO\nhp+3BJhJrBBNfKauQ8mh3bvyI8FOJu3srkY/apk97F+tYdoFYc0VzLZG93Yz\nrVbtTvVDR+ZESsibuUELJDDZanSsvMReX5YzFW9cmrdgxWuywTlvxFqfBtpU\nuLGPfM/PFZ6pvXaGzCMKyRPm2joX4ea+QFEttAAnpbvGAz0rTya6GYZjqRy6\nsEfstKV2ALoqi8Yu2m3nxB97v/1kYSADWjr2L2br4OqKJTyl+nGOOq0HesbB\nF/d+3Q7LHNit6yNtbMGC2i3C7D17peMG96q/WtaoEcMT0dhBxUVp98uMpirT\nK6jrYE4J8WoHGsyn3nrtbMCcazkums9+/IDnMc2I3ObZRdBgbOIVHb53scok\nu39rHQzF8vG+9S2elCRYdcrgXYI9+p0D4gjB/pJz2B7Kmnt4lnaaATAwAKNw\nHOuJZrUky5aDIqP6kmFaLcj11iNjwngYC4sCM1GaPk81IEFTBfXtzD0ZR1TX\nR1i106RSvJA1F5r7EYqVYXOtD8JSbls0vD+914IAMhBr9PyJX7+zuaUml/xc\n+2Ja\r\n=5KSS\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCksfWA4eXP489i5+ml4BkfQBFo2xiIOCGqmrxp5RlcIQIhALn9vZB7/fUy3Dju57U8KoQy46cru2vMyZddrZ8LI5Jy"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.0a4669b.1_1562962526086_0.6944698288228823"},"_hasShrinkwrap":false},"0.0.0-canary.3b5ed2f.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.3b5ed2f.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^5.16.0","eslint-config-fusion":"0.0.0-canary.3b5ed2f.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.8.1","eslint-plugin-import":"^2.17.2","eslint-plugin-jest":"^22.5.1","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.13.0","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.3b5ed2f.0","fusion-test-utils":"0.0.0-canary.3b5ed2f.0","fusion-tokens":"0.0.0-canary.3b5ed2f.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.17.0","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.3b5ed2f.0","fusion-tokens":"0.0.0-canary.3b5ed2f.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.3b5ed2f.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.3b5ed2f.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-7AxJIfEjtqP0Tf6BPtiPtOnL1/CWwLqUhQsL5k4GYiFv6w6y30ybSHwOXSbHYJZ5rUhpiEy4eTAaXRAH5MNU+g==","shasum":"8354b6f69f1679b9aa380ab1d920b87160ae2b78","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.3b5ed2f.0.tgz","fileCount":18,"unpackedSize":32694,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdKPEVCRA9TVsSAnZWagAAztAQAIUmfmWPsnJ1omsEtzw5\nx3HmDUOooRTSxw/8K7FRKxgjV/5o7j9zWC1rsji5tTkdONeB33pN5hU01x7P\npz5puHG5ETJx9CRDMZYk8SC6zBd9lHzuvt/hJnHXXD3dptC06/XucnrgrCjR\nN1wzlT5IYMaQuVNNRZtd/rTmTg1R91IsRSOnlxHd4g6tPYZad0sKHgWXcKLS\nQG7p+BlYyJ2D5syHIQT+z656HJxyYFOrlCgz3i4B/Ab7+zh/3tLqjcHxeCoD\nrNk5Yf8XEZU04PoTed2YRAz/zZUXMHW49LUTzkvA6yeNFrCN8nFtWVa6pYVP\nHEGjtZJRGJInNvZYZPdfi6L1ctgDtKzzZDnHV7vQt7aArwPYrLSQPjuOsI02\n2lg3KCHRXDXRxcQM2k9YhexrBs54cBEZ8ktSfmhrFGx0swSwmDQqLB0kb2K3\nvOmYlKANgnNpSgWcvujsvpfkQLpKz7lwWFBnI9nd+8QbY0I1b95lnjwksKGR\nEp8ZsTrKSeoGAqrXPy6QjtwbHoQDwpBi5W+BxZszheTeggad1DAURh8hOZf6\n0MB3PXMGe4EVSBIdufWH6SYs+ypztJ0GUtkiO1U0oYtE9cDcJrjJNd9Td85o\nHgChsf6X70Kvt0RdCzvnoT4Ukgg2iYFY4vqOJ/zbQg48x/Bdj7/2pNkofiUL\n7aUG\r\n=uv94\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIC0pMkKgiZ8I94XicQZ0nrtI5YL1v6DjLYReEAX3Nc/bAiALTsE3RdtDHohS3oejqnpVJmLg42ngsrH7S/jFkSKgRw=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.3b5ed2f.0_1562964245057_0.2591377026274113"},"_hasShrinkwrap":false},"0.0.0-canary.db655de.1":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.db655de.1","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.db655de.1","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.db655de.1","fusion-test-utils":"0.0.0-canary.db655de.1","fusion-tokens":"0.0.0-canary.db655de.1","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.db655de.1","fusion-tokens":"0.0.0-canary.db655de.1"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.db655de.1.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.db655de.1","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-mTC7GKI53vKu/PE9FxKnjJV0hr63U6u47jlJNdofQ7P/FIUoBXFnwFu6+7XZvs8hNGIEOi9LfZ9HqR4+shSRIw==","shasum":"4fd717d3b8656d88fb5b49a194a81e11b9ac993b","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.db655de.1.tgz","fileCount":18,"unpackedSize":32737,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdLSM+CRA9TVsSAnZWagAAhrQQAIvXMTG7uQ3V9OINvxeI\ngvIdqkuHXqtqQR8Dt+btc5PYfY2xCmfYuIERkXeOHkIWMc4QOung7ouzt/uO\nDwmGeXyhLfBoL7jcXA/VkQmoa9BTzK4MSb5AHD6PtAaP94tLHJfmlwbImhOt\nWEHhrM9wcMgWq4Q8GcZvDLpDNOqYbthAPCy/CSXuPQwP1BS9fd2B924ZGE6y\n6WGkOlpnd2St94Tz5QdZ7g8nMKjvKjOGLvN0UGa+mXM46mFE41jPvbTPWAR6\nzE2Omtm5nIwXvAgeOpnkhO6t5yBiHeQwU6DneE7IamveHolh8hTgbZKeMoCG\nNvOXrhPKvRBp1Ggk6oj44Dx7S8cSJMDhG9tTXktveZUTAv3z0SWJph34Vmq3\nLkTvWjIGm0ri1+wXIWRYBuCs7KtJ/L26ZZcMVF2LBUhkFhBTnZ1ccbz3Vy0U\nwQ/p+aeYSrgJeoEXG/18NxhAnjvjpYsiSNelKl34zD7byIV0EsFCbwDnITMQ\n7QNH90pD/AgRaFwq+FW+Z0GeJj1AaHZJw+QJrcKfCaN8BbqFsoBi5UKC7WqS\nXV0Sb0iH+rgntLJiW4pWAhe7/CfYyML6Mmqe6noKvXrsHS/WdpBLKL1UUCMQ\nxmjDU1sp8V43kcQUf9N2cL+9CU/y9aKFe3g5NvmNPk/bhkCYl9XvgVho78Y8\n9QYP\r\n=EJmx\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQC0rX9eHshWkBgaLNt4z3+KDbXRYViLeEQknPC6obLAmwIhAMP8nnNqJLhUOuFEtL17EoL5hWPfeiXEx30+WNZZkU7Q"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.db655de.1_1563239229983_0.6635058547300412"},"_hasShrinkwrap":false},"0.0.0-canary.396f8bb.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.396f8bb.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.396f8bb.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.396f8bb.0","fusion-test-utils":"0.0.0-canary.396f8bb.0","fusion-tokens":"0.0.0-canary.396f8bb.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.396f8bb.0","fusion-tokens":"0.0.0-canary.396f8bb.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.396f8bb.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.396f8bb.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-1VzHeYHVThBQV5Go4h8Rt+rAr21oFeZuoWLDMAckmfU3q8T6zUjKkKgiEC0tcQNencVWY8RsbC4j+MDKpYkfdA==","shasum":"b02a5bf50094edbafbb5dcf97f968cd5b1dace28","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.396f8bb.0.tgz","fileCount":18,"unpackedSize":32737,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdLhRkCRA9TVsSAnZWagAAm0AP/3wQzzok1CHCUq4NqJvJ\n6/LBmYiHfT1YXPceaPCJdbgSzvlOZXvG4zqfwNgGVzpPhwapNpnXk3Hkex2S\nZGkjbqcWrRGzWm9f0i/ndDxFTKluESDcvdbBA5su1XDyJYF0Gt7EQJIeXgTb\nCzD5jmexwAYUlORSzvWiI5eYwUAQVs9Bg3ndLQY7lU222JeSgpc1i9ByK1yp\nFgtVPwZQGBAB7Y9SP+ztC9E7BucRQ1q7VfjFl/KgsqOnFsA0A1doONpnhjTj\nLkTjJbUt2nMnFotIL+ZNTcgEeIr9Sm+qBpugu6LobKHNlYzAc0xJSCJfLXIK\nIqxZNHFUScm6O/RJXRKHbpuzo5cWDhiXtaDFVRd22o1fd1PKTV02saTsJHw+\np2NjetduZCh742lx+fyU7KIa/WcCADwy7FjxqY6Dya2AM0qA17Jzi4a8w6xw\ndcrsNJGTJeoysqc42wBDpizzdL5E04oZ8+y+sxxcr3wLtarF/M8jC+kch7I+\nijYKvsw8ruO+rn2dfNCVkLk666cafj1hZCoXTbYZ5j873umPcSZyolfaUvgr\nyaEbbnBrnnA7e5OoWpW6YqKQjbiECVZ+pMa4DTP8irRcG5jOj2W+BZ0LdsEd\na3zuxO6IZA1QBgFELB14CIKTy+zaq3GIBiZdkO2rSu0IZftp9G/ED+4beIII\nC+5z\r\n=3Dbc\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQC3qjiddIZS7HWHZ2qV8cVsyKJ7VHNrOKGX+zH2jqoi/AIgMc6Cb5Dtd2kSXEnMjs5nda4/BrOYGoDjCnSwpjAsPqY="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.396f8bb.0_1563300963946_0.9778702724508257"},"_hasShrinkwrap":false},"0.0.0-canary.66cfac0.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.66cfac0.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.66cfac0.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.66cfac0.0","fusion-test-utils":"0.0.0-canary.66cfac0.0","fusion-tokens":"0.0.0-canary.66cfac0.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.66cfac0.0","fusion-tokens":"0.0.0-canary.66cfac0.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.66cfac0.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.66cfac0.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-XgjqlhWUoXL6s5qoiPsREo78u/zlsBpaKuXYUM/przQ645JIa/cOLcD4gt2Nnq9xSeMIl8KTx0x3MglF8gtf5Q==","shasum":"084ec2e92b57715fce26318311e4ce43b8a9d494","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.66cfac0.0.tgz","fileCount":18,"unpackedSize":32737,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdLiBVCRA9TVsSAnZWagAA7+QP/A05rR1VDaWC6wJjKWbo\nxA/QK0BN/Pt3Pap/VHRiTn5Grw1z9Zjx617MJSBIbDgUE0qcK8+m0Hxl1pX9\n+SEyczgT6vZLJp2A2Q1j1IUjZLOPLIFDUbHcADOBqb33t3FwovVw5tGCwQz5\n1WM033yVkR+aFxK26gfpOAPIHPvjfdnm9j/uTsogPaoUA9JsuQiJCLT6ZEed\nwfG8gqt5jhnH9tNrklVjYhvRE/AN10e4t+gPNM0FNwSxbzqZ736YL4dBVz45\nenSNN7+SG0N0/IqoDRtOY+kZ23Z1YvHFob3MmaZPD0YlnGQW0Gx2anxjNtz9\nfpMhVIh1/MhLyU8FJbqRFaPBGokdGQWEACxmiBfgEdKnlMBCeittRAtgPpF8\nOQakVggEpEeLxU2k20PpDrXS559fMcNJoni2r2ks+Ns8TJ/d7wX6pYgclQpO\nOfiXS0rYhqZtNpXsNGmd2uQhiZIocZQ2Q+B8NwMcx8tNOhfAdKpKTysH5d+Y\njCyCUJRGcThrJGECpx8RYRz7bxOBi/LIh88NBoHdw4DxQysYEMpqwEqnSIxO\nMkCnTfUdJCl2DXJJ4qaqn9fsSQUMg8B9ZgdMgYngZ+Eg3zdr79djuebhOgsd\nHyzCcVtws44VLfiyK/k0yrUhy3pH3ZauerB5yceSX65IhMVw81RG8aCB1CGj\n90+G\r\n=lk/K\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQC/ReGaaDR4UHoV3yt9/RisqW3E/SUAlwdCO67AOVkPJgIhAMCJ5j9ckosHYuYduvi+QoWa9BeR1Ij01zmzaCISFn+G"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.66cfac0.0_1563304021187_0.1905336315576176"},"_hasShrinkwrap":false},"0.0.0-canary.403f456.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.403f456.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.403f456.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.403f456.0","fusion-test-utils":"0.0.0-canary.403f456.0","fusion-tokens":"0.0.0-canary.403f456.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.403f456.0","fusion-tokens":"0.0.0-canary.403f456.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.403f456.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.403f456.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-4aDBtvxJHrS4YWJEUpecvoifTs4DzbuHt4KjtNgpavohH4joztW7+wCAg5Gl2TOG8YFUuANu6vZsKARmB9Wr8Q==","shasum":"86d0fc773818dddaeaf27f24769339ef1b4c35ff","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.403f456.0.tgz","fileCount":18,"unpackedSize":32737,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdLnHUCRA9TVsSAnZWagAAHw0QAJasY81iB+WYiGwZ6y/7\n5mA9PNGLFC2c2e8bZUSF7+fuNT1eJ0LUyau2deSBnprucHI4XJGip+AFEvpR\n55F9latQGjgH0SFS5eJ4Zbzh4JwPdqdregacNgGeByqzw/OhTKLlljdmvVi8\nG7Xryxn4HzfRTTCQ3vqea5ynu791Z5xLGc+aedCRmx9fbVvOguaQm31F2A7J\n2xB8yM/0hSNCk8G8Aeqp12LUfDT5M1R/hWdng8vsocUNHkdjjoCEMI6LJ+B3\naaAb6jIFFeqBIGv6rWfeTvq6LbGXYvFu77XrDbKI9KDr8i+8tuj5oc/xUxRI\nIYxcF3EGurpYzeHveh9cBx6C4Kof12VTsrEorEOj1kvMzR/uglxYYJ3HUPkU\n+ik1nutBcTW38yaxcDrQ9BiKnOp/vicRQlnGXCIWrRwTKd4cT7BQmRZjqjO4\nfDkWQQsUUR+D1Doo25gwEWUG6lwZuQ7jy0pBdc7anaBlrWIPgsM/nAoLqvM8\nJCP+AmABCiIy9fx84PojDm1ZoFYKnNB1U7A89sh5EOJGNJDaf67JrPJdslFo\nfKa++6lgmpa7kiDei+ehwWarXShV/vV7f8k/YV1xA0NmlZ+SZX/2DTlrw20M\nqcyA32dV8txA9Ip9AozRb4cJ4QdZaS41vZr9AN2BSHAUJOmXNsgy97TPnwrB\nAdmj\r\n=OriP\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIGwwWjObrIhjS0rfPF02uCaxig3vwk1nua8R0N6c4hsfAiBWXuqbkgDowjx7zDnjiHcqN+bT9p0wv67Ib0Humynsdg=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.403f456.0_1563324883541_0.38785046840826043"},"_hasShrinkwrap":false},"0.0.0-canary.ec8188c.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.ec8188c.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.ec8188c.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.ec8188c.0","fusion-test-utils":"0.0.0-canary.ec8188c.0","fusion-tokens":"0.0.0-canary.ec8188c.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.ec8188c.0","fusion-tokens":"0.0.0-canary.ec8188c.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.ec8188c.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.ec8188c.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-YmQ0XTFc4cpweCYZtHEgRQyTi3kPXLVs+T0ImtS+undIFPlbl8NiDjYFHH0rGk5j/SNFScaGAZ+t9JlKtmgMoQ==","shasum":"ef505cfb281cce5436a2faf386ad0decb635d94f","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.ec8188c.0.tgz","fileCount":18,"unpackedSize":32737,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdL0SoCRA9TVsSAnZWagAAnwEP/2ZdpbaztH77pZKZVBG8\nURarJ0PccFqelpnaNU5dQgAAotF5tKHJU4+PoG1du5ZxvsEuv6fqd+7AVM08\nuuzIERumyu0eyV0J05w3gEiNpYV2Z6Cgis0Ti+3NS4BX2WnGULb+TByYDMet\nNf856hqvWNTAZ4ZmcIOu+g/lltvRUHssTPokvN0ilr63MPR51Jt39lfte1Mu\nXHrrj4RPlL0AF7ioiSlocxpCL9kv6FFSFQXa5aBgHmVx5rL5ATc0jxFM618F\nu+hQQNukD0+l7LtZYF5CBvuoSET7yzWPt7jW5M/IrrK7sR/gcKvNtwLbPvkM\nRi2qeygABq9oWs/62Q1BLFoBScpTq1dmFFnOVuQNVud1TDemKno1ZQeT/UD4\nM8+/RNT5wgy+IyEG5Y5ADpw8HxbBmBHlMnJpfZbwmrqy5M4bBAjzOblIaJaI\n39K+T3F9z7bNjazD2A8ba8pz2zU/aCE9xS5knMkVjW3I21M/jFBbIGjWZd6G\nPOyHRDrHQ136R0DlFABPODwCbzeY3nPBa07rShi+FdtJ4F2t+l9Q0UHdnrBJ\n7xVn2QY4lFh4kLDt9LHUxabX9bK/26TXTStgAWChhiJ7aiL4Lt7BuwDullcE\nERzht99BvbOzt4G/j1IgmUrJ+NHFR9dBW7BZi6hAW7IBerMTK+wmDZC0YeGz\ncMKr\r\n=g4vL\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDgPCAngUd7699UWzvWWl27wOslDtJCiXwQ4zm8jTmdMQIhAO7/w2d01603ALmnzkjy3uOQfTxeKZe30vdWwZcZDfpz"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.ec8188c.0_1563378855584_0.4088771543808334"},"_hasShrinkwrap":false},"0.0.0-canary.e9f07ef.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.e9f07ef.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.e9f07ef.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.e9f07ef.0","fusion-test-utils":"0.0.0-canary.e9f07ef.0","fusion-tokens":"0.0.0-canary.e9f07ef.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.e9f07ef.0","fusion-tokens":"0.0.0-canary.e9f07ef.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.e9f07ef.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.e9f07ef.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-Bw174I96At3ExdwU/1FxgcLS8h5m3RDa0MoOc+JYqXfflG6SCty53G94xDCLlr1LaQq/uFvHqRlapnNyGDN7iA==","shasum":"57b2d42a61f1db8280015c9902e81f88f81add4a","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.e9f07ef.0.tgz","fileCount":18,"unpackedSize":32853,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdNerHCRA9TVsSAnZWagAAhO0P/1gxpBICE8u0dNT/CPtn\nVBGjeVOyNxiX6KBiOtCFHsDtIq3E9v8UPDKdKixplCoV4QALq6mrRbiLfzrW\nxzaXMRBHxowHlPlwvfCF8+01UmTTXq1WN9WqGXVxwfvo9exALdRu9iG8V9Ie\nXITc6Ig4yoOtjYzTlbrlmFlaPIDIrgJ+BO4j8L8OVV5XQG47YuRegaxk9i3t\nY+fxWY/RFmpktS1CWdZAduTCUunVnakcxlt65kpEYTqJtdy4YroECJngaFeq\nntcZklsvmwNGzT/GV2wTGJ1U+C7CceykO/LslruELbSWxOIujUkVtAlz/FWf\nuheeurdRK/ivQn4JyNxsO3DDv37Dw57Q23lVMBNpdrPIi0ROxouUW1LUqOJF\ngseiDlZ1tQhxVjOx7YyqM1f7k2lJ6rK0H1lbH3p+8X7U3yiWhgBfOSd10NkM\nGl0JoTaUHZ5jdHvMGduzFg/d92sEKnhEp8eCzlWQNK5JV3fdTzPRn3mv2WBV\njhReaoSCuAnyqchEmVcp19lDByQvcTOXOWwGBPdu7zwxH79bWR5/bNbI7qnT\nO1u2eA58KBC0PjS1FNJqd/ogfoEkE+MYLt6z0mS9BBgEd09GfkoLZrlElpK1\nMqvY6bYPgk2lTJEWp9xRfXzlTmYgZr8DoETOKcky4u2G5pNo+mLHp+9LU+Ga\nCnpm\r\n=hgil\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCZgJAA5e3m35IrQJ9yw1baU3J2icLkqANNrRAO6wXG5AIgQt+/6M6fsBFONGgLgPjKHWLkDmYOcKcff/TMimlR/Bg="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.e9f07ef.0_1563814598501_0.6006252143455222"},"_hasShrinkwrap":false},"0.0.0-canary.fc2bf62.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.fc2bf62.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.fc2bf62.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.fc2bf62.0","fusion-test-utils":"0.0.0-canary.fc2bf62.0","fusion-tokens":"0.0.0-canary.fc2bf62.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.fc2bf62.0","fusion-tokens":"0.0.0-canary.fc2bf62.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.fc2bf62.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.fc2bf62.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-lf3VMUSBSQQJ4bHRAeqZH2PVQ8YK8dY658FjSRNywyll+KwlUWptOZT0uFjrGatUsUtHiZp2QQbjlD8Y8mDTig==","shasum":"20ee96bd21ca1eb053c53762186972adf7a1fd4c","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.fc2bf62.0.tgz","fileCount":18,"unpackedSize":32853,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdNhgICRA9TVsSAnZWagAAkCIP/AkaYYLC/VoKe0z3JROG\n+PeVHW6AYGMlCO9RIvi60LOC4vivrlaa3ZoKOBkNYiOtA9kxuTgN+ZMS93cl\nU7Rb9j1J/h9oRjc3bNCZoVUJZyCkiAlaEGnMzhh9QMd5lbRJN9nREQps/McD\nD7g9DlaloyWCqVeL73TLxSPYBGlZYjRMVmjJS4DwanG6YXook83EW2gDyCqh\nYaRsRr2c1sj76xZVZ0neu8+2yC519HL7/BSJQHEFThSorDIZuYhP2pFPD5QT\nnTMVcFRdOdYCXpPVdRdzd64Up/1MKzJ+Ipe8guu88/A2IzNpvtQ9rxsv3H9G\n7rCBD4/vINEzfvYXwqN28N9yKuB/xE2JLPkN/8FwhWpO3ReNerWQBA/i5fu8\n1P2zHw/BUUAp57Mmt5cQuWLRVJ7FuVRRaDldwOgSQ3SJml3a/xjaBAVwhBs9\nWvL2P3nNnPxyHGzNUkBoQidhPwB03AClL980/ud/axrVgACaaB4th/6jyDgB\nMnqCUgGHrofG0Z6j82D2J5XuQJxL9UbcJLbguCbNoMXkJCIUL0YjtxhgX+07\noLKRYobRYaj81+BsG1dUttsve5PNKL8V9cauplxZXB2gYNTq+EwXcf+XKaq+\nDuxu+T/6JZoRKbVPvBn9dWp5ZD7pRlPt/evU60+1gcGjOvH9LyBkNBIEymot\nWvWo\r\n=ZECt\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCICp7G16IimHzicOFItK3admI+ObH2tbl2tb+HJAOgYe6AiEA3yYLBYhgKsMyBpuPof4GyhWVyVcGFywX1tqb+Jf6aKU="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.fc2bf62.0_1563826184392_0.15157227321318434"},"_hasShrinkwrap":false},"0.0.0-canary.a8de467.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.a8de467.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.a8de467.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.a8de467.0","fusion-test-utils":"0.0.0-canary.a8de467.0","fusion-tokens":"0.0.0-canary.a8de467.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.a8de467.0","fusion-tokens":"0.0.0-canary.a8de467.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.a8de467.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.a8de467.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-Vlf57LUvpxcU00/LUelU2HILoLjqmSeVoytpv7wJrkaH7zHFvBvuWn8LJRD2Uot+fvQvl+8P7dBKaJKckeb92Q==","shasum":"bdf88bbbfeb2ff9522e53ba116c2d85b855d54e4","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.a8de467.0.tgz","fileCount":18,"unpackedSize":32853,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdNjS/CRA9TVsSAnZWagAA+VwP/3qjrGinW5HwXHLylqqy\n482lRmwdBMtY1xKr/rmNK3fFqoNIvJfvHz/Og1H0x9cxOphDF07jO8UFBifg\nkjW3N0Ro6JoQqU/oWaJ756DnpqmjLl+RUKiCm37Au9VpxQLahfk+Mw2ZYvt9\nmXx8UjWiBiJkChC19VwgjZCss9TR4RaA4HhoJprpUtpZmYEgfMinbo8ap4Qj\nOb22wwdez2e3F3GxTOTxo4kSjxYWeIS04KCxgCR+b+PXvj3Z56gbkcHxjmKQ\nyABs7obx0Ora+NQnwn5olpUR8RPIWz2JSls9Y3uo8OFmI0mO6xCmMf2BRjz6\nfKR0y60Sx4GXaPhbouUIfGWnT2ZwYj+A0cqDUv/BQ75oaKgrrlHkznqJRpKy\nWs4bEmsJtcAKpr4EEinL2uNyDrxZoULOdGdr/v12hTic5ABaFxNXRoltWlNW\nmoC1eNneT+vzEJ8Yj+BMTzmqu6oCgbvVGebfKfF+r0VKT0nMwxPdVHKhUnmL\nq5ZnhsNueuQ3lXU+F5vWFthR/cNZWBSyy0hggYGtwjB9ue+lUiHTiNkcc54A\nyFwVdYYR3xYfrqbeVbmd5VVzVw50TBCaGhXOH8c2TxAtzc8TCDpUviE7O/1R\numFuFHkhy0g1BZnGNK2UgMQ86UAanLVF+WMnmqCX5awYlmqNVyXckwiFVRCA\nhtdh\r\n=Xg84\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCAFvOygjj05S73L0bm/itDwL9/totDU3Sddrk31Z8tnwIhAMzlZCdhEgN3MX7mbNpaCZMYvnzPRbbE0654v4XuRADM"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.a8de467.0_1563833534765_0.24885619438737794"},"_hasShrinkwrap":false},"0.0.0-canary.a8de467.1":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.a8de467.1","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.a8de467.1","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.a8de467.1","fusion-test-utils":"0.0.0-canary.a8de467.1","fusion-tokens":"0.0.0-canary.a8de467.1","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.a8de467.1","fusion-tokens":"0.0.0-canary.a8de467.1"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.a8de467.1.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.a8de467.1","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-nW2y4GZ4RHu59me28KBy3jtpQLXV6aK3bdQggvVlQZHdgtB0arRSUVUYBIg6i0flmd6lza/3youEXMKd9XeJdw==","shasum":"c98af4acb3dab28345386675c26db15d3d99c78a","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.a8de467.1.tgz","fileCount":18,"unpackedSize":32853,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdNjYnCRA9TVsSAnZWagAAzI8P/30/MSjD2XlQjB452kkD\n2YQBdoakvvRRJAeI+rLnXMyUljdU6BThlZi0PQ6/ZF3jyKQemyZnydXjqMNs\nmcWADC3ImQwcFslV+9kWdt2wLGqyhp6INDV+NnfjtSvP8dz5z7cyVde3wKIT\nnyPqPNv9fmCQ6i9VlQ0Fq6+ZNUykaBT7YaRX8KobZiPZq1TQQ4+R+gEnJey/\nESIFyqt4ECWy3/GaGQ2JEHZ9NQa/Pl6SkDsNBG0ZVrfcaC+7T8mVeTuPD234\noL2iJoA8quqW9GFUFAV2+aWi7wZ7gMMSw/17Cu2ckWG58V4uje5zdgjktIS+\nCJTGfCMtyU2PHJ5FqxVjSz8XQAA8i/x7rscjOVehy39vRZkOPtdAK26v8lU0\n8wStVWHOuACipgolMHHs8feGk1ainPh1jrsGz69p50KlivaXtbsoDziT5Ol7\nln6BmwX96J9qyfmgKbXwTaNq8NwCoFN6sFhju3+xmn/C9My2XWMZBFmrzPQd\njv/2HCUZoD8oco5wKYKWoHLOR0oXysYptIXaUV20UrtUJ3T6p9cmiwh6xWUW\n12+02zUlu2TYenpjYSuWBbEs4MsePbk7+NxwuuyQUJoEihYWYLB4VLffofio\ngDjPWXrGqXGweBg5QWRcZhD9ORGFV3uaII+/pfBw6mcADxvVNvwtHcmGcDSF\nWXxG\r\n=SOky\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDIsXPt4sVEXF0J6zevG21PyrPT3x5kLHBGp41KZ5kVtgIhAI4ARvOKzyu+umOm9O0oQ00ExLl+KSLsw01W0p+Sg17F"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.a8de467.1_1563833894441_0.8189499777565883"},"_hasShrinkwrap":false},"0.0.0-canary.02195f4.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.02195f4.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.02195f4.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.02195f4.0","fusion-test-utils":"0.0.0-canary.02195f4.0","fusion-tokens":"0.0.0-canary.02195f4.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.02195f4.0","fusion-tokens":"0.0.0-canary.02195f4.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.02195f4.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.02195f4.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-spPJpBmG9etkNlFrFLdgtRaSwK/FZNoNTkcOcJWAE24+wz30SqtpPeeFMbMOzLKINbBRgIAm4aalZc1mJchTjA==","shasum":"101ee124c9535f7462986f6428851860599858a1","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.02195f4.0.tgz","fileCount":18,"unpackedSize":32853,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdNnxUCRA9TVsSAnZWagAAFr8P+QGP2B3TQ2PEs56Xt71V\njWXJEAMRmTEKjsxMj7XkzPuu+Uv92dF60h3d5ABhe3S9PHwQVMwsKpcmKyuX\nO0QAONjvcVx45xZO+piFcYXvY7wbSXKMyQwEH92jqP5H57fw16GjQtDbx5kn\nIuu+ebwYEG1X8FH+3G+ThFYX2khW1nvSRApSCJAVJjhbUIHClBDKJN/D5QFs\n+Q0xsZY+650RUbDV/suIeJHM4MDVNx2cPJ+A+ygeMKpZedJZvleo74B+Z2TT\nckvILwIyOqRguJ76p7gBE3nUAsGqtxO5z/c/knfFu3ylOhBaZ2lyTyCGR5aZ\n2l3T5oeZbL4KrO6zzKICd/gLQ7xETtJCE6CNwNfHC4DP/AVJTedUHu+1sSR9\nCfqXbhmyACKBVdVwqtbPHMSa5U2/1kCxzR/YhF/d41+Nt56BVtXoRJhd4mNB\nvK9eTK9C08ZgbXkmHps/h65Fh4xGo7osSAEVJmpBYhSHPxWyunbv+8kWjq05\nk6Osjxe5T+ZiAOpzlHp+UfFklrkCO4155+4GU6jXD71afNoqEXZGh7cIvJp+\nGKaZku7v/+C19eCAgfzvYPB1KDkhsNn33sYFYG+NVMVu5A8aS9o7p29WY1Mi\ngbwijl3fQdMUu5Mh/ZS01PXTMEM/yO8i7ffBUhpK6W2Kz5SX2s+u0Jp5+Cc9\nb+a5\r\n=Nygl\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDPAM989tBSe/uJ6WSdvPdKVCg0KjKHdtwN/OYhX7STkAIgR8maObnBj7P6Az2i3rXUl6i+7FmLw0Gcs57bPifB/74="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.02195f4.0_1563851859428_0.46026257316174446"},"_hasShrinkwrap":false},"0.0.0-canary.da2cfec.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.da2cfec.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.da2cfec.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.da2cfec.0","fusion-test-utils":"0.0.0-canary.da2cfec.0","fusion-tokens":"0.0.0-canary.da2cfec.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.da2cfec.0","fusion-tokens":"0.0.0-canary.da2cfec.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.da2cfec.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.da2cfec.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-Fwh2gGP3uUFrfbG3C1YLb9iMBO/XE7vbDCqF8ZTxKph6zw4Y7r7gD29IH1islCYRHYcn4RqSZDp0kHBIub2ydw==","shasum":"41fc74b77e4608a4295eaa0a349dbaa0bcc70ea1","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.da2cfec.0.tgz","fileCount":18,"unpackedSize":32853,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdNzcyCRA9TVsSAnZWagAAzr8P/3VNojHxphhoich6unhW\nmg2VC/Ylni0H3nKM1zbJNPyTScyf/kHqIaynTTjlxYyeO/CWNa3yOKDsETeF\nCpPKuk30R6l7HPCE0Dg3JlcJDAWQJU9B9tl1jC1cKtf1XLD5hqHgbigpFXRr\nGfRfX4NiNbvW9OpBwAbHM21d3TE0FaEUyXzxOPytoUmcDPbGHnTAJuQihTp8\n6usp47N8rbsID1j2GvaTklo/SW64+YLUEWihZfsv/3QYyWujhurNdA4HD/Ii\naC2wP4HSbwdC7Zx8FJ145FpGE1tcWbs40cEtnJzXJis68cpcpgWEcsopqeKX\nXK3A3DHzYSMH7fqBM7cnTHWtr6SB/g+ulss0lwWzx6T8iQNc5DSZeCLr526+\nyBbtTbk6513e+15L4qvcYE85vS0/tOf/l6fOspGVps7aGMZBR9IlXV/Wq7A1\nhIVQdTE1Dpw1ANJkTOdoLFkbSsUGNnXcJP35NipnHI0GzXmEv1Mj4eO0q/UU\nEAC86pWLiq5LmWMAvkSMFiw5AIT21/q/vSKO5YEXzmbNLt9pqHwunCuXzJ+J\n+/ZdHmx+jZS5/lds/fcRlmp28LQMn+A33l/vCQeC/6nYTgiUym5bh1Wv28qS\nsiLe76RRmtTBzovLt0o/w2V/qjbR2itmMl1ZUHfOiSy7Z3QPn/wi6sgmXps9\nSNbS\r\n=tmAX\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCt3KBOq+pszN+PoTVVaX4o0S1Deje/YF8cb2s9hUhm4gIhAN3/XcbpotAnTzDkR64tOpbef3fEpHhYhopq2TT3zcSe"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.da2cfec.0_1563899698274_0.7279393621251571"},"_hasShrinkwrap":false},"0.0.0-canary.14b4f0e.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.14b4f0e.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.14b4f0e.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.14b4f0e.0","fusion-test-utils":"0.0.0-canary.14b4f0e.0","fusion-tokens":"0.0.0-canary.14b4f0e.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.14b4f0e.0","fusion-tokens":"0.0.0-canary.14b4f0e.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.14b4f0e.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.14b4f0e.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-aagR2Jy+/MEt5M+LvqCOXaLYD8HMJDfUfPZ6QRAvKgzNwXdTUs7J1CCrVRyMlD4CBi5UnzcGH0+h06loasgdTg==","shasum":"204e7fe604b82fb1ae366e8a55553d25f341479b","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.14b4f0e.0.tgz","fileCount":18,"unpackedSize":32853,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdN0YZCRA9TVsSAnZWagAASg0P/3o0xDd+7+EpQ4zS961/\nZtN+FMu1Fsq+aSfDKvBxMkVCKYCE6TyDnK3iHCWl9O4uxj7SEprLZFtHJXwS\nTpr0GcJH7PZdPlyQKQgnTCu7i/AtcFKYEnwBKlxGg7byWpXwAGh1Kdrjmq2v\nggInt6ph3jFkNOOf/ZKM162xf8Lu8oBhHPovKBmD3K06FzMpkUmR6rK2UBe4\nMoChDdl5yqGPh6afpHmMiFm9SGgdxe1tGEqygTEp+zYlrHK4fEnGGj1TCMDL\nvFYXcAeBMITZKR6HbjofgB/upS0HdKjqJEmCqLDALY0l2KQ/YvX3OI1R5RVr\nEY9/DONkD3PQfflUJtDI7BXbGnBEKknPYfcfbFy90bZRlH4FdLTLqFhxxwXl\n9fQoIgB6KM7aUKXijfrKqyZRTYCGZmWTp/N3zon00y72pJN6STG7PrlyRrek\nPnxWCFqCDFksh9R4GhyVnwiUHvVV1kNAQBrLAkqMBBjJFz+oXDNEzyZYp5zu\nnqvSnCv0L7wVpP/8hKaG8UxDBsL0xOfklDrGpxBef3iz3o1p6bMrq0gcSUVX\ntVNd5bLQNi/G25BPFXpYFUuWPLDCAEAALjr3H5IwvufDeJbNsmhOP5/w3kR2\nCY6bcKf2FFj23j3I46/7wW2kCYOsc5udNhCuEFz/SoJkj5txmleCRnlHkqMk\nkGK5\r\n=dAun\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQC8jkjzMM9ZuVTA8b+BFuWfAg/dU2Ky17b0doyPU3aSugIhAP+ks8hfGdyaBnON2ozIotTYBk3+yIRKyGksKUdmmJ8i"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.14b4f0e.0_1563903512991_0.7822796275034942"},"_hasShrinkwrap":false},"0.0.0-canary.0953f07.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.0953f07.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.0953f07.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.0953f07.0","fusion-test-utils":"0.0.0-canary.0953f07.0","fusion-tokens":"0.0.0-canary.0953f07.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.0953f07.0","fusion-tokens":"0.0.0-canary.0953f07.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.0953f07.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.0953f07.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-99SmKc4tFfE5/Bqik/Yacw0aNc3JrSzjrqs3hjIXMEhaPjlwp0D0ATc7554ewsA7Rtwpy42MiFgqEXeKqsFmmA==","shasum":"8928a589d4c15cc806334196e4014f95ebbe5324","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.0953f07.0.tgz","fileCount":18,"unpackedSize":32737,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdN4EmCRA9TVsSAnZWagAAt+YP/1z8cJh8mvM0fWBkiLwq\njR/wZ0PXj1nUxnHiKIjQfLb2sb3WdY9NPAb2zS+9NyBqC2kM7C2maR88jglz\nBFoj8X2yS6c+sQOyB1x+32Z3+158j57NjnbJs4lix1wGzyYsB7emXCy68p46\nwqDL55+9GI7TzisVMBreP/GAEBMtnERYTAP3CUhjhBQnFGwPv2hsDBvlWjMs\nxUyfVqHy+zgYyUroRBXB6PLDa62fh8e6Z68VDhfG69lk5aWLAUnsGDRJWdg9\ncgAwYmUdpt/YVh4n51p+a4c78bp16p40NUG6sKJLxqM40qm+boulTo6gZ9v5\njibDqdB7LjajWx+LVqrGXRNolMACqH8VNMY/s1Klwtv+c0c8REgwceDbXNyU\n6Thv0axrXEQwMgaxuVwxaKXh4tZg1vWuk7XZgUdi19oYWVX+zlkdk3dzY57e\nQHFU2QAt2inhXG9iyca1fYg8LJNbKQEey5+CIAmQ/kf60ZEydoDVUdz4R3sT\nt2aNrGg7kOuodsxL9e/k39GDGbXbg0ZOlx1c4MW22b1H4PPyUzfP0XU/iErn\njYJ4d1mJ/NPlEVJUF4mfUe8GFmEebKXXXzQau0HrpBEIkmByoscO55JQk8yV\nX83HFzEHEcEK1p8O23jJiCzoi+JAT4l859STnRvuWDl2lnM0GQhOGufK4TZA\nAaBQ\r\n=J9Px\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIDvhikPg8YJRcWGRZpwaQWWLuaNldWOZe6PK4Gy2pIXpAiEAiknCyezZqhtAB7cKouyF7izhQ59ZJ1K0dIfWSKxsr3M="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.0953f07.0_1563918629273_0.6170442519234611"},"_hasShrinkwrap":false},"0.0.0-canary.471a10b.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.471a10b.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.471a10b.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.471a10b.0","fusion-test-utils":"0.0.0-canary.471a10b.0","fusion-tokens":"0.0.0-canary.471a10b.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.471a10b.0","fusion-tokens":"0.0.0-canary.471a10b.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.471a10b.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.471a10b.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-IqGMuHcYGHThRFW/55mphVdY3hBhw00hZ2mUjaB+Xi5syqhAutpqJIbSetdHFjr3abxZWYF01Qwhy1ZILgIRMA==","shasum":"df98946b13372bd6df4e26cf8910f34f32cb5cfb","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.471a10b.0.tgz","fileCount":18,"unpackedSize":32877,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdOJHBCRA9TVsSAnZWagAA3hEP/i/PYbepqe07mG6+ZCF+\n2dJiseoQFV31MtSwiBw6woMTa6HrZ608t0+edQWKJhhx626wLbzSjGQW0Wjz\nwWORCogv6vdD8vRyN/2ycZe0ZLjpBNxlpuMB9PyihW5eZdjbPkTJCCoDN2Io\nF2zk+jy6UWzqnJplXQ6edCOnYczVobEV1M0PeI2CHjabYj9vuIn0GIFQaRoY\nXts/jqHeFDeWUwRBRi6kXr3bC0UUVPNLXYW+Q3TRYbCNiy3KW2ptu1hxDgnm\nfXRsKQHSxRncTQ/1PTW5Yw9RR3NOMkNGOFesNBFrcRSQGNXdnmI1UqpM1VWr\nEOItl1ZMfENIiY7UcNwqzklYbOLwVXqJa28tnTXjJaIlBjs/vP8Tl1nd62Y3\n+oUi8j4bJvhVMUhTM3c9zCdMO0faiuNO7568u8eNcqH8Breu419ZoT+LZqV6\ngNgZJ8nG1C30tKjkFMv6vZaPlUor/Z7Cxx8xZM4LMFVgsR+muJ8fz/wsnPch\ni/+p9hTuwyvv7WExf9I4LMbyfKMW57ZDvA8hqMr0AIhMD5BTdRDyNdeKeDyo\nKFiHoTgzCCg3saN1UOhOHjc0AnMsPw2jb6SO4mNqZ8ebcKqL+788+PiIjIDm\nC700FNgzGgPkR0GZUm9vlpyQKbYDAJIbCgl77SNB9ZqdFd5zoEkfA/kSma1t\ny5lA\r\n=+Dmk\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIBA7bbuF/Xi+78rU87NOBgswGnkOwtgkQl5H9mviCOq8AiBGz2LPRaoOI27CYpF63qfqNnyj/6OrDu4D99G1sVpgeA=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.471a10b.0_1563988416634_0.7129010163899296"},"_hasShrinkwrap":false},"0.0.0-canary.9dc742c.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.9dc742c.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.9dc742c.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.9dc742c.0","fusion-test-utils":"0.0.0-canary.9dc742c.0","fusion-tokens":"0.0.0-canary.9dc742c.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.9dc742c.0","fusion-tokens":"0.0.0-canary.9dc742c.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.9dc742c.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.9dc742c.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-Qhd0u/+PltcELky1bLRVF9bVqf7duV0SeLJA7IBH3Klf2/aLO9slUIOOym19QOwGgRB/Tx2qsQGEJqrTMlLgMg==","shasum":"255bbf23e3420e1151e30e99f85f56a17f12eaa0","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.9dc742c.0.tgz","fileCount":18,"unpackedSize":32877,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdOJHKCRA9TVsSAnZWagAA1h4P/ik8B6GZ0C/0CEXs6+mq\nJolTBpK94Tsz61JbC5cPrliVcXtQF9GgSukM5+InxYa51pP6lGydXwkvI2JL\noS68XrC8xTZ8qt1Sdu4oosG7ilwxrOZ8A3Cg+07eebquzBECrbUvlk/VqY4Q\nuYNPwiAm0rszFinN+SG1gBsxTdr+qxhTeYdSqZu+AusvC9oJ8XP1JGHv5zQf\nYlCOQjsWFKEej5AqZbCPih0Wz9YVDywqiGSpgcl7+yneJPoOtbbdKBhRmCOd\n8858jOPggyN/u+w/O1FWOZ3+EDAr+Xjc2ThLJ6QpvZFySMjDRH0pziWD1pBC\nJjE0DA0lnwBVDf+BpCX9BlyUdstx+iyidl0F23VnuhC7w8RdY8b7S7BtsdP+\n33l7IDfYI2TMWTvgjMf9HndgGvW7lXTp8rQ5g8ylzdcMtaboVHKRrao2p1iH\nAHIccAcBsEEhJJjmb//DtpI/wL8kWxPjkOkFmizLnJ0qOXEno/oN91DWGKj9\n46mMu6ULiPp3WgLsCrN6aKm1NnpEUVzzWG4PQgk+U45NOlGRN2hHeDXlD+rq\nnFirEfA7sOIm8hN4vmRSCPFHa0PUrkjv+75jo5+Kkl06W5RXSFz2vjSxfv6C\n5rPePKWkdy/tLW5A9NDmitIHLIVVVsfXRcmcz54Hm/Cj26YJ4rV6CluggjBZ\n9ezV\r\n=haP7\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCRgI8lH3D/cVWESA227rkwcN1RCmjXMumqjy8vS9xOXgIhAK/FjUDuronme/TChzrEsxcFgQD6DaMe3re9JcVGuS1P"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.9dc742c.0_1563988426134_0.6326682297845696"},"_hasShrinkwrap":false},"0.0.0-canary.fbc7ca5.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.fbc7ca5.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.fbc7ca5.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.fbc7ca5.0","fusion-test-utils":"0.0.0-canary.fbc7ca5.0","fusion-tokens":"0.0.0-canary.fbc7ca5.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.fbc7ca5.0","fusion-tokens":"0.0.0-canary.fbc7ca5.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.fbc7ca5.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.fbc7ca5.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-KB8JwVEBeiMAYQWxCkqtrLDe5PtybXilXsZHFqTSRhcKkL7OlFCW8Nqmmls9Rers0Ppvjf5vk/xosKKAZcvpGQ==","shasum":"2a28aac935a97b83824939cfe1f359b857b0e58e","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.fbc7ca5.0.tgz","fileCount":18,"unpackedSize":32877,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdONHaCRA9TVsSAnZWagAALYAP/1gemurZn0HG3VqoDZw2\n1rsrI174UgyZQJ43Fw7mQPqmxvulPScbizRTrq6QOW0OKm/JyE9JyryafmbU\nKAtzf0NDU87cEpV0NkT5undapfhPmo4Pxr+nGtcXD9PmbzRm0gNO779+ZnwW\nNHZGU8jaEmvtCrzcD3uhTVvnhRSzgnzxAP5sgMmpj+Dj1KBV5uVJG5fOS36D\nk0hnC4tdDmJwa5hWMIXqHNd2zmRlcS4A2WncGUqYh9ttjPN5FStLuF/izX8j\nW+w47gfTH/bdA0K+rtuOlWfSjspV9l/pr/C4aycjbL0IPz/8AeB5qAH/3lTm\nVoTfNgd+kebPzfSrVK2fkDCb6v33UdrcT8jKIGFa6iLEUmZ88Q961IdARJ1A\nbmnO2klUT96VtbVJ9I49c7+N2pawd8sKJz9JCGNL9MzxUwnAXlk82XEi1F8j\na850UPHd7rxFdfTsDNgpt/ZX6952dDcvJxssR14FpVxzj+3FHJQPL1TSNSgy\nrIwnFCyJH5g+AUSO1E5h6cR+TYHtos2Jr+tD1qk81brCAfQDGvx4Bq1izqkx\nVntIeHzsTqMJoiQ+pGB7Wmmj7LGrJ8rrRvafGBVgXhJhPUm36R3NtosCj1nG\nmdbXNP250DVW4J5thCKiZw0+3lk8m4fGWZoeTDP9YpuvPCyNJL2rhs1rAPSj\noyWI\r\n=Y+JW\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIFkR4GoI8EsS9QoIkW2n9ccKzQcsflLtr3aYK5jzt/E0AiA1pCsSvaoCiLjVNVDgtCrdP8Aet3YFCLvUuM8oM6r2Kg=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.fbc7ca5.0_1564004825827_0.24906301312195755"},"_hasShrinkwrap":false},"0.0.0-canary.08790d0.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.08790d0.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.08790d0.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.08790d0.0","fusion-test-utils":"0.0.0-canary.08790d0.0","fusion-tokens":"0.0.0-canary.08790d0.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.08790d0.0","fusion-tokens":"0.0.0-canary.08790d0.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.08790d0.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.08790d0.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-YgLoystyv5gz2sjwTrlDumqqj3Kr3XUT5IB/oNJNCm5ODOvwZkEm2FVrYjzEISDPJGRAu33bxDqop2aqFzMWVw==","shasum":"7d314cbddd78553f344e68f3eebc31c38e1ddf6e","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.08790d0.0.tgz","fileCount":18,"unpackedSize":32853,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdOOI9CRA9TVsSAnZWagAAsOwP/2VZuWcVXWoLS8OU3TPp\nj15PsUBQCPK8mf5jhpODfzp6/rdor79OIJZ67QmKp3DSTgT1UJYJdLwiH9Uz\n9X/Zm0NSSTNhXU2xjVzF0E34TnCE89sQwujphzBdJZB1rxCge+kM52gpAMOm\nX5BDFhcMJSjRwRUXprlA2iNtqnQMhgCxxz6TEzyCCIdLp0iZXs2nAMIyHtLM\nUfPZg/NKMCKN44Jqg7dQSK/6bDmEs/ZlQf4a+RIV+Ma09B1Gy8ipilF8gClW\nyfJ26EgUVJCSs4qIHeboJuoJ8Bdsu9HUyEnnOhDw5vEmp6GNP6T1Nlrp3kVi\nQ6g56n1A5fm7j9GNkir52YBYbCwKyHM+G2v3t0ZFbVSXnjYl2WmotQFeoTHw\nTCQdOmWX3M9hY0SBSMYPrh0pYLG6yMAqu1GjxeVFdwWGMP1KvovGdRI0rMde\ntNeFo7GG/Nfe2R7UeneiXzl/jY0kfOK8nm3m37HbTq4Wj10TkkMFjpWhhQ0k\n7yrxCVyfrZuw7dHANOsccl2Gp7t7adaX4TfRCktjKd2x/QXklV5kmHB3BKEX\nr8KyHD9JcfY2sj2o0d2zeIBcMfkm/E3z8OhVdchlwAz8DeH1dnbMYWEVWPZN\nY9nIoMwuiQREXs/gUQmplQa9u/sb5hxdc5w7lomMYvFN6uQ2EUBGVkod4Oym\n2mwK\r\n=xTF1\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDV25vKWqO9crmIYWI/87zbcQddbNSbZQduIPMCGjEi/gIhAK5uf8qGQjQXJFS0EsEkok2qY9PKSZWU8DU3BUO+4k85"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.08790d0.0_1564009021214_0.9768747956246142"},"_hasShrinkwrap":false},"0.0.0-canary.17cfc1d.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.17cfc1d.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.17cfc1d.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.17cfc1d.0","fusion-test-utils":"0.0.0-canary.17cfc1d.0","fusion-tokens":"0.0.0-canary.17cfc1d.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.17cfc1d.0","fusion-tokens":"0.0.0-canary.17cfc1d.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.17cfc1d.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.17cfc1d.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-dH2Cm1L+cojHB9y+AotOp5/+KWf0/6iS8iKmjrDcE64gMyZTFpOG2oaWSoiU3YAbGIcXbrd8pgNRirwg26cGOQ==","shasum":"d3a6a5e61ff14efdc38b56f9ec84c2aff79b3da1","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.17cfc1d.0.tgz","fileCount":18,"unpackedSize":32877,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdOOJ9CRA9TVsSAnZWagAAgsQP/1d7cCbISmRdMC4/IxoZ\n3f5CzqwBVsiFJc+qLu073ikjLMSaWsgUpwP97daezGBjtxG76jL9ONhfOXWy\nd0szCmi6rDR5etaCWOCQAIju9abZHkq49A1QxDDyyErKcK+37N8UvetmuTql\ntESgU8D4hHVhAl0SKj8YuDNIGrFF5CyfWunw9Tpa8cjb2WjgNEZmQEdktwYs\n1PuSidq5G4IgN5Wl4qTEWSJdmldKXAQBHXq7jPcKNzEypb19Lj+2myetAfy0\n9LvQxPN9Hy/e775JxolFCbGn/0f0A5q0RHxSKkRU+X2ezko0RHOqlt4PZyzl\nwM6elEtz1UvWitGjscqjGqcij8lzEw0JCZF7lWFxgAvxxpx/IH7UqWEKmaEi\nnK1sbrgAwvLPlbySADTic5VrmYNARJY93AkQmIol12on6peuSvwK2QL/5HL3\nmma90Qjvozd/e4Ag1WRhld1yj4p9TJxyrFgPUBGrV+gO0/MNJve2whM58Krw\nArxH+55zcN9WjwWztxjvfr7J2rKB/1Nhv7gH6xzR9L/YGLIeDFvJTOu0lBDZ\ngfoXyByp5ARgI10QWve7DubShqEeFsQ8mUUc0jcee/U/7OfXbNXaAB8bDmZA\nv8BfLZUskIwiZAYeRAZxl4UDxddv1m8RnLzFl7/dZWEEKzRY0cBs6xVknIMi\nHfkC\r\n=i20F\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIEF6Vc2j9JceZQBp3ZF7qpu/g8ZbLmwnhk2TPd70n1hWAiAiin0mGl0VxmzFvgAzrwWsUp5PxRSIQYZaITAgSKrppA=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.17cfc1d.0_1564009084710_0.8339550769908108"},"_hasShrinkwrap":false},"0.0.0-canary.d0e4cd8.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.d0e4cd8.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.d0e4cd8.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.d0e4cd8.0","fusion-test-utils":"0.0.0-canary.d0e4cd8.0","fusion-tokens":"0.0.0-canary.d0e4cd8.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.d0e4cd8.0","fusion-tokens":"0.0.0-canary.d0e4cd8.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.d0e4cd8.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.d0e4cd8.0","_nodeVersion":"10.15.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-i7vB/5nfECJi5FU+VFbZ84G9MmvZtQZMW9t+6YeCvNELHmhTJh/bfhyeyMTTRzNu7+SlNDbE/QU4pgCHy5tlhQ==","shasum":"61178a2ca489ac51da6bea537ea5989eac78fb1a","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.d0e4cd8.0.tgz","fileCount":18,"unpackedSize":32877,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdOOKqCRA9TVsSAnZWagAA32sP/i3weC0xjrbMZVQveiPr\nyQXVW42jdYD4BTIj6743U5SAXKlbYbAxhu+cmdIQfz37fyQ3Lb1Z/5vtcz4B\nvk9bQVqHsZddIkA8AbIl1p/UlHtZPFPAGxsBlAl1tB/1MM9/quaWl41fYr9a\nRQlIVHz1Did2Fs7Wswf7igjtYHrMZ/HADcIY/cDXW6Q5yiuWBLiMopXNcpZQ\nVWMvslNvt5ainURJ/iQOfmQteRGQHMx4HqFeDBTzQh4ypQwvzKd6qabIoo64\n54X8YLM9CWc1QlGas5vZoOwxHuEO5PLWaLcsnNYhOMPouJdYcXHErV8H6lLi\nDng4swveUYiREhg57CKLbQfFKLkFDSBYKexJTFjVVkFNDfKziG2Av4oH1NtH\n1BmV4Ssihq807kneSgZs0wK698ALBpSHpe+0KVp9YF6+MzouuGd1DvD7PDKp\nbl67ZCjDFbfllTShyHVhFrW8ILbHYy9RHfXWAjg2+dCqFltLStO3UbECyE5c\n7lTrf/Nq8mM9/dAJVBLmgrIBdKur05N4OVOS0DFPpgdeqe4tiYrPVevcFix7\nGiDSdl3aXa9l0pajrfk2XB5Sbjdxp4Z+cUca96TLPhhBu9mL0eb2qx+ksc8N\nKPq0mRHmxtG2nRvSVb8LboY6wViQ1azNMVm5/yJphIVMKchjhkl+rZxa/pU+\n+QB0\r\n=T3TM\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCICNfzOPf/HmtSdnABICgnswCmTgS50MHwjjFyQeH+xLOAiEA1dd6T+myFQZr49WDXmXAAE/JhggfV8vYJt4g52qDsY4="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.d0e4cd8.0_1564009129849_0.12749647474457615"},"_hasShrinkwrap":false},"0.0.0-canary.6499178.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.6499178.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.6499178.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.6499178.0","fusion-test-utils":"0.0.0-canary.6499178.0","fusion-tokens":"0.0.0-canary.6499178.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.6499178.0","fusion-tokens":"0.0.0-canary.6499178.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.6499178.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.6499178.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-VCyeAHpUvjjZLbw0RzvFX8dP/eX4q3KlyUiv5e65P93gD9DpPD51NmGxS/0Le2q6AZ14Y7YAbgQ5EO0U3C4O7g==","shasum":"6f36dc24eab87ede3fd92a9055a51433ebbde082","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.6499178.0.tgz","fileCount":18,"unpackedSize":32877,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdOQAhCRA9TVsSAnZWagAA42IP/0YgxoUWPm3jyRjl7/+E\n8CkvPkdhCaBieIouza4+61bp6cdwKim7mo6AQs6CcpbaH4TRISC1u1xuZRqs\nMwXAenNiwdHsLJB7DcyGd5h/mKyeQoIPUFjFaE5iH8ZfYp5+Nu7WMChtV4BA\nxQypg5BfK8ytoB+NJPoVu/mlXNgfwkLzo6v/7ZOF9XhDlI1tUrg6Mvwf+Txr\ntCPcA9cK6UgLbvJAQ9KcnRoN8tZVJm6O8cMJQGmt25VbyOGUEvPNZXSsv9yY\nzXHDi3/XFuTk4ESN3zXj5BDp99feJWq6+1MREnNCp6lFNHA7UgcHxACkMDs9\ngR9T3m5Q9EZT2CXqVpNpzNqyR3Mae89GqWBjWITGrOfa4v+z6bLfk6oEKug8\nhieiECEUAplvo+yPXgy2qTx3xcEmgHdTQYkxW0KTeQyBa1i9i5ljhaMYdkz3\n6xPzOHN9iXPrtBBTO7FatzN3gFDwXJXW7fcPICzu0s5+tphuXmvvmA393oJG\ntgT0XP/XKagmiyezsS/Qzykw899Ej8uEKNRyKBJtB0eNFwakHQKH0BLqqTkM\nVlekC4yxJRwmtRV3GiKWJjbEqiti9NknMQa4P2Xer0SaLeRT8c9Af5qDvPYr\nLG6ZvHInad4wY7FrE6xcEykDll7Q6CBZubMCT0pCBS85rZjkc+RsAazcxIso\n4DJm\r\n=wqn5\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCqKs1KFVlbwek5Q37VAq2jOQ4h1YXD6ifZAGZ5H4bpwQIgGj/GB3733oXLSQAiNmJgdA9eK+M8E+hDnRz3H5lyjY4="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.6499178.0_1564016673102_0.8790825934091699"},"_hasShrinkwrap":false},"0.0.0-canary.47d3251.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.47d3251.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.47d3251.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.47d3251.0","fusion-test-utils":"0.0.0-canary.47d3251.0","fusion-tokens":"0.0.0-canary.47d3251.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.47d3251.0","fusion-tokens":"0.0.0-canary.47d3251.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.47d3251.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.47d3251.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-U7vCekr6jyB209GYfW9OEVGDbYx5dm0jBLf5EZ09xDCNSEkvtbd7xl/G1qS1KwSiI78RLzSeh1P+xoQriquPuQ==","shasum":"8d6ff174ac75ba006402f92326581ce18c754e67","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.47d3251.0.tgz","fileCount":18,"unpackedSize":32877,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdOUdgCRA9TVsSAnZWagAA2A4P/jnebQkWY1evCjw2/JmL\nci3ok45obBrCRS+oPdm2CjdtDwB5VSPupFBv/GfgMi6XfD0c0QB72MAnzzHj\n+/zrv7TJLab7ciU3RtEFLg6Z8Yz/TvJZovZjvr27VBES3YU9Fbx5XTmCEOAE\njREy7QjNmzWBwoslO0PDHQYinNhYfRjC6JP/cJi/FMa/1B+5SEtCih+FY5km\nGvuV8GZmDepTl/niWYin6UWkepvdf0VgGCnte9vDricDJ7TEGUvVAgWVk8tC\nsEkZmNRR+4OjN+yG5D4gFnpZLn61+cMM3Nv42/+usNcxRuTyFneMZQLtvm+L\nH+o2MiOXJW49b8wqnxEH7ubQNpfil54766GVBjTiqTOWFr7SiekRDSFxq6Lv\nRSs5FjwozyOynp2fwMvaR8/mLJ5jPSALEetKEdmrkwOkPm9fu3K5UgVgmSEO\nfnxfe21BsKZKCdtd9sezyqFJSCL1KPkfiTAW1621va05LXA+WZcMTRdcjnFs\nFPoYgD8Ko6FAL4GeHR96k8bQR8L21Nm4ONFHSKoHu5HiEDjQiZgdkA/q0MTd\nKNv1Hj4ZYXIquYETyUoAnPwkcnYeJocGBCb5TPktDwnJzZYVpFR6OH+HYZ41\n7yEUEC38iuP7i+ZbpSAmwnQNvZuueyhPVMgZu4KCtgtobwOiUhGcQ+NPNtDu\n661L\r\n=l2UG\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDPyYAtDz2SLyugE2CjWAPkZ6Jz16vMVHLWKkzQ0Cz7iAIhALzOh04VH32f6utr/BkZx/VLNyXsqGMLawLTTCD/8Cyq"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.47d3251.0_1564034911942_0.7720230559113606"},"_hasShrinkwrap":false},"0.0.0-canary.1b63aac.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.1b63aac.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.1b63aac.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.1b63aac.0","fusion-test-utils":"0.0.0-canary.1b63aac.0","fusion-tokens":"0.0.0-canary.1b63aac.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.1b63aac.0","fusion-tokens":"0.0.0-canary.1b63aac.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.1b63aac.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.1b63aac.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-bhWOfAQ0Y6/VfaTDZHF/Py9zexIOrIsP9TYmwKNsevIjLj6YmEKjvXpgGlAEAavtY8bwcUoBisY2+houneOOYw==","shasum":"6b2f5d3c040fc256283db44ac31ecd0581425156","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.1b63aac.0.tgz","fileCount":18,"unpackedSize":32761,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdOhIdCRA9TVsSAnZWagAARjUP/Aj4CAFvNYx33DT/nPkh\nNVhVWUObnZFFO1ZdsCCPbNp20I4zgHrHjhHF1ksD5lhYZEhtBjUKIab+d2TT\nmSzJEAmR5heC2XwlkBKIfD+YKw6XupvzV8hd7+5KEfY1deIYSpojbzF/vfVa\nXgKlSpv4UtXrEhhV3CxdPrE+qEuRh3xvQJKeM86VPJDfBp5UE4h3y0lauVmj\nnViJn6ndHUBaV+kO/L6sHdxoT6izgR13/gykh8U801aT6krCwv2C+jEkKUgE\nrg0F1zRogqASOLRwzOJZdH5T7uC6ZrHPqScG5sPqhpXsgvO0VIgYbKfobmBe\npS1Oih34pVnyBdeYC30QeRee14bJZPvIuPROCbkyA1aSBQPt9lVhHoUjRAEA\nqqGO2kCN6xW//JNlDjytoW46ueKba4iusSAJ+LAfZ6gX/ZaUi3HxMD7WedhE\nz1KcMLctmwRWG0BblV2SOqE5HjO7wkcZo+SCcj2A9WIprLfXikSkcinzIKl1\nleTnIM1oUGU+GgBaMNrRxQO3c98gJsGRNPWeEEP3/dBbws03tpGjn2+5NSWK\nS173/uq7cpKMf58sRr4+j1LVeqkD+suRTG1X3bvZ7mAGj9HmNUoLgfM37NXN\n6SFH61arM//GAFV740hunJrqq7Nrsl2kQ0CAPdYBd1X9iopHGGpSreFk/fYU\ntNWA\r\n=aKRX\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIGdk0PjpiJwSnNrKEWQeCtz6QDeqe9nQmd//TOMUc58cAiAwXMRwGfr1SocXEu51Rr78KPaGhhuz2Ml0GH7liTjbLw=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.1b63aac.0_1564086812534_0.5176557977345979"},"_hasShrinkwrap":false},"0.0.0-canary.675492e.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.675492e.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.675492e.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.675492e.0","fusion-test-utils":"0.0.0-canary.675492e.0","fusion-tokens":"0.0.0-canary.675492e.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.675492e.0","fusion-tokens":"0.0.0-canary.675492e.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.675492e.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.675492e.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-C1j8nrzb/5RFihi0eGBjrv6BoCiPMgsgUTF8E1tYksj4o4QHVTznW+4Tn+TJ7G3oOQrOn9r4+YIizLypw31oQQ==","shasum":"d7cd27b0dfc14c7e7cb40eaeaeeaa0a7082cf5ed","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.675492e.0.tgz","fileCount":18,"unpackedSize":32761,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdOjDMCRA9TVsSAnZWagAAPwMP/ihWSBSyialHCIURyWPV\n7zastwLjA5ZPaRpzCh/rP83OQaxZRO6DeQS5n0sAsLN+uonn7UlEtAmfjhoW\nkppLW+hiXxgQWGE8cdH4Gz7C3SO+pQ2XQceX3wAyYtzMBM3CsLKoWG+i/rkf\naOQX6FOfWiMHFTeOTnw+e9iggGHuyMFdcAYmI7zu2DDdRDN7nQ8X2CYwOzoJ\nrlMWmOresOpW1x3bpVoN1ONnC/VunYHa+LpimE3kyAjUwIoeQ8yj+DcEc0w4\nPGW39xSFjcd5Cx2OR856xWg+X3uuXlHdWXfVErbnyBCoftLl4S5422vWzv7Z\niELxTyPniI7UIIxa+BgbbxoJ04IMvVD1vBeDpGyJSYJnEEMshVQIUH7cXKwb\nIMq+AxMzbKLl/1tVfFMHDNzwlgqOxnEirrjnWTz+gZr4cXN2IY4cOeLnDFJV\ntTTIsshp3u8iKGLGWRshH5Bo4ydw758sKyYt2jZ6edM3MQHh56Ux9dKByWHR\ngZIZ+xui5h/EOZq+XzrkSL0b+HUIf4kRp8nBvrvlyJ+Qu3bPjDu8wzQPcxpN\nX/T2LShT/3+xxW4QPlLGvZUODn6FKDgaQo8HDbW/4pnX0x/6FuUopd/Bi4KZ\nvCLQIio3s9ZhuLwU/wVn6fugKe85rfUXUkg3dxOoPDscGm3v9wkEw7G4GsKQ\nO/pC\r\n=Elsi\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIHfEQop8Ou+3t5VyFe8wA40vKBirmWFhRhOlUX5llDb1AiAEJ98Q47+nQprJro2RHlD0jYyHCtUksbcD+Rq7tWQMAQ=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.675492e.0_1564094667866_0.47000574335859735"},"_hasShrinkwrap":false},"0.0.0-canary.a8af54e.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.a8af54e.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.a8af54e.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.a8af54e.0","fusion-test-utils":"0.0.0-canary.a8af54e.0","fusion-tokens":"0.0.0-canary.a8af54e.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.a8af54e.0","fusion-tokens":"0.0.0-canary.a8af54e.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.a8af54e.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.a8af54e.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-W/erXBVn0u7NfUAUY4YvbndXiKTIWfTrRk/GqzIYBn1u2lQbcRv5JghFfpHTt85mC35+YAbfZGQ5x3YKCEq4Vg==","shasum":"7f045f11b9e309fac9953b109a582bfadf044f97","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.a8af54e.0.tgz","fileCount":18,"unpackedSize":32761,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdOm6/CRA9TVsSAnZWagAArLYP/0nMW+YtZMzAEqJXVNiR\ndJ2KoggJU6zwbFwMSm194fKr5/Z1EABgW8zgA3Qp5ueZNNrQBKWb2jd9WC6t\nkrCzQTc5F5WhcguoDY0BK8UJM1K2ZgzfXl+C8/i5eGgDNB9KSEZBB0yzgDhY\nmFa021SNrx7tnStPZiskQy68nLyyckpyffPTh9xU1lj10nwnJ41nxKLuQ/g6\nLLANdxiW46r6HDQXwqNb9DCDigsv1yaYtA748wqKgIiYi6N1h8zHretibVsu\nma+c9k7IwIkXCNuZ2BzebKwoGKkdtPiW2g+HrbZBNBl2W6H6L8l5IVGoNseR\nei55/rHGW8cYYK4lpC5kdiGMaAvr0wwGpRZFZdg8+w3E27/bs07tTftt8wHc\n/Zih81yyHsSANdC9V1jI7kfJ5zn0iQkGdERWv6fitHkeGlPRNHt0KOb+Eeas\nfEVvHa1OLyE6wT2dYGuZL2Evi8lPstJO+kNjRU/I46HHTr7lvxdp2Mt9sBmA\nour7M/CY9JHRI5YxXWqDRqA9X3/sdUYhQBmBAjxPqpyASVuen0xjxoA9wH3I\nkcP8oK/ZEB+EYePLkS5WC7ABYCm4Io0sJliD2ZaY8wS5ZcOPCHRfXPy5Blh9\ngTbJEIA57+jV7DfOKNw8IBYIvAlDEI2Ii1joTJh8pJXV8BCT7bWbm/hwKx9s\nnDJ/\r\n=GDsV\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIEQbj+MmtC7SZnqk5Klw6iV0WdN8FJO/5sV+MxdLuugEAiEA7zbYQLcGMko66KB8wMA/StzGuwQ2txjm6u1FOq545Y8="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.a8af54e.0_1564110526372_0.11996888617480872"},"_hasShrinkwrap":false},"0.0.0-canary.4a47f03.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.4a47f03.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.4a47f03.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.4a47f03.0","fusion-test-utils":"0.0.0-canary.4a47f03.0","fusion-tokens":"0.0.0-canary.4a47f03.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.4a47f03.0","fusion-tokens":"0.0.0-canary.4a47f03.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.4a47f03.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.4a47f03.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-uY5jvNmHQBCbXgC+ASgE5lsHLmF1W0ClmaeTN+ze/KWhjq68mJwiD1ToM/3gPIF2VyO/hD8GSu2YYgX05FCfBw==","shasum":"5fcdc924bf445fdc680ecc097635eb7dedfa3405","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.4a47f03.0.tgz","fileCount":18,"unpackedSize":32761,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdO0m5CRA9TVsSAnZWagAAaOkQAJC5Un4fO/onIwYVbrQU\nIXMRGKfQyaBxPUQltzJOUxBaUSsRcpd2Eu6rQYjhXZDXptN7shrzw32KD9uj\nrnHUTrLztr8SMHzJIezEYPpzG+N9uVn4fNt65S/jf98Ullg7AWFHPdlA1nKP\nXmEuYVW1p12RG+BHvTdyL+5vl7zwtbt/IXwmcOG2hjMdrvMLcJb7SJWO2s22\nVtfmjPPY1MDBOGkKhzyr1vzf1HBjhJwcAjfVznCQgjYyi2y03Ur45ygJ7tTo\ntcyHD9d6pbPz1mmLIgmQvPKQG2yhRVoEewsuRgRE6tg1tb8KKZoZ1HUSPfBY\nX8jZw1o3gIs0rFEgWG5c8BY/qaYCyRz5iVuBSUobv9OQtOUh+LunGl6unpIR\nxJ1sOIvy7CgsITk/sp2/rsNtLPqtO49db98qTSSdI+5g9KBbX01hwe0SH53f\nVnoaNNXY6ssxjTLyeoas8jW4lLsxsp056x5cCsDf39VFwnTD7FqDi+utkYhw\nK/y1RZdQCOCLal4BN0rwjooyVCc9XtzDU7dFHdmmbKOXD1vHAdz5RWKiNCnP\nJ00hZwwquagrfhkYznJs8hpOogwQWtyCeEx1LA/wYv4hQBN7JYrm11fN+YcG\nD7OzFdcdgosfD1MFrcwucBmLZ2L+xhN3qoeAyWbPRVhze9Pw0pl0C+22b6Os\niiF5\r\n=hoL3\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCywc//JmIWN+w8FdDjR72LTQGrdOy2QcBpHYH+N6SMewIhAOEAQvB3veDHqqy28uFHk9U+1QhWLCZSfT6YkUh8DltH"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.4a47f03.0_1564166584784_0.8739795200478182"},"_hasShrinkwrap":false},"0.0.0-canary.88403d8.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.88403d8.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.88403d8.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.88403d8.0","fusion-test-utils":"0.0.0-canary.88403d8.0","fusion-tokens":"0.0.0-canary.88403d8.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.88403d8.0","fusion-tokens":"0.0.0-canary.88403d8.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.88403d8.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.88403d8.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-vMzr8PhAOxA6PCEnE4E4Olm2SnCvXHEpTjThvSCb41+AEdDFenVpYmZlWSKYsseeb2l6NiYhn6uKLbw+Pkwkhg==","shasum":"7f2e74b1a8ab341d4e6b7d0746c424eff17bdf59","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.88403d8.0.tgz","fileCount":18,"unpackedSize":32761,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdQNlaCRA9TVsSAnZWagAAHTcQAIuhY36Kbfn0h7xtAecV\nf1I7lcGfjT3VlzQoeJ8/hRk16RjGcJB3IOxfLCfgKmO+LN6D2JcqEUm5Bz2t\nFRIrBRRL8lL9Eyn7rtm+jJs1F2WW18cRJmmgyf/AJBnL7KpmJPxxiVLbXuDy\ntgAG1T5NQYvSb5v0VwyqekF2y8pBVTLKDGiDFeEvCRCIBJGIvG2ugOXZSe5B\ndtNLgjnt7eCXVBqIoivOKAjMMyGruS7Bfm0oiee6cSS86NDE0dMWdIaj5Dex\nEXt5NfQPYDTrwqgWSUbusnY37NW2cRWpKr84GsQw84JWtzbl5KSr3hYh1BqC\nAA1kyS6N/myqalC4RryJX5x/Uh3A8XXUgfzA141XjVJn9F9mql+SHjP2hQEe\nkXC+H6BmU3xHG78KDiTdiTwIDHU8Tsa9QO8sS77bNljqbjZCC5oip8FdkIXh\nOb2Rm6YXlQQpbjtauLO5WWqwW1VupHEElapIoR4xuAOzzCjNiq07OyhkX/3J\nELmLvNcvrJoKXuBFlFOc9OUhlcb0y+2EllrzYnhlRLH6fHiiW5koSIbMITQM\nrW2emOxS/eZ3GYCcJt15E4QSAFZ3ksJydgVyNUOMeOCKdpvJ4zyDQSSab0Gz\nKJIjkn80Krbr662VtQMCRzLlEMHQiGBt5x8OJ4lGKLLdiWexo4ektkqqTqNz\n7n3O\r\n=ai5U\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIE4c9UbUF1mDgixZTTbWTOhYnIhtdgxYpLESRCJUGS7tAiBIxTMnpHMSNB3mfoo+UYp8kYoE1wdziaE3LUSUL73kMw=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.88403d8.0_1564531033980_0.1841561747631848"},"_hasShrinkwrap":false},"0.0.0-canary.96b08c1.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.96b08c1.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.96b08c1.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.96b08c1.0","fusion-test-utils":"0.0.0-canary.96b08c1.0","fusion-tokens":"0.0.0-canary.96b08c1.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.96b08c1.0","fusion-tokens":"0.0.0-canary.96b08c1.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.96b08c1.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.96b08c1.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-Z6FycG3Spit6mgDmscOdPFFFyAwiTaM1BcEtD6y3ME4lB+oWrC0sOIk/ZKGKfSyeUTgo41OVl1axFdscIgAhXg==","shasum":"9907429491152fd0be77a54afd284e09fccafd7d","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.96b08c1.0.tgz","fileCount":18,"unpackedSize":32761,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdQfxCCRA9TVsSAnZWagAAPoAQAJoco43nvScM/ZPpmzOO\n2+YWzBEi7pytPca/v2hD3lFrPr4g7h+k8lHqMUjAzHFENYddsee2wjkPj4pg\noiIwZm0jpp9LeX21td42d2Uix94ujLMK49Pl56b/dGk/PX3VUWNroHkCakUs\nE2nTK1TJOn8giGYztF8nuf2S9nnGTkOI9yyLgCvS/ZMmixldGty/dQ/VYXq1\n/aFOiFkfQ5XGkRLGQ0dv7owUwwYPF47ToV2zjoiM9EoWTvpXA5Sq/YRRVcfA\naa6fDT6zP500SaDh46+u6C3veRPJXN8PCVOyR7vTnmqRUuNuzDi/swb3MRQ0\n1+roeIHZxsLthf9DnsKxCTc15nQIhqKFbfy2f+QfLsyYh9Oactno4xxR0EBE\nm7p7QbATi2jf02V6Xse6qjRqHsaHpftU1Fn8abaIOa/2F05RXB2NliCtK/lT\nbL32zqDPJak8YmDYl+X+Rpfk7P3Ihjsid2B/xa7/vJluxZnDr5eeFimXT7tq\nv6YXy5nqyygdWrhtCsKimmLX7zV/Q6MiwMVDjP7FWvlBaRqr1K+h8x3T7WdE\nvvxtJ/AlH53GFeGLN6jdueXXa15sfVNb3npb1y5D9uK37iQDbgL3BtfySzWW\nsTy5HTR8Xa2x49oL6MWxkKtgKpDbp8ol0dEGhtEwEt43afu0g7G72O36L+Xc\n8HoX\r\n=sj4l\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDSu5ppLoWTpW6xgZ32bEqkg5P9pJudg0ciw0RiTOtGfgIgcxzkAnAYPZede0lH2LC77N4gQoVoRFQG1zSaOraILho="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.96b08c1.0_1564605505770_0.5362304619295752"},"_hasShrinkwrap":false},"0.0.0-canary.631e52a.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.631e52a.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.631e52a.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.631e52a.0","fusion-test-utils":"0.0.0-canary.631e52a.0","fusion-tokens":"0.0.0-canary.631e52a.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.631e52a.0","fusion-tokens":"0.0.0-canary.631e52a.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.631e52a.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.631e52a.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-GWdLg6lh/NHkgbvfXbQiq8K+eQJcUZubIn4Vr9a/SB/JfmeitWwm/CcGg+Y75R1VE2M8IYbJYYRmba7gYZXJmA==","shasum":"ad05486d917b1738361510864642274d28096ad2","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.631e52a.0.tgz","fileCount":18,"unpackedSize":32761,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdQw9XCRA9TVsSAnZWagAAl2gQAIBIr3bap6bjY0fgiBnb\nEW4/sGujtkkmtitJZYdbBNoKUXxqa9NQE0vvRTzPm3bKBcns5MDNtUtt8zAe\nTuDwt+iY5+/x1P5gmvgvJexZhOxOfoRLktLMYJhQEsXO4S0JjAaPfSaxGpUE\n6Se4D1o3nNQytpqBHHceg6q71FYP+Np7akFPE1FiQg7XuJ2VjcgbUsunM0gJ\nxpEZStWwWcg6HWHV4TEj/iBL70C00OmHWWfJrPzwfRBaqBoAbXeO6KLcoXzC\nEPW5ruLbSVhTQKq+eEVFUvEo/DY0PZM9dGnzPSD3wMLwpr53hz83iCZmdqlU\n/1Izsi1lsphsTFtmhN2F32niTO38j35sn6GHKiScE0OuHQ7s+N4fcJASLJEp\niUDuCBvdaGhD08MW9YYF42lLqYKCtNOdDeee1o1QSv/nvcj9tWbibCL40zlM\nUr/QlRkN90kRrNVkbvxbUJhhQ4mRCsa/u/p33+1IUahEeVUTBHN/gpe1hSQb\n7SnxnIDE031Tvl6vPY4wsVGeI54eOqWSkR2YxtFF5OwipIn7chToWnDQjaIF\nqZlHsb3c+AM32OrVsv9NzJnS0wac5E9Q7ZI+3wYVDwvTZIhm64Sff+CIhcQ0\n4x1cjh7h7efn2F8+OX3hcLZlhzP4z51e1U6rjaPtQuKkFsYCI5UChKYkVf+H\n7gA7\r\n=NCBW\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDiyNtK25QBy3maAYxapuEcYI3DPb5MPG9HOTNW+obHaQIgAmGcOwpAw9KsoR8G5F8XZ9GVsHVq7Z+75COASu8LljQ="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.631e52a.0_1564675927120_0.994249933269945"},"_hasShrinkwrap":false},"3.0.3":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"3.0.3","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"6.0.2","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"2.0.3","fusion-test-utils":"2.0.3","fusion-tokens":"2.0.3","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"2.0.3","fusion-tokens":"2.0.3"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-3.0.3.tgz","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@3.0.3","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-sTjo7lc66bWYDyvb53l5BsrcEJgzMoPlmlfUtMJQ4GBF9CQCDGJy7Sz9glAI5nQhh8HRGUHcsFJ4D/r1oVsnqQ==","shasum":"26f7d7ef2d77132f4c8ae098292ab1dec95d3b5b","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-3.0.3.tgz","fileCount":18,"unpackedSize":32642,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdQymDCRA9TVsSAnZWagAA3esP/0zBEt37+IuplNdEFp3e\nnugzQXzXNVLp6Xcr0rc8LpTUGQ+9zKzngFlseWtVoWSevBs5+2bPx9ruPSpu\n9kgqBeF+bM+6FLuptVC1Pj5dy7fE0dUUKvABFeGUDd1IJKxtKkhCHmcxS6lU\nFOZOS5qpvgv3W9lsYz/XxmUJtAFNqTRO1nG80929rZyUlIr7/AOIbhr1fG2/\nWG/7b+GIAQYh6dkdqB1mIIifAkQdzO+ofwe5/NKDWKj3LDT/NNWR7jcxSq3K\nW2kLvMCiy/1Y0c3Fbfa50D3z4qrhIjQeVwoxw8RA4Zhn+zmGFfMQ9BdqvpsX\nh1a3lDJc2FootX92PzLpMpBNdEHLopUWmq99rlYDz3nyZynTrx09B4UeXCFE\npjKV6LPiMVVoQ8losvJuqsJ/bS2OeVsfUIT/qVxbzZ4Y4509zB0BJ5NtJsKA\nYsfP8Lq6D4FuMFQyy2yLpyl3l1mvL8TIllCmqimgFYBYhseWEQE1M14SGV97\nw8CC4VruZlG3bHfZ5Y/dlTy9v1T1gpv5fCvL1zYjBF+vmGjjaMM5oa/nH4Kr\nt+Id6yEdhdS92VM1W06NXHrqR0JaylaDu952bW1H2d7r+yrRQKVAUEviE3Z3\nPM3wfbMmoMil4RTaoNUwN1PC6jOtDZLvQ8qGAQSlw/86niVd5EZKI+htgX16\nEzz1\r\n=cVFI\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIGFo7Ub9NDdJ4FFCdxwlOKJjnT54S1hv7Jjs/iUulYsNAiEAhgPE0z0qZBQIumUwwDmAt44OiVzkLTwxIfjThbXMeIk="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_3.0.3_1564682626778_0.728262711883672"},"_hasShrinkwrap":false},"0.0.0-canary.bdd94ac.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.bdd94ac.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.bdd94ac.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.bdd94ac.0","fusion-test-utils":"0.0.0-canary.bdd94ac.0","fusion-tokens":"0.0.0-canary.bdd94ac.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.bdd94ac.0","fusion-tokens":"0.0.0-canary.bdd94ac.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.bdd94ac.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.bdd94ac.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-Hu/tNVld81Oc91JfdySFVU4OIAjlggoTF/EHsXdkX2XsMs+Ia4FVeYmBA2Yw7uH5qvVJQt29YDvrO/3CAmfUPQ==","shasum":"48f21d29c3b176fa02caf240a24106aec34327e8","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.bdd94ac.0.tgz","fileCount":18,"unpackedSize":32761,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdQzFXCRA9TVsSAnZWagAAVOoP/0SX98r5MQbsVubcyuUX\nme0v5dr6Lwchy9F6Pkd5mhYKqbZVvNxbntnT7CXGCWfvkBzdrd6fC5UUPuAJ\nvm7ZaKWrHQ1pF7AfYYdOhCOMqQIzHouu/7tIHzhUDNgj3JgL6iUTr3MwQRfR\nfTcOSHbuaq4T+KeYxiQu598rR7DyzwUGBwA3Ra/3mnBcRjOecRs6fZudS9Wv\n23bsMtphZmvT3hnTXPVex94mTdWfg6/5+sd9ldEBZAMCrssJtHNjbcblHYVv\nV1pVBhHgoJhKDrOhl/gFQDDPsjEYC88ABLIq6IuYgUDLN+d+QKCuvlC1dHer\ntXgmn6+Tju5Hf7rQNvESBD6NdEmbRonCOc7fpwwqJNianKH8lv8dkV2FobNW\n73aKFiOexN2U+nglhyLjzmeSqp5ZljpUrkR+v66FxMv+04PAHBSryZ02F9rB\n/uIDQXgNtL7GWU8uOnxDgeE9iOqVWmj+HdKJb9UYJxoWr1vLvwQCq66ci2jf\nZQlZOdqbw6kcuLSFHKwmMEKI/WCgdRJQkkqy/nsmvGjMiJqDZCu13GhQYwib\nBR7PuNwMASSmDyAf2YSV6cAN3365ALTShgqeZgZZ7OUaXGm1gCuVitlo/vRR\n7pQ5+cJV9zo0VS2dyEIk/x+9kemZ0/7BJ3t6SEjtzITKEvaQBb3i+gI7utwq\nfrtU\r\n=BHsC\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCOrIVF462WX2R9Tp80ufMbFWmMCydQaYiSyYA8XxiZiQIgDDPKS+XKLCbhuj/AYkJM+7Z0Bk6pRIvCqKNN7bAJBD0="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.bdd94ac.0_1564684630799_0.5562322354657447"},"_hasShrinkwrap":false},"0.0.0-canary.ca9c1e7.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.ca9c1e7.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"6.0.2","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.ca9c1e7.0","fusion-test-utils":"0.0.0-canary.ca9c1e7.0","fusion-tokens":"0.0.0-canary.ca9c1e7.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.ca9c1e7.0","fusion-tokens":"0.0.0-canary.ca9c1e7.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.ca9c1e7.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.ca9c1e7.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-oWGd5kzV1FvtE6k7iuBUaBfEUNTPk+GTXI0jfupusAqiLorJFSUTB4/jZACqYKEf0jDqNympkWMCENiC8DV/0g==","shasum":"08f53a09b4dbe75966effd1d63305a56d46c8295","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.ca9c1e7.0.tgz","fileCount":18,"unpackedSize":32860,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdRIpwCRA9TVsSAnZWagAAB+0P+wbJI6r5bHDcbjVvs41S\nrWYIxCpwKRMixhQ4YMN4cGEV+tSbMdRodgZx4ppT6fMta19YTpseW5SpiU5C\nntpQCwtuf9GOAv2wohlwiwdDzIb4hoTVegc7zAKj+9b29xrUs4J4Ur3BwZul\nxWcpVoUUgXCLCyDk4Pjf/veHHMl8V/ROmYUKAQd8Lfn04idAKLpP1W5dhHna\n/if4bSVCzmgLS4rdPujkkbOlu6Zrt1wYuSj+tshzLEYNiZDJAzppjoJqJaVn\n3R9/7I0nWLwNm7xkcnjhAq4yHyqJ4BvJQdEuAOzR6BcpkCH2Dlq6Bt9TZR7R\nLrVZ9kjzOaYr/jvZTVHibDZ2eKmsFpbaUJivkBqY53/+9Cq1rx+j7fr0MapY\n3hv5nIbGRGL16QLqLN0iGIJb+bg0kLhgCYCNxE+iOEDQfr5bRxi9A6TupJgx\nXG4dRG/BoiXgmXm5kMUeT4bOCtlYalgtCSOKLZ+6vyM+7ukPJfgsTdGjZxnL\nuv5PvHOEdzNjaYPEB+OzrH+HIUdN7l8xP56dw7PIu6a2vbaRJexVSOfu4Ixl\nhZgNCXbDsQk0l8iLSgE9y1dZ0QD57q5pONcmALU/3P/ROd84DMANqRXHRkMg\nGpeBt/8XDEltmIOXzSoQg5nfVYwrWkgXHITX8MRsyPIm3Acb+SVsNzA0rf8f\nzWvx\r\n=bjlx\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIAWEVvFnDe/AXA7KaGt3yMOi0P8zFOdWw6ik+QP2tx/3AiAQa6vC+EyeEUbs2LmS8XjZV8BGGUe2Ovolz3Odfync5g=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.ca9c1e7.0_1564772976001_0.15291494905659464"},"_hasShrinkwrap":false},"0.0.0-canary.36c6897.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.36c6897.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"6.0.2","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.36c6897.0","fusion-test-utils":"0.0.0-canary.36c6897.0","fusion-tokens":"0.0.0-canary.36c6897.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.36c6897.0","fusion-tokens":"0.0.0-canary.36c6897.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.36c6897.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.36c6897.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-yfATIxo4xZBj55mopOOe8iUcnEJhHGQXU5VE7ovsxQdtr5ztxo0WG2ci4N60JwatInnwIWL6O2W7SPxoQrQPcA==","shasum":"3d61b4d010dc4add8d2b68ebe6c6f48ffd80220e","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.36c6897.0.tgz","fileCount":18,"unpackedSize":32860,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdSI0qCRA9TVsSAnZWagAAmGAP/1menWJcMQGQED+dieCO\npFyHE38yyUhrdFpcqLO2mlEmnRicNFDUysraBmUkcUsTt7myZR2JMkJeBDp4\nmkfmbYsESzySAvGhAlKccwDMAWjn2LiIQHqkhaFwkqhfKE3zP2hEYVo/Mu/A\nvvlVHe8bFx42XLnR2Vj7B+ELX6LEFDYBPsRmhnq3b0s/gxmp8m7SKJPlqcam\n8e7x5rRZuRUxcniup9pwc2ZKaDwjAzUS20kOH2lPSaun5TqAqjDqaeCYdliO\nha1jwHqQcE/8BNQmiYtPqe3NaleopJZ3OR/GHT9n6E+7BBxWDi0ejfyq5+rH\nKrjM8x0pNjLMndkRovHkvQn0fTMYz2lHdlX3tIz1dzrRtURUZJx5PhK/Tn5A\nAg1py6UFNvN+M42pyvMiGBiu6EWm0BmELD2q3ll3Ltl2jrFWiV/KXXsyqO83\nL0z6JmbT5rDnsJNygR/aueWjx531fwO3Jk/MLBN5s5YRFDD9Zu2SYRoFy5Yn\nvoOUT9Zcab74ZNL26Km8hk8GHoEZqdNHr1exk7ceZfjaY16Yn7aq5yCFDp+V\n7F52DxQ1mqOZIYSv+CCQiFOc5yhsg+JENpZu9AQhaQrVh/gJNR3oeEPAh3P2\n27neP6wDot9TgPU8XhxhBMqfE6+9XzTsgIXtWCAKs7EA6pfBdZQWpEI3fh5C\nGvBE\r\n=daR+\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIBlkwGsm2C+GIW0/1TWUs1X1IW9NhWvVJfPXpN4Yf4SnAiEAqtHP4xZWjRrGodgnlvuxS0me9sCmaqwJw9KdJ5ODos8="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.36c6897.0_1565035817868_0.48760284241903973"},"_hasShrinkwrap":false},"0.0.0-canary.87693bb.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.87693bb.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"6.0.2","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.87693bb.0","fusion-test-utils":"0.0.0-canary.87693bb.0","fusion-tokens":"0.0.0-canary.87693bb.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.87693bb.0","fusion-tokens":"0.0.0-canary.87693bb.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.87693bb.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.87693bb.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-7zfXXE2UQ+rU7WjJTFAfAbDBEYtizdybZ7C538m4VVFtLk+zHD/rZsTIA1za17KMcw6EO4RWwtgzptwCHY9QIQ==","shasum":"26065c39a6719d407670c3aab3ef70c25fd869d6","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.87693bb.0.tgz","fileCount":18,"unpackedSize":32860,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdScAYCRA9TVsSAnZWagAAqs8P/jcVQ0obFQbbxDUTyY9P\nR4FSt40qCpuvucdLCeqfswq1mj/vm4r5dLYqdXTBX6rWWRyo0PvY6bdeYjzf\nZgtuLWLr0dJXcLvxl5HG77fGUma5LL/R5C41BRaxb41eCw/jEWhD0BznBWu+\n5QB+rNWeplimJD8XBujUhsw0wzIUeYVp3yusHjmUJfohfq9Ztc7Ro0WSSOz1\ntHn5zMhZVdFiB65797Tqc6aDwlvYJ+9T+mgPl8TrLVUXya+gBFxA1HvLnw9d\nP863dNLy95jIrS/3mKTJddIaANsyGpW3cFMWnifhZ4WmI0jpXOqUCBCL7zbB\nsYlhB+RI9CFGt6Gfsj0vkE4O6SLZZWvFXcSXWVNS8n6F8U4kqRftZLbjaN2W\nD3kbQlyTmLq2fV90zOYdoIE5ai0CtyzA9PKiFK0HzsXzlL9QAQA+ZiQCFDs6\nl1rk8vVmZqrSBCEYKvUEz6arr7IFJyFoCkkjJNMdVStgOuWcpCB5CiZohd96\ncBR0wxWoFMgdRkcP0QqaJDQpiUymqYRVS4dZ+ZRz9VZPYeICjzA9ehmSYYo/\nvJ88PWCGUH/a+zbURsw5/nDGW0iOVaMv2HlqofwD9hkgx3anVV1iYPqYdQyf\nxmmE8+DvmfI9tPE/8eRPTji6Je4cNtsdXqO8lIbqQNFaZifvIy+RE8foJwcR\nNLyW\r\n=OMNR\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCJUp/0zyyHokLo8TEz+qIlU/IZL+cFEW8ZYs70YcujxAIhAO20TXUbeLmQ8oD5HLO0IPO9anDGDeLqJyizhm+Oqbt5"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.87693bb.0_1565114392239_0.48318264265853217"},"_hasShrinkwrap":false},"0.0.0-canary.87693bb.1":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.87693bb.1","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"6.0.2","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.87693bb.1","fusion-test-utils":"0.0.0-canary.87693bb.1","fusion-tokens":"0.0.0-canary.87693bb.1","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.87693bb.1","fusion-tokens":"0.0.0-canary.87693bb.1"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.87693bb.1.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.87693bb.1","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-WspOlAGlp0HpqnEDa6+lm+yX0W4X5n3hoRznjGR5VAZvkhGqpRWB24fPBlKOW/Aqf/XRa8JVdNCXcvJDdatLPw==","shasum":"bd507647bfe3ed3684b20122fac27c03b8d57321","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.87693bb.1.tgz","fileCount":18,"unpackedSize":32860,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdScAyCRA9TVsSAnZWagAAM1EP/jTOyqqPy98bWmAkUrXI\nWf01eBbl/PdkU1A7tkVfXMlyq9q0dJIXzxNjYL3/EbTryGwYDsOEBdEsYZt3\nrpquyN/8hhzPiXMQZs/QIzZog7RqtAH52SkN9i9a/pj2NI95VT52+KgCCIbj\nrC/HsV1fkhcnwvjj+9vC881Q3ZFy9abWLHOUz6fmb0UMvE1UwTuemTZXRzlK\nv5iyY4b61H+G7QX1fBvZTVXJP5wD+59lA1MjTs2EsBtkTnOF4Lq1uXYgwYTv\nXuOi6TttrHyOl3lY0lIdznYukxd8D0S+ZiLeRO31xI1d5s2ky2VIjNFaZEDG\nn/9v+4pS1BzeWFeM3S4qx7OZcrZSnsvEif24W83WWWw++BVz/WaQjZAOmXDk\n1nuK0bmHqBJpBkT72mVOfsEgQjTleQzZdVRrRHbuVRiFegPPUIKS0qD4/lVN\nu+7t/38YZbPxPH07BbY6FEkBBG07o4xHCAJfp/0c24G1D2xB6g6XFzLws02i\n8rHwtQ4sWVClRllytEwigMX1GB0tl1SlIHnaHdy2Mtkh/TLGFfQoQhQZ4TZf\nEbzEcGJkrKgzw607YkTF7v46aywm3DqvvK7nLXpgfOjIkogLmJrZub+peVgn\n75peJOe4AoT9rXwLQGLd2MDvDl9PAid28waGDcl8VsDC93Jcr7QS8VVQ9hGN\nzMwi\r\n=mAnS\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDUzXcsNpzYOwK8nlsW23Je61/f04LiCbHwGt28X6Wf8gIhAMnrq7ZGmDNxwkFizFurtj4tAH59x0NXIaqvk+8mMrmR"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.87693bb.1_1565114417675_0.8519504927161152"},"_hasShrinkwrap":false},"0.0.0-canary.73b3b7a.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.73b3b7a.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"6.0.2","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.73b3b7a.0","fusion-test-utils":"0.0.0-canary.73b3b7a.0","fusion-tokens":"0.0.0-canary.73b3b7a.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.73b3b7a.0","fusion-tokens":"0.0.0-canary.73b3b7a.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.73b3b7a.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.73b3b7a.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-Deiq39k1k98MNm5fw05vS6hkAjhqhMLd+0dUrkhRMPExFTqDhB9jdMCcMQiMCvRtc5CU1oY5Z9lxZmYnS+WJag==","shasum":"0e50575bfd50835ad949f5d77e2c9d2ddeb8d8d5","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.73b3b7a.0.tgz","fileCount":18,"unpackedSize":32860,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdSexSCRA9TVsSAnZWagAAhxsP/irTtj1i0ASpXU/oRh1B\nZ2HBKBkdZJPVIJnUHBcu9GtI2kay6+S/UgNVarSJfkoNwBWJg2CvqrN1ix8Y\ncOqJV8p3pGI/4R5LoiOixp71FtL2SfRAN86GVWhUrDDdy5/ndicTiHQJcMWn\nwSlBAYxBp626oKyDIuze74A5haCnxOPM36xSwI9cCOiecHwPE0XGqOegOvPl\nFvi7tk8HB0LRRv/iAezVWuB1ELEPM60wpqrkYJ1DVgI8QlsvwOPcHuMFuaJ3\n8zWfLl6pEuK4OdFupHavHhz6HhPe5sq37WAP1yoIm/p/ZcattcynKU+uLO69\njRUw4FynvVtnbEvakVWZBhbos53z2R82fq+Z2o64yAWTzo01/cYqq0pnaq+r\n8G6fc9eA8V4InkNaZTjiwNMBXgX2oQXAVOpLaFJbz8Vvt/6+YsphyM/cjA1l\nSOFRAwf2eoyq0ROVB38Ewat2UzkbXTHhs7LCtMYwzc77QKrCYeCc/oCkAMih\nmRcj8H7F36Ikey/McUqUsjthEeEbhRO1iChs1TqiPHPQYD2B+lepLKl99T1Z\nKwdy52GOr9Qo7KbbCtWDCVz5zhYBLzsJnFESRAA1P9r3FTJIbwa2WkNbPj6Y\nEqG0EPAz2vubsGheHIZ87AJ/yohOOS2BVHoHbXS7n1W7d/FdjvfvUgTj8fDy\nXU5f\r\n=J/XK\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDMVovmNZH8VSGCF+cZexxS2sxBhqJwWGB3NtDv9maYjwIge6AHw2dogxRuSx9hZNxYPbK7ew8PW49lahcy2Hb+pHs="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.73b3b7a.0_1565125713880_0.24186879831197983"},"_hasShrinkwrap":false},"0.0.0-canary.3a6c203.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.3a6c203.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"6.0.2","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.3a6c203.0","fusion-test-utils":"0.0.0-canary.3a6c203.0","fusion-tokens":"0.0.0-canary.3a6c203.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.3a6c203.0","fusion-tokens":"0.0.0-canary.3a6c203.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.3a6c203.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.3a6c203.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-eGLOQqyno4z033Fqt/zmoX/lkJhLAClbWhe+Cy2W3yMRnthgJmvGVio49bEzKxua5Pi3liz/Nb1SDG8D6vG/1Q==","shasum":"c7fea0fca43a4437d5248a5f053288c8fe151b86","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.3a6c203.0.tgz","fileCount":18,"unpackedSize":32860,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdSf16CRA9TVsSAnZWagAAsI8QAKOUsZmkdumGXamEi7xx\n1kVOotCrL+Dh5JaZ0SeJjQKvwwVPAEMwiIopeAAvitY6SYex27QyBxHunCRa\nk1+zlVMn0RqaR/sodE+lhA9YOo8UpLaaTSGiVcAhGJOoWEAqlFKG3Qhnw+h2\n6oW/nvKjSnBWEeMxB3x1hLxOImx9F4Nj8z6lZVxdsjCzzc1QLESUaG8cmMEd\nX7KE+e9M8k+tq8JCe2Or5trAa0zCrC26BZe9TDR0Ig5Jq8PEY+TDdIFxKM7p\nq6TFIDLPaM4qgwYWda3CE+RHiZUFS9aU8XiiMeT/3OQrjSoxwS3r+evy2Zv5\nXVcOd0OdTZ8FITdlYKlJsT3dcsUv8/H/+n4gZLv6s42zdq4zbDcMN6Myv8Xn\nor3NnzVKIlk81xQkmRoU70Fr2lDErymR59HHtXlgC+BqYLucJV2LYIs3qjEC\nC5ra3x6BINWo+Y6xtaF0EpWBylJv6PHTO/RUXm7H1XQT4KuF8/UH8FxSE5Yf\nLUml0Gq0ArREtldzDJ2psWaYlnmQhBVbQ+VUMJT/xcfSMc4zO3QYGTnyWIFx\nyUm7jtPTpkMN62NQ8LrflVAHEQPr6z4RDWfp/EjRwBujPHyQRoTZysS2o2gt\nZmBNr/ng89NO7+A+4HiQzne9A0/NXSP+kA7etZW6TIUxk9Fo3bhHpC3J6k50\nVCK8\r\n=+gQZ\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCi3KSdLUy0IbuF3K3FpC1CgUwG7EbEB3lViYRJJ5ovHAIgS3xTV90NGlWwt3lZP0uWm+57fMErh+uM32G4Vjrrhos="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.3a6c203.0_1565130106208_0.2970919644566652"},"_hasShrinkwrap":false},"0.0.0-canary.b30cfc9.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.b30cfc9.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"6.0.2","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.b30cfc9.0","fusion-test-utils":"0.0.0-canary.b30cfc9.0","fusion-tokens":"0.0.0-canary.b30cfc9.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.b30cfc9.0","fusion-tokens":"0.0.0-canary.b30cfc9.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.b30cfc9.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.b30cfc9.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-VjODqzB7wCYOtOoC8eWBDYGtNgGedeFweWIvF33vZn+tYOIk4oUJauwXaV5Fx+LxrgpBYp9cWPh0PVQ4CYEgPg==","shasum":"3b27c893053bd07fd59caed32f626870aac392a1","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.b30cfc9.0.tgz","fileCount":18,"unpackedSize":32860,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdSglNCRA9TVsSAnZWagAAXH0P/0qCixF2YR6IA8Akcee5\nHqtl4zwrChn/xaQRYZMZ6UBk8kIdfBENU4fQYucWkF0y3OW32beq5TEEyKjy\ni/gCUElQ6yZjSZsyPKl+nkqx2CwHqOS7cBJkgqHtQQtE3zeI2erQQFfaC63j\nApc+fCSiHgOsz+Qtvhlcl8h6zrD37+Q4OBgw7/V0n2q6GTAz0skCTCwpRF3N\nU+r+bOKsybECfROPRe17k+A5I/myrhh4RYR/IDTStW++bGS/XBwirsI1gUqS\nlTukpdAyTlL0OuC7uCm9ZXa+/YBkZ6h9VsQf2T7wDhjYxCGy3xg+fkAgXlUR\n9Qo3IqHpIx3LXjjcg1CcJtBFKakn/0rc8O/7+7lweb8huKUUf5ICtkl+qMwp\nI87VDMWihaMwhI7KXX6MZU5ufxEo7hzLQIpPPbOJYI4GDM3AS4Vqz80E1ai5\nrVqzYN64RNkrNBuJKPcVPOJl/O3P2zuirnHntcY05VR034ewer6SERQA0HE6\n1nKboE+BthQQgMl8KqTSNbgejPG5jLD6z+FI8rG7nPcPQUJZBS61YgGII5iT\nPcaGOPqmAsgnTA0HCw+lcQmDBImJjMCeJx4Uqf1pmVmlQuXhxb9RUxRe2flz\nnIXQODMTfdilYlvU2P2qDL7Nn7M/BNC8Z5tvJ0JcB50ue92fVfYOxtVIGpYa\nwmy6\r\n=XPfM\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIBc4z2t/5pAFlr7lTTLhsx4XbsSZM3UHmdBdyWrSQYqXAiBQ/u0B1/MO5MZdquBBnTOr4B/IxJ0EFu4UGb1W7+tCAw=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.b30cfc9.0_1565133132644_0.8287497703646316"},"_hasShrinkwrap":false},"0.0.0-canary.d1e11d1.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.d1e11d1.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"6.0.2","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.d1e11d1.0","fusion-test-utils":"0.0.0-canary.d1e11d1.0","fusion-tokens":"0.0.0-canary.d1e11d1.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.d1e11d1.0","fusion-tokens":"0.0.0-canary.d1e11d1.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.d1e11d1.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.d1e11d1.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-yTAkZ6+9gsIcEwjG7lD+emRQH5z5yEkM4/c8U/MtKRhdoE4XSloBSj/CeP9FayQS8+t6N5J/R0jVUshLRSmJzg==","shasum":"bf520a934bd5f14fc97a44aab2e0269f542bf578","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.d1e11d1.0.tgz","fileCount":18,"unpackedSize":32860,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdSg6gCRA9TVsSAnZWagAAd2UP/j9uHwSn3ghsuiEmPOe1\nXB2FDCmPEvPtggZeKaKlIg0BtqDnWdRLn/RkTngemFwuS1F90TgZVYavmauc\ng0yRrfuyztP+LfWfZyj3gl5JBXU5xr/FvFO3jTuxR/m9JZt3hQQTPCr64NuE\nY7XwuAhKBHsVyOA/ltiOFltN5W/r6CC7O4OaE/xU0ugjsg1pNFDnoVy2MEcZ\nXsLcaxG2xCL1O4aMynIx8mzQQWVV4yephCQDjA2s8rpuHUVs0BNvA+EZ6GZ3\nHLXE4o45GbIv6fQnKdeEdi5aPgQCEAAl0m8DUy+gP2hl3DP/O3LdS1KBvASr\nzfk3e7iOAWN7z8baCA7YbF//+YYhFdVLKhr/2tO3ciaAGLkccQEepCl3IzS7\nFRpehlQMx9zeD8WARQTgomk01Ff0NUyZNP43GIMf855eiPaMtrF4ptqXMIk4\nt7LG4mvM7DLeoBIzes3XmTxkuWvTt29ZAV+79J3P+CyftraSNktr2uE0G+Yt\nBHlUN3ytTesmwTd2DYsB86Jb0PJofq1chwEQNAsPVu9fZt7dBmSeqpu4lKeG\nUjJ0UQ3/f7RDhqXcpFGblwkHbyWl7rb9bLm9iRNvG/IAERTVYkwjqQPNqLZC\n+TvREv1L2vln6sUtdxI2LzMlZIKjf0Khhjb2BervEKQM4D1ED0GOoegJuyIy\nbFFo\r\n=4ZmY\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIGUJj8SdksWcCBwJyG6mU2uo5+h3Hb8Ge+XeZo4NQ7NdAiEAkwHlW9Ndwpme1SUjS5WOC/Dy0Rch32htU0eMaiDicVo="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.d1e11d1.0_1565134495699_0.982126821407266"},"_hasShrinkwrap":false},"0.0.0-canary.d1e11d1.1":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.d1e11d1.1","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"6.0.2","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.d1e11d1.1","fusion-test-utils":"0.0.0-canary.d1e11d1.1","fusion-tokens":"0.0.0-canary.d1e11d1.1","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.d1e11d1.1","fusion-tokens":"0.0.0-canary.d1e11d1.1"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.d1e11d1.1.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.d1e11d1.1","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-5JJ9Jpp0DeDUe5HAaysccDBjeQhNO15iYfkxOBHv0JOhX594YUKTbOv4T3bLVFz0LG650ZLNEB9WGOPBSQACZA==","shasum":"54df5339cf1f2bc6378b564004cf2f7d29e54b24","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.d1e11d1.1.tgz","fileCount":18,"unpackedSize":32860,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdSg/jCRA9TVsSAnZWagAA+BgP/jONkXOZ1VzzU65O54ID\n4CqTKWLshYgCVtd6UIy+gdwpsOXzfwjozHM4Zs1ztj95dTt7joB1SJ9xGgNW\nltauaNHjkn7lxwdadrNedAWQgrpwBuOx24Y2NQrY3tQUa05ZWhRKhhWYDgWR\noZZuiHu92TbK2cEUr5umaNyaRHD1A0XKHKBRJVIfMAyNrzTPcfE8VLWQauva\nY/YCIL5netykKXpR81xEN3hde2UtHVwQRIcgI9cehPh377dK6r2XI6/5OQYQ\n5OecauTYWzzBsYQ2HqwWgTl5ajaz079nIqnrKF78JWljM4VsJL22/vZcA0OC\n1lxDYJx2o0EJcseB4XbYLInCKRrQP1inQrQBiVELUzrlhOP7jNhyndLboOIy\nMz+jHx0TI6GD77NDOp/RAKONE58Z3LHktfOE+uceXsteP9GvWMotRIEgZmgj\ndoHDODAJ6LnjH4FybzdIQLOrFAVZdfDA+6raUGtrWenSlvPKf7kcpiva6uwT\nXLietGRuXguQ3kpQpQyYN/CCbGvy4ZdK1W6298p+WJ9OdNEL7GLu8vD5n4HC\n57pS83Chn4lyyGbcSBUqSi5ZDTqV+ixa6jAbr2+z8Ivzz7ILFYq4j+qH5cwc\nM544F9TWupBFqr/DDCgkXs2x3DuyqaCtFpOqx72zK/BX03vH/ga7P8UXuidv\nant5\r\n=CIPJ\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCFl545GTb+dQcQ6QbjQVM/IXRgrhFDkK/ih7evJYlIYwIgGrWodY8vzqIjPTt1Z3DpNWB+Ty1u/HYqv0cUOYkp0zs="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.d1e11d1.1_1565134818507_0.9108211347280264"},"_hasShrinkwrap":false},"0.0.0-canary.465e7e1.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.465e7e1.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"6.0.2","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.465e7e1.0","fusion-test-utils":"0.0.0-canary.465e7e1.0","fusion-tokens":"0.0.0-canary.465e7e1.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.465e7e1.0","fusion-tokens":"0.0.0-canary.465e7e1.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.465e7e1.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.465e7e1.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-wOnGr+PFqdU77txSeMAIJ37LrWy8d9zxmd2mQyUpJ6vTeyW9k8N0qWl6Dk4mTv8s6C8fDjfZjW+0QQ8aXUL/ag==","shasum":"d9034b96ea73a8ac6ffa6a917d392c900019eab2","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.465e7e1.0.tgz","fileCount":18,"unpackedSize":32860,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdShceCRA9TVsSAnZWagAARCUP/2kK2MuMXFTcMP0V6a20\nhlDa3VU7FS19QGWftTQVqaKkfQFdomFmW/iEwsyBq4sCLQU0k3jgG12aczXT\nm6jF4hgNjRWWEVZLvfBbaG9rU4l0VL3aIj60/l0foexXCQmRH7sML+rCUFfc\nieiZTln9DKuJ9Z/0Xe7d38Q56Gw21Mle1W5+ZkRSM7eG3Jtqn/6zn/RiSEVS\nB6yWydwbOFjj+YmT6P4GES5ZO2VEEESSmtlEWtIJZ/Db/S7gC/BQ5+38ZPnF\nBe/XfV98c6vviNkH37Ix0Ae8G3kk3T2+MXr7RC5bWUtICZJP/CRRgucw32gA\nP7wnY4WZJIxHeXuqDjezUjS1zlct80DEMYYq2cDkZtScww3C+X7NsWySIacj\n/mcMnTD0PmWNBzp+4CF+g/jpStz/uur9pZktUzYIEb2KHo5B0TdkYZ5XmIby\n4tQRvj1OGdwFCjf2JjN2ENhuPCIrt3r/Ohk+1G1Kdz6pqMYvyFegyAhlPGrT\nGql/m6NwjA3LMzp1jcXUKbrHQ8nwmc8FcdnmTQr1BES+9cKRnWmcVyESuBkX\nXxMA6mhYwfNQFWaPB41KOYw3DDKoksL1j0gvOd6fIgFCfNdL57xTmBcVeFqg\nXytGFya10EPKg4W/JwmuRlYFYkz65j425h00cHmg8ZzbX7JmOgsiEuYHtC2u\ndt2b\r\n=3AN0\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIHPKUY2oXGKBGrhBVPGUt8X0nE2+3opY5Vd+ZyEbxhMDAiB+8oHyeFTb0zJAf85LHOp7fw6u/GkOWiXFWGYA+zaSGQ=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.465e7e1.0_1565136669595_0.5611360837754056"},"_hasShrinkwrap":false},"0.0.0-canary.465e7e1.1":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.465e7e1.1","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"6.0.2","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.465e7e1.1","fusion-test-utils":"0.0.0-canary.465e7e1.1","fusion-tokens":"0.0.0-canary.465e7e1.1","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.465e7e1.1","fusion-tokens":"0.0.0-canary.465e7e1.1"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.465e7e1.1.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.465e7e1.1","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-FttpZSkA8RB4N1SuMmai8LcUMmbVmFuDH2pMXQBr9g9TsYP+vOC/gIfy8Deg45Q78xkCz65KazfXXWIMilz33w==","shasum":"4a9a9ceab5c1113d026d0e9a68e5102a0ca62108","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.465e7e1.1.tgz","fileCount":18,"unpackedSize":32860,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdShgYCRA9TVsSAnZWagAAsW4P/jzc8DMQtHVJoNUfttTS\nrrYnBh059iK9CCtlkJaelR1zM6ZkSRhUnAdaaoDXsrRS0dfu3o4WkdKD4fAc\naysuzbJ1EHR9nFbJoyo2w4BcMmPf0D58Bgo/zkgAz3y96gxklRdJ8hHR1g8j\n4AdvgdSbyRQoQVsbRYF5qUGGvq717SegL1me/3gEHiqfyCYdvyEcHxSnQOMP\nXcBwYeGsljkprR+BeVYbTfeQSJmv/ArMhG8L8+tKkmKccszXWCQMdNnjGBbX\nAvLL8AIDhrhGOawRrSCx9ISZYnaHVhyUi2iK6wLvqLVgFnJCgntn02jpRTUH\nbjIly+DKHGI7upPlGurgybESi7TCcSJRn3cvPodTK8pOpN9HsO3X1ntGL2SZ\nGhdVWD4c4pHAsj/6+iZhn1mIOy6g0DKh4v91wrzFIvvIWwcdvEDbABZLR7nD\ny+FBHbRjU661Ha9g7VDhkkTvVYsm1zrI11p8wnL3TUuJoEpEM2fcS1EYksEe\n1JgRIL66BFWzkB+Wa2h6U/0jP2z+YUCLuveH3N5HWuMLHX46teY6gAPUhRGv\nN3ysxiyoeGfdpVolScTqnaZrN3xRZjeGLSaNNSokODxbcLAoy0BNjTPWpSAe\nAzsrgBqIRY99bcYXqlQI4p7U1B/y3lQvZ57DSD6VbFWAGI9PwLRntu/ve58E\nfHSm\r\n=UJ7k\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIA/PLieUGOfBQWLtHJT2LhAFWIqChE/OMoTNPLibozQwAiBGBptFfcnZLROAICdmysX1Y1PtbPd1cvlERUGTZnA9Eg=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.465e7e1.1_1565136919798_0.6267695638296862"},"_hasShrinkwrap":false},"0.0.0-canary.465e7e1.2":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.465e7e1.2","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"6.0.2","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.465e7e1.2","fusion-test-utils":"0.0.0-canary.465e7e1.2","fusion-tokens":"0.0.0-canary.465e7e1.2","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.465e7e1.2","fusion-tokens":"0.0.0-canary.465e7e1.2"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.465e7e1.2.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.465e7e1.2","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-NEVZEoqHbr+ciMWSDdUUeNUd4gkaf1hCE2hL+fwGVlKHZJOoDBNYf+FejnQRIjjvICilGjDVbEh0mBne10m+cg==","shasum":"1eb5b584d1ed556e4a0ebc9faf76dada5a195065","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.465e7e1.2.tgz","fileCount":18,"unpackedSize":32860,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdShhCCRA9TVsSAnZWagAADzYP/iqYE2OQdmrwCkT1tUr+\nQ41wEUIhHX5SqaRkrrtdZjsknJv+Bxs8nvTNv5orDQu+jLgguP/gd0Vbycl1\nhz5aHhbsBLBXLaL+oFQLREBM3c2zvKdMB23c0Md80WBsqh21XqRIdwzfv8l8\nPDNbpNVxUi+faI/LZk+dfoNiXvvupEFzNvVTeA9TGBgoQB2xUHHTGio9mnrd\naVMEJXoZI1+8Llv2mqIzEzg8drkpTTET+ewVvGzdoMFxQqlEzhjDKzDalx0Z\nNqOQUtDGLrU3BlRPd63sMx5gu6dtU/sTKwwjfoAKfDJBfzC84IBq4id43xyN\nu9b+7XmJ/hPYQB5YckhQCbdYuG1cQg4l0pPoYB0OKZe7kZWbyXt4EcND1iF+\njDlRpCy4h5eKwAXRUVgPwQPftjxq1hi3s6zVURjKPDTKTJgaGaCRNBSYC32Z\ntfDXsyx6FwgVYXyAnLD8gAmoZM4xzOHIrMWfL5q532Y/4Q8czdeA6v2RMLdS\nPIE6YeUX+2xptvlt6L2w/eG3f301nmkVmc9GEXFYmFKypg/dzc4E3W297Yk5\n1BcyuL+xUr33sMvmOiwPhVGGCM9kPuVZVVG40mm41X5+oTJhEPInmTZ2dMOa\n0XDXOuHcbMXN5DAh3KxgFrZhxI1ui6HeunEaoVuQCM1PLxaRcFyq3xLS6EDa\ndgI5\r\n=bDLA\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDq0QiFT2uUP47Ji0Pl7edPraOCH3smeVGM1gtsvR5lvgIhAOZFsFLd61Pe7ZBVcndnWzMp7ASyHc2b+Tor6ZHBYag1"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.465e7e1.2_1565136960861_0.3284999762629224"},"_hasShrinkwrap":false},"0.0.0-canary.bd48967.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.bd48967.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"6.0.2","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.bd48967.0","fusion-test-utils":"0.0.0-canary.bd48967.0","fusion-tokens":"0.0.0-canary.bd48967.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.bd48967.0","fusion-tokens":"0.0.0-canary.bd48967.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.bd48967.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.bd48967.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-MPBJqLPnrgNm/M/+wRf2ZxF/l2yAjvJc/CHJVfw175AHaF0yCUaiIVB8ZRdJn/3t69fAVm/3/JWvWBBUi7Gm+g==","shasum":"45b93a5286846c953491c0d21436132b9bcf54dc","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.bd48967.0.tgz","fileCount":18,"unpackedSize":32860,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdS17JCRA9TVsSAnZWagAA9CQP/ifZiNleQtvyTgKcCU7t\n+X8Yvf0dpFsevjTnJioAeCHr5q4eGuQxvo9ljNEy0LyPUcXe8TFa1aFMKYNw\naDA8D6yxqCIW5yv/BvNfelRQ/oYTCgDVRTqyn2hKrcmqm5LYrlzv5HajIWg8\nCH/TA2wnqAbpnGEZi7NwsoUT0xu3tUX9bjYkc/7cwkEb1Lp2S7K+rOGw1TSv\nrs0/zwP5whImU4ooSPoK7rsrwd2y5i3czVFxPP2mDAlVtx5NtJVG9IuPhZqR\nVWtALIs7/n3Zjpcfyio+msWafJ2anURZHMluwB+gnHi8Hr1WQVu2MLb8c7VM\nnt1m/XKsqVwguV5/0iKqE6YCyJZTRbPMYTKGj7g7BR+klg2/FfmmUpOBO4BN\nGU8t4oHvmGf4XB/4UTNiWa5o3/Mv525CM+N21ns6QhRF8RQIhciKf01XxOA1\nRLliDCP1riPOgn0s2bR5CWUp6e1QrFH2m7W7F+LkXKTSuq9evrTRsrJiXHvU\nHbjROhiGO8J2NZNTXzMirnRmmD9rX4d7MqylFrpGLg8fcOMjJLG6In1KF5qa\njUan5D7FRjilocHXCW++pB8fT8xaYPFcs+pTfGaE1DL/gZcm2omEcVDqs/t6\nfcMCgx9am9pK9MbPMnvRnVfvuEW8JBeKNA5nxnQelMUJbm2LkuefLW07jsYr\nM4pv\r\n=JYMz\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIEHxwPQSV8tzKt+WG5UQjBd89dr7KCPxl3sZ3c/BHOQaAiEA6mco8FMFYidppHAJTpYy9B/xkXUzF3O6crXxATNBLZk="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.bd48967.0_1565220553143_0.7799002310009362"},"_hasShrinkwrap":false},"0.0.0-canary.aa5bec0.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.aa5bec0.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"6.0.2","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.aa5bec0.0","fusion-test-utils":"0.0.0-canary.aa5bec0.0","fusion-tokens":"0.0.0-canary.aa5bec0.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.aa5bec0.0","fusion-tokens":"0.0.0-canary.aa5bec0.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.aa5bec0.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.aa5bec0.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-ahdxLuWjWPBbf87/IR3pphUwsfJ39Gnyaqr4xRq4XPX1bYetQR0qCem1G7+R8vlY6qo6jSWIuw2scU+I5dcHgA==","shasum":"c62b8c3f664ad54ec5e3a76375f1320c90a64863","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.aa5bec0.0.tgz","fileCount":18,"unpackedSize":32860,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdS4BUCRA9TVsSAnZWagAAbooP/ikBqzstNfrgPCpCL6XH\nHj3ZdZION+h4481yWI8NmEcNj2Rvun6TTfvNRxOqTfWIENeH4JxYCN1lw/HM\n3/J2kYuWrfLdPwX7vRK2WXiaHlSlP9iEzo1T+n/h73slBLkN4TZXyIPx/ZC1\n/hyUaJZpmmsQN4V7IDHuTrz/SWwQoUkmh4n8qevwHqy63V0e5Q6a565TMi6R\nlw7oQhDUS2vszBz/0gFeqcGExz9b0ha9a2StJXI1hE369if7uSaEYvSeCL22\nuXM+Lqn7fUwDdZyzOz8aoqxlwxdXu56pVPPhO0XQUVxeIXKLLuBF8HhgE0Wg\nCus+JotdlDS0j7dNOXCtZU9k+DgIszZ3zptJlkmGyLo/UUJcyIYbDNalFdLF\nYizcu5dnT0RN2cBFALvwuFXb1y2qsEpHDsIboC5dJAfK+AQadjfmcH/E62ta\n1rpsUWTOAGAlx/fUQmzMdSb06DPktgfKeBxFNWEOmxE++VlGcScEx9NBNoq2\n7Ri3Kga8QrZYDcdjmTsQa0XlmH9+Lv8yUUaSxd8VxgjXQTwjClNY502LxFpG\n1nSnZYRjAvhsVv92H93E3021WBCcXLFysia10Nlbf+rrAlPGrLnujCroo/A/\nRQwxbekEMceHoV12untPBx7JYWhX4bRcNnFHGMrUcJfOpDFlMPtqwGYrjh8x\ndTtN\r\n=Ffh7\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIEbnsDxukUnoexqLq9v7LfP9rhQgQVXUbcPSG8Yasi1rAiA9wLvyfOgHj+mjtXUftdrVocMygeQXX4X3IrPsDMg8eA=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.aa5bec0.0_1565229139722_0.26250631626085186"},"_hasShrinkwrap":false},"0.0.0-canary.4c8e718.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.4c8e718.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"6.0.2","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.4c8e718.0","fusion-test-utils":"0.0.0-canary.4c8e718.0","fusion-tokens":"0.0.0-canary.4c8e718.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.4c8e718.0","fusion-tokens":"0.0.0-canary.4c8e718.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.4c8e718.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.4c8e718.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-xOdk1EvrsLxw4cwgX9t7HFzrceSFaJBZbE4W8/rTe0Ov1Qj/FVZywu9+rHi2bijPnU3mYwOuk13jFn7XLBaP/g==","shasum":"76efeca8cac0c85dc3668d8ecd8b2341f71d0e8c","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.4c8e718.0.tgz","fileCount":18,"unpackedSize":32744,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdTcorCRA9TVsSAnZWagAANo0P/jCVIGixi7zC/U+2vpcN\n0VT8ssTTbbiBDq2zwJbwqPphGeMzDIIAor/1N+LoN38TPoF8vD8NOVz5A6Zu\nLSIACssS0R21ACRM4pIzrargfO3tOMx48jRZFosN4e6kHLKveMdGo1jZNua2\nLZWjg7JVUKm9YZyOBiH+yNUrDsuSkgg2sGMf8L5x59gRe7CKA8u2Vu87PE1E\ny89KIkIgKQguBMeHjje/xnKOnlpoOB7EaozvBgzCBbDSXxoodweQvSUq2rCx\nU9SoqKwsWnomKTmlcAT7St3VG7+sfF1zv7BE1Ze5/1ARbraqu8n37jv32+Ir\nwSIYLxKGJKaM9fgg2Iy/F7t1H6tys+6Jg93V9ao6TTdg5cmUpmdb90YeLoDK\nsR6DIda8QSo9l0mdpbHEUnHa70C6aFnWw5ejuCqUkX5aPWjOA370p8H4h1iC\n2U+GxivRmhS8zxaM9zhpY5rm8qzmpsD7QouZWxnSSmJh6sPgGqiML/Vcw3mf\nn5PeOyWSpYVbLmRVNRuMgFSk100zOhPFahJP25Qsj0swmkFQMhUSnbukP0uh\n6PEOtvkCQooCc9VcgmV41zAbQWDyanTSd05JeCg3YCTdqFWu3whRAXzdJu+Y\n+td6GcpRlZJDqCYAh/Tz+VS1MUU8J3IJM3xTNNYDm2EqX5fb1EioS0Hq5I5I\n95ee\r\n=qyZN\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDUiXLXtOBPZKOKc24sRRbtBnAkfTT1wvOxYA8oBZex4AIhAJKTHFnCeTEGNn/xQO1Awgdq9H6yXdVBLC/IlIXCimDq"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.4c8e718.0_1565379114907_0.6076972760959602"},"_hasShrinkwrap":false},"0.0.0-canary.e3270dd.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.e3270dd.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"6.0.2","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.e3270dd.0","fusion-test-utils":"0.0.0-canary.e3270dd.0","fusion-tokens":"0.0.0-canary.e3270dd.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.e3270dd.0","fusion-tokens":"0.0.0-canary.e3270dd.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.e3270dd.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.e3270dd.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-UhYJR2j84ZzAjXV+OI3qKC+rXuU0qIW8vmxLo+vG7+kSJi0jPc9orLudG1e8aaQVcidMKH3MG7GgarewRwAD3w==","shasum":"a225994edb50932b06f9261288d6aa4c0d300755","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.e3270dd.0.tgz","fileCount":18,"unpackedSize":32860,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdUaSQCRA9TVsSAnZWagAAfm8P/i4nA0/wvgEOIvPrQUOO\nAcyxV7kmjKIwgGeVICvbKk6ASqnnTOfKU2MzkmMBId8A+PtC/LlpuBcwUsep\nKSMfUGNGCett+4S70lCOboZKuyhLXWUyAR3BFXoPEV7asm6CqmLywlFhF8Wr\n609f6/F9PCUkKxM2XxyOmKhh7rxmyLu4RraUqaEFy+A0G857mFLO2hivHngv\nbaTZZ3nPXZt3gSWuJV5ln1CjeCDC64eQGHFH4vxchkIfNqi3nDwJvQkjNfMc\nKzQV2GWptEQeTrfWTetpLrJ6ADu9eYcd5Bm1DJghgqfu4hqjd44mm7vYR/Wr\nSY5+OC9ClDICltVKxbOcfPVo2Qs6ckZmpfnQvgj8F2AvgzVjeu/tb7cFX1Kj\nuO0P+7Uc8SpnUZCCeK0KW+20kh0MFAsf580S9hook5T1oBdgaDAUYU2h1IZY\n2mLRlS1MRXFde1K/n3hnApBzlvLmmUEhtiIwjtvbboMalFL2FIRV2M4lWQU3\npKkHFPGBb/yMb++6oX5ucV2mVeNMTwhZnQLbzeqge6mPeobz+zYRkJevoQrF\n/+7Oi6SLKKatakImBVGPKovWYSsNFMZnqDmXdaAa4FTm8pX7CmoCbLyqVrFk\nqWFRR6R5h4yA0+Y2A22VaZWH0yiclYEAHoTxoCBqWcOGNpQ4h5Cf4TQdm7Ap\nmX9D\r\n=Ryr7\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDN9wzq8XkdjtQQE/sVF1iU2/RupJkxtJtT0FkqNgQwvQIgakn6HCS/QmLWtwj8x863zvQOU4bBF5W9I1L2eV8QKas="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.e3270dd.0_1565631630946_0.5628803186392712"},"_hasShrinkwrap":false},"0.0.0-canary.73f956e.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.73f956e.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"6.0.2","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.73f956e.0","fusion-test-utils":"0.0.0-canary.73f956e.0","fusion-tokens":"0.0.0-canary.73f956e.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.73f956e.0","fusion-tokens":"0.0.0-canary.73f956e.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.73f956e.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.73f956e.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-2DXimvYKCH24IAoiAi+b3/uwJZpR7c8nwQY1B/unKp8tVRnHDN0nmaUY0ps0Mg812QQ6t7hsA5aO0qynLMClsg==","shasum":"c880829ea8d5611bd12d828390431ceeab30c5d3","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.73f956e.0.tgz","fileCount":18,"unpackedSize":32860,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdUwvtCRA9TVsSAnZWagAA70YP/3Y8o1tVqqEi4fBtWViT\neBbtpntqbgPX1d+401CyT/6oT//j6AByLMz0J5yVInbpndhWgGJp00dJElvy\nfsskQLOcaPB/c+UlSk0mTDEyB/ay/WY9kUZYXutSHAA3NXiGlS+CLYyRl10H\nWiKQCyVF5L0i7wh18zt+azW9AkU9tscK0bbl/dm959UwAtKfUySDVjds9NzD\nuKvoTZieNS1+XBnD9cEaTF+ucPC2ibe66ToLq9+gFhAV7wx2YGH75TTeOn+d\nIrgH+2lS9Woi/cHOS/eZbQSTmGUfuWDAtgUj2xkwtqKZNZkyphvndn71RIfb\nmnNnatN45m+yQqAjrRfgJ34bL0JpqUibuULxn4efrm8QCThSllvy9Lx+e6bb\noYyCtKb70piAH+KI5udM+oIayvG/fP3mjHYrhSlygrvD9rR5a4GImLNt8R4h\n3jBOYeuvFiOKlPNOAlcuckEG3j5KLSgaajDFQQ9n0RYvGh2ePe8dOGudN1Zc\n/bhXIr2YcNgLHMncLwsRZkKetR4AO2Nnhx6UIOI1l0d3W51W+t6ARJ4Htcmg\ni1bS+CIkp+43FQIR3LhX8GY5fHQHTDAZ8VuUzfQrkAKAaCzzIfg4fC46aQBy\nZ2VLHMha+jgQGylTKn8/oGuQY44PKOKkoXNLKYn11SpWrMkIYOwllyPevfcK\nPxnU\r\n=/k6e\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIHYcaMPo4e1DkOsot48Et5KWzWintWRe13ZtRiILFholAiBH2wBy0BASUtCrlP1ix87mX+bpVC1ZYsqxP72F9uRWqQ=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.73f956e.0_1565723628478_0.5143354539695861"},"_hasShrinkwrap":false},"0.0.0-canary.1e7190d.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.1e7190d.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"6.0.2","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.1e7190d.0","fusion-test-utils":"0.0.0-canary.1e7190d.0","fusion-tokens":"0.0.0-canary.1e7190d.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.1e7190d.0","fusion-tokens":"0.0.0-canary.1e7190d.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.1e7190d.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.1e7190d.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-UAkWs3vKN/0FIJIqXdEjkjnUnawG+LVXRyuiVTlh6sZuhLuMMExk4eAVs97jVd7jY7rqvlpLAq1jkV/VYTKqdA==","shasum":"492aca96276aadd3c8641f7c54b64e0b6b378a76","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.1e7190d.0.tgz","fileCount":18,"unpackedSize":32860,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdVJc4CRA9TVsSAnZWagAAodEP/iRPVZc+AQ76sdUn+t+N\nqORpPj2VwkNM7BW/3KWyZGFgpdzxJBb4i3DhEM/6ZfVUt/mTP3Hs2gRRUO9I\nVu5WpCeJHEq1oNH3gnt8gQUKI/YsSpjMnh8vs1kieufaLa1GuWUeULsf1tL2\nYDz17TaclM8rh1a/UoRUO7f4JKgsL6IHJOqjp7kRndXQr5Df6UytoXpHgo+x\n8NA79F/UF9h3fBG7wH7SNbL4eYBqUCyK522GwjPSQyhYT0cBf894igl/DCET\nCRSgDpDEIbuGF9Xq2KAISXAIYX0NY86Kv6k7KxmyXC/omzy57ujUj5JyE+lz\n1S6gSw+FMopHGpBFTGHOhJ0LUzBuNVJUbC8xu7RyeNEwPsFikzrBKN/Gl0iF\nuJpIS2kc1PP4RPjFESyyVM9tJSiH11nmjVeUYEudOjjdmRe7XJUkVa31oEzA\nSheQf+NiVcVGXlH/D8715IZunXTzsS1lL6NT4WzZOhs9xn3JKqr50ONK+R8s\n7qNJ3UIa55KjOEUjknKFkbCPj0XjfjsHtQwpfqJMTrqMA55uKapnW81dXuhH\nk9us/1l8fooSMdbN+D6VPUhEdWIkbngHEOMfSyY6evhJVFSFrD2t8qH7ZBSK\nqJgPNLt+Izkff3yggxCG0CNjoOdmGusZ/UdgYEAitay87jPcxMqzTZHfylKr\nazTO\r\n=el4F\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIAcFi/T/qzpHKkuswhQ/p6S4ElzJqY4PeMOxjcaUnp8zAiAONYsyJfAx+1+Zp5hatUKs60Mv13MOSfOM1c6CDlgQ8A=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.1e7190d.0_1565824824081_0.8678064063466968"},"_hasShrinkwrap":false},"0.0.0-canary.b102bb9.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.b102bb9.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"6.0.2","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.b102bb9.0","fusion-test-utils":"0.0.0-canary.b102bb9.0","fusion-tokens":"0.0.0-canary.b102bb9.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.b102bb9.0","fusion-tokens":"0.0.0-canary.b102bb9.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.b102bb9.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.b102bb9.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-DXY+FlwvvSDDuq4lR8TSWQEjPI4dlYkBmDsaUAcT2bIEIT4MUJoln2FzxrMwKjUaNOTlj4RsFVqS3xV0+a/CNQ==","shasum":"399c5b355f4c8554dba66a1926c7bd56bbaa8402","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.b102bb9.0.tgz","fileCount":18,"unpackedSize":32860,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdVb8XCRA9TVsSAnZWagAAeFgP/RSJQa8TcHzWeuXHysDK\n0dUbxyfV2/rZNPZt96USrr0zz8ADFWrFDfcxfJSSYtt0F20LTOUofLvUEMuf\nVuzm0mHQwJ6myN0IF6Hwez/ypKsCq/hiLfQMovMy9NnTWLCkm6hbSxZXQOI0\nle33OTcwocsgnWOHOaNhhaIUGED5ViBOReXhIqID2RPkIXIOaX7/wsM5R4CQ\neU9wEMtL26YQItVhvGj0T9KvaU3+OWWOF9xWYry3jJR45Ko767apZVJ1HrLZ\n54qgL1lj3QxM/ArzXQYzlc/oMM9f96/2t0ebgTfO3qd38XWcaNmVt+2qXyMN\nC9nt2ywzI9v1plvL9OxKFMObWaOfR1jMPY2ucpxJnPVEKeoWBSyK2wKngQrt\nMvlrq7PMBPuBi3lBB78eVBGS94yeA4pZLzdwtfTrZjRMujJqXVkx9k/xRiVj\nRXlZ520fUSpdcczYsHATDSAohmqh7YhJg0IBVZL3dStrzcRDwL0pbysg1BMW\nJIwYIfIbXS5myWYbeuroKmJkcV3mLfHJYXxjqVNm+JA4uSJtMyIB5YXPOHIT\n76sS7zJCpsLSoHBynoeDFDItX7DSRQssB0sPePqrugJ2OAtMTTNBlUD1Velw\nn8ZPvCYtYq0892PZ6S1cr6NZxZwf/mLJ485mFaoe7B49Ew4qQE9gqTNvByBX\nRJXp\r\n=oxD4\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIFpcnTj+11hskv3gdbNAW22D8QDvs2x4uwGRSTf1Eey8AiBYz1U247d3qVFJyzZoLkU8FetQRNFuNIvOo80F5k9tnQ=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.b102bb9.0_1565900566918_0.2310090921930128"},"_hasShrinkwrap":false},"0.0.0-canary.ffb0ab3.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.ffb0ab3.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"6.0.2","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.ffb0ab3.0","fusion-test-utils":"0.0.0-canary.ffb0ab3.0","fusion-tokens":"0.0.0-canary.ffb0ab3.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.ffb0ab3.0","fusion-tokens":"0.0.0-canary.ffb0ab3.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.ffb0ab3.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.ffb0ab3.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-7MUdaAmjmkAC9Wo9IG9Fgz/CxZVgyX4mfW/QsfR+lo3uDyxQrfhJGmTHpzYl6rSNsAvBUyE5PRrRRy5tbP2O+A==","shasum":"763d44a4d54d491f66c84b6ee50e5a5aa930cc08","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.ffb0ab3.0.tgz","fileCount":18,"unpackedSize":32860,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdWs4aCRA9TVsSAnZWagAAQggP/05noU/z0D/mTRZji9qU\nR2jcI1JBeDWxYyNQ886uJmB1YhcZ3EqH74NwGFTdRaC6O1hliSOjkIo/PMjz\nB1NIdwDCYo5oxoKlMGFBwuZZTLMLXl25q4lMqgWIZB99H+EXdDA71PQidnCy\nHK4KpVr2aoSOlnU7Czbd+dyxVS3WcJWF6bBXP8DQY+FhZbr2OMEFNHS91a8b\ndg7c+XFXD5umIi7XdcC/vQzKLJYUr5Tk4I4sCRh6/8+y+Cr99thWUIA5hEXw\nYH13gTFXG2nqFzAihSYtpXFpkr3/GL4fy1E2sI2OEX0ZcGznOBWfJK8vWcDd\n0PEgsQESXVWfwxWqzludPQqVNGfR4IHpR6+0eSBGzazMN8AQDeNGK1B9wcIe\ns6/RPS90IEj4fImSoEb1uDJfkbESsbGpECtkaxEUIgFyzP+CygC25fBcDeYo\niwcF9PmqYgafdTyhjqejJvaooOEK8KqhsP8MV6KeilkSJ+UEqaL7kX3a0930\noXJXckaIgSAh64ryIms6X0GJM2ju9dt9YQNd6cjC+l2T1m8iDe2RmIX1bMeK\nUHxH0bAk/sCLvGJxMQ3oTjSfKeic/bcdPKGRCwLbe6VYK+5P45P+fvXPTlyH\n69Zd2B/tS0wpAjXu/g1Bm64xhRIAdFfL34qdgU0+UjcuQGYan/ghIAWKBTRB\nsieX\r\n=gvAy\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCS3iDYtUlg09ee154WNLRp630uf7+eemJUFphsAqVNVwIgSfqwx8jGCSxumoCb1Q0yvoQ86+2/GflXpYlVUwbrFRs="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.ffb0ab3.0_1566232090309_0.09506782429914207"},"_hasShrinkwrap":false},"3.0.4":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"3.0.4","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"6.0.2","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"2.0.4","fusion-test-utils":"2.0.4","fusion-tokens":"2.0.4","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"2.0.4","fusion-tokens":"2.0.4"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-3.0.4.tgz","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@3.0.4","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-L9qUItrgnF67JbcjwT2IEDGkjt2sLr9FN8C9TcwKEGjlVwy2WzhSDLQFaiGRXwNdsEEH6QFJsIdlonrvLx3DPg==","shasum":"5e280bc2181eddb60accffdc35a4b58449a82459","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-3.0.4.tgz","fileCount":18,"unpackedSize":32758,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdWxNQCRA9TVsSAnZWagAAwaoP/1UGHpkcfjvGwsmDOf25\nL8MqEz9ejG9/XVnGxLd2o6rER7mT+JfZZ4LDzlEnkoq73LNvcqVuIZkXXNu8\ne7j5qOPqlRLLnTkQdwYzZN72IxREaMZScBkO7g4kNj5kRutcaeswB7fIyT6g\nLetsPniimxFUSBuEn3hklJVjbPXtNG1dD4LAhJKT0rgme/zV8Gid/WXiQsn6\nujgmKabZeRGn9eRBqbZ+peYid6m7vnTPQaZKlgI7lujug8KS8vDMeav0L3b2\n9fnw87edkGVRd1xZ+k4U5/WE22C6tDZDoN/zB9gMwHedb3WAphv/sXjbq3Gu\nxGtAHfNbunBPRQdgdI9jT4euGgGv2z68nokrd8/QNOTNWXzK840fntXTnJ12\nbuhnGCku1bKdvQ6xxwUkJk4h2JTugJV3XcFXnQzh3vvGkWD/ejnMmDYZl5kG\nUhaOgKiYKiBClAMSO/vOYO2FCks/9+QcMzTBu3X2PEpz9SGPN42UbiSHAbLu\nZpvNIi0V3ddoevJzMBQeDmZcdFC73LVVHzaFBAPUiRrMHYDbWx27c86oecSL\nwEzzfscfgpDYLISd+djz963OzyYGVmsnc7RPmTqKU74h6pBwP6vfmnw+2aOv\n5LYpWlck7tvBcVAYe2TBmfW49Lc7bPtTIFqBjplyxmpXUFINpiC3U+n3KtDG\nPjpT\r\n=M3ZY\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIDnqYq7Wn+YzY+y3aN4l50FafzXkXErRg4SwaDZC8b0sAiEAsYevXNeC3Mbhr6x3Qx2ovzUrq4QmKxb+uo62ATHYPHg="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_3.0.4_1566249807589_0.025527261046679905"},"_hasShrinkwrap":false},"0.0.0-canary.e2fcadb.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.e2fcadb.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"6.0.2","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.e2fcadb.0","fusion-test-utils":"0.0.0-canary.e2fcadb.0","fusion-tokens":"0.0.0-canary.e2fcadb.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.e2fcadb.0","fusion-tokens":"0.0.0-canary.e2fcadb.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.e2fcadb.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.e2fcadb.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-Tw3Piwx9FW+xqvKllLEbsow6RoxpvuF1rTj+7p0HC8zo+L4NDjXgt7Z6GY8jqtT0Mq/DjExE75I1HNZCtmSrug==","shasum":"fb211ac8c8225ade2c478861ba5348d7db7e44cc","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.e2fcadb.0.tgz","fileCount":18,"unpackedSize":32860,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdXwgbCRA9TVsSAnZWagAAKj8P/RGYZrP+0+TBaUxh/4mV\nVLAgwFV7ghkGi7XutFDld91Js0OUggDfPZbL6m05/tUt6OM9k47YQUBNC/73\nPtZiW4A5gCJR7p1R63OnLUfBix/C52u80V4UPYeoqq75//5GQ8/UhcFJ2NIy\nxlepOD+OQFAv2p5OvKzGChIBdd4w6RgHM6OLZ6qmhazaftjIBqqoCbveE29R\nZ7fT+Q727xZOj50umawH36taYCI4nQDZy57DBSe2Z14hS0wqqKcLWqojPx7k\nOtO0VhAP2cnXbUi1XZ7/7dkTs77Tchef+g5R8yPsg/IBvQPL4g3DFCY+t3k0\nn+3iscxTlrVgF7LdguYFLy2tfUCnJfJX0dXyXrczD4/KzaKw8X3y+zgUiqSn\n3Nlmqiql37eIzw3qvq4QET2FVN3zkAtNneJpF+vu03hsyud5JWrV8vEHuRFI\nLf9MnAb1j2UM9rncpe89W+1upO+CTuFp4uuVs6wloG2n2GmAedxNXaseKdTq\nzQSnQt85NdJ3nu1gM2ANYleKrF8EK+Pl/XPDe8rApx8z87kiSWGcVgRl3zt2\nxFiLG0chYlfwDiXDayzGCUylpDjoWbD0XSnMnsMidAlY8D4ySmfe7wP7va7k\nvvIURBSSUVOhl6yMbgicUcRoQWFOqJxmLivEbKrpFSLAi21Zh933GAZ3k4Ds\nyNWL\r\n=PF2m\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIAeXxVcdEcZrZneG3ZVKv4jLrHwD4mgfOpGzVJ8NQXY8AiAM3N9OIaK198PUSe7F3uMfSl5Jeoh3CJA2SRNWyFK9xQ=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.e2fcadb.0_1566509082843_0.11815871670942246"},"_hasShrinkwrap":false},"0.0.0-canary.d767d28.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.d767d28.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"6.0.2","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.d767d28.0","fusion-test-utils":"0.0.0-canary.d767d28.0","fusion-tokens":"0.0.0-canary.d767d28.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.d767d28.0","fusion-tokens":"0.0.0-canary.d767d28.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.d767d28.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.d767d28.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-8kn4kEu8m3gjeVP2P/nxarYBXITNicRm/3RleMCInMI08qyzJuZqOSsPdcxVr+Wsd+6pippe7I3/tUZXQlQqMw==","shasum":"c3bde735c5e51816d34af36144c3c866d22dc2f9","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.d767d28.0.tgz","fileCount":18,"unpackedSize":32860,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdYC4GCRA9TVsSAnZWagAAB1wP/0vm84/zTIM3QOCIi74I\n3tam7/kEH2y1QjkDm6Ijpv+5RrQd7+so2tnf55VH0wNFj+O71wDydmODzHSi\nGV6cGQKGk11Y3wTl4YTsepr0iSR9nhigwIMuIllWCGZBPaKzSUjuzj0j5jgj\n4PYuxKV1GL1ewcYciiCCVIvhdcBuWtfCr23hFK59LQyPAEQwFaSNF3aedDf4\nj0P36c0elCgLi17Ilg0grE+sU4cazlts4mxPYVNHV82UKfAyb6sGzBBCHYdy\nIJB9DfBvXkRu7n82TVNTfRxVWDo3uVWBTmO3FLslgpdd7M9yT7FVeJ4YCTxB\nckMbfzMk5wbQne1AQM0nGzrRwpWHjnqS4BTCwJwzG+Bb4Z2Wv/9J14mRjjmg\ntNb8ahudl6N7/GtaditAyor75bMRyOptyvmyEPGf4sYR+T6Upwf/Qi3HKrzh\nZk65uBV0kqBMzoxmUGyQuSUAS9Ev9D4u4WrfApptdjfFBTVv/i8CJ03tWJtY\nH1EsCKQ1YHK9M/MR2ecQg6YTnbEYYdO3gD/eDstbSmmihFakfbWPYMHSueAN\nX34iFbF4Mk8KUTRq5z2BtBn37aC+aWKFSMjNLUEZicEyy7Md7fXqr16vAsNv\ncimmSqVmmg5882eVpoFiK78n0EdRkKORiIOoVJUvjzrLcjIOHEByvtnSM7Nz\nWDK2\r\n=/TAn\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQChzNT/tT1x6fRWmFDTmT1K0ke/4V5hq10NZybt+AkoPAIhAJxnqd3jTL60PpYvrglFqMca+d+YwWrXDZe6f1C8+gsv"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.d767d28.0_1566584326030_0.5718149935413908"},"_hasShrinkwrap":false},"0.0.0-canary.c189a42.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.c189a42.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"6.0.2","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.c189a42.0","fusion-test-utils":"0.0.0-canary.c189a42.0","fusion-tokens":"0.0.0-canary.c189a42.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.c189a42.0","fusion-tokens":"0.0.0-canary.c189a42.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.c189a42.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.c189a42.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-egnmuTdxcOJRz4AbVMQPPbreYm+70kOy4+awHsmaACtpMVTCCtFwnRsioO174sYCwG8pjvyfmqq1kbcAq944mQ==","shasum":"71d5edd44516f51d980a20557fc3524b27456b3c","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.c189a42.0.tgz","fileCount":18,"unpackedSize":32860,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdYEytCRA9TVsSAnZWagAAkBMP/RsiDQ//kHSpnLMu4Rkp\ne1si2wqc/9DqqcTgfUVgl1lwm3dxr/lL81KWcsLlt5ADJsWBHFgXx5HIZ/cV\nJLdwE5xpe0e3WGtqxTHf/PjlDftJEaXFW1UT9TCHp2kY5dypMB1pfuy9X+tF\nKwKZnmDGJKyaYcgwC0eiMU4dL0eU0a2FptPfsaEzS7kew42Ad0fvY3KnGpRL\nf9IUYI14Gsz96xObtVmaohDjw9tc97uckUj/wEoRvfQReRF+cVqZ0raODSiN\nAa7Kwv2OD1siNwHHS/Z5CUWmcyw5HDEls4qlyzXpFkE3XJMMBTKWNpKfPgyJ\niAeQVQ1yR2DRhZTaeycvw3GKvmd73WMjGoAmmXCwhZPBjMPpOGB/BebRSKrz\nBfnHkVYgRlmI2/CnIfUfpRLC3T5TK5yKwU4EWBVsOIOcud4l8RTPaClQGaVT\ngwJFTTLQhzPHiGLNe23FuOmVmdrI0nu0u7Bw9yf1e4UluB2l4fqVafzw81Q9\n0GUWcO5s8S7m9H/MLIOCZZgZqXEY/jFgO9EXcg7rgG4tKo7p1D12ai4vZVxV\n3pWMAe0Upf3whJtVhjdkIgsdLG+mHVhvMkAMCmpUSzaXFEc20XZbvYzET88E\nb5vIa4d5GEn5tK8Lb67Q+8BIj4q3sLBVI8mApTN4Dwigp4VHRM/FU4bOSeRK\n+rzC\r\n=2/eW\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDwON+MNuu+irYtNY1WlIChZJjAnTXT9gi+IoxQ3+G5+wIhAL3GCoqTU/ZDbZDJ6I3p7PDkPIJ0ygwYTFK4Df7osnbt"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.c189a42.0_1566592172986_0.43693274509124813"},"_hasShrinkwrap":false},"0.0.0-canary.aa40d96.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.aa40d96.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"6.0.2","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.aa40d96.0","fusion-test-utils":"0.0.0-canary.aa40d96.0","fusion-tokens":"0.0.0-canary.aa40d96.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.aa40d96.0","fusion-tokens":"0.0.0-canary.aa40d96.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.aa40d96.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.aa40d96.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-xauHnxEFHrcNd1pqqoLAr5EL8eQLUC8NmkaiLSmBQwEKymqLtru8qZ9IlTdsN0XPLWRNg/nDIruI8k12N13BDA==","shasum":"3471140ed6588f4caf97902b0f7c5d5a7c462041","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.aa40d96.0.tgz","fileCount":18,"unpackedSize":32860,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdZIqKCRA9TVsSAnZWagAAi1IP/jUDjF/gEN3Ykxyk7gRe\n13v/Y9O1EDfUaVsADbw1A3Es3/9ZRFv40D0dsmNQz4btGsvWNhOmLjXFg9VQ\nuudyekdV6yanpYYs4S1lSpZguvjbB6KjbK40zLf9HyvZB4mcF9cQluPMRQ+S\nKiVmRv8MVDtr5L9MHnziGK6N/LbCf5W2uRSLbOETJ2HXBFqw0o8w9X+1rj6F\nrV9BbU/hJpNvZhz2IEh7ITkhl/+kdd/DaqaT+qUL+HEORfoT14QZGvFkdHSM\nJ54z+qoSkHRzbNcdVEGuFl9HfpSoqvP0jnYwZj9oLE7F3bkPtaF1aVbddGkv\nlJ4qshMSt3K0Ve+lv/zfTUz4IslWTRSrQmYTRhlVIDapyfdkX4bHVNrzLHwh\n6I55g/BXBDfTUQ/WMA6ghQid9rZkHKeeVoYT54qrMld41J0sh3dcYZEapMXB\nHrLLrLE4CE5VdXfkYs7zBfAtRAHrEJ3+6fjGZ9CMUp7gNS76vLh4NRg9mYLu\nXP1QzK9zymCNe2NieIgKNNHGOv/t3BJJ4NSjC70gAuiNSk7Ap4MAJ/Y6ddTI\nxS3EjqwU4H5jbp1YrslXlr38RYtYcUdXj2ZlL7Y3IkcuSn3K74axaH1QbEtV\nluMrIUZFyo2uzAqkyrwC5x5iDlbADlLiFVjVjXCteuwWFYAJK4yBwCCAYJtl\n54sz\r\n=ZNNe\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDF9d2NlFoNFdubVtF51jTHRHzZ/S7re9MS0hViXXpV5AIhALoX7QMLOFadkNDMD00oM0BYuSi4LpbomCn8jkDsVKwo"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.aa40d96.0_1566870153576_0.4696278741207556"},"_hasShrinkwrap":false},"0.0.0-canary.a9d6e7c.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.a9d6e7c.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.a9d6e7c.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.a9d6e7c.0","fusion-test-utils":"0.0.0-canary.a9d6e7c.0","fusion-tokens":"0.0.0-canary.a9d6e7c.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.a9d6e7c.0","fusion-tokens":"0.0.0-canary.a9d6e7c.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.a9d6e7c.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.a9d6e7c.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-WcWS/GwoXVT69EhZaKxNzGkdBMxxUPRKkugNC5TNXnCvx3Ot8llRb7aZ7PMJUc20xRAsAdV/zxxwQSC459pSHg==","shasum":"c88cdbbf2d6fc696f3f95cc13fc6fbd8f99dbf3e","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.a9d6e7c.0.tgz","fileCount":18,"unpackedSize":32877,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdZWH1CRA9TVsSAnZWagAA4tAP/2FsVUd4q59G6ySVnrj1\nxlC651eTAKTvowaKbVknw7ix3zR/N4PVRXQGbSypcr/0Y6rP3Wz1jcMGRG9C\nirXK0NztMZyHPM+/vMOyeQcfClBriAzXExCh1T1U2Et/p7w1auvI6uWM1H7+\nZOMS9x5On/23hqx50QCHMvyOOBZfCy6MPVwohr0NvWWBTSGZdulcXKZ2Ei7h\nAqWb3Emiu5TUgvYiVpWhw53J4VXSz8Mzd5LzbXHa5ryIDGa5FAYKB+82SkO3\nsBJhlmukD2NV4BlYZ2o9WgONH8bRzcAfDeYsOYxAt8OhhR4zFqPWXhftxlbM\nm3aiP/ELWQsx+v5hvealgf+tEMA+FaTgzqOfFLWk8AUrpRi9maJHnFFd0TWm\nyTwakS8OUeL0qf1S7XxDBGGzEQdDtUzcI6rVLxvoAMetQRdOpeNCvXC90nog\nY1Y2qEwynaUy3/AudYgUc5/myDAiDOJ3dpuqSauE6410+TbXxlpR7dGkelFQ\nYqsPKUSU6f/ZWriQDoJQPX7PMBl3KEJnt1CTkcuxhvS2dC+bANxQWnhYAyd0\nVZ4f6k1/blhn6AgQ4Z0vZnvc9O4kNhTGTNDXqQZVuP63mQp6saEsT8JfAjmK\nHW+YCoh7Y1lRxvdtyOP0Zf3uBgvrnssPoVN6qrTEprZ2mG6qWyND9oPzh9wP\nXYba\r\n=PSPr\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIEiETcYJQE3sH5ydcu0ODXlZs30Yx9KitFkp62gbDQl+AiBAAjoE1GMHnS5rHl9MU/9+cDdC3T+5xra2JdwNqMCdYQ=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.a9d6e7c.0_1566925300335_0.24367123093083332"},"_hasShrinkwrap":false},"0.0.0-canary.f608c58.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.f608c58.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.f608c58.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.f608c58.0","fusion-test-utils":"0.0.0-canary.f608c58.0","fusion-tokens":"0.0.0-canary.f608c58.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.f608c58.0","fusion-tokens":"0.0.0-canary.f608c58.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.f608c58.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.f608c58.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-MwkjsoaEJd5383PuHjpB3xz7gfuqlz+vPBsNMbjzLhkZZOf27XKmE3Wf30CdE2TYSrDxHyEiVgvXcCA6Y+G6gQ==","shasum":"0e81e18a87566a9882564a8f62f371005e3d59cd","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.f608c58.0.tgz","fileCount":18,"unpackedSize":32877,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdZZR/CRA9TVsSAnZWagAA3MMQAJo+hyZuDN82bqvlCn8X\nXV4ujxQdWS+xReCySKjgh6mRtvKMsYgVnpgfoELAHEE6f12diuOtvqnR8FLL\n71lTx0ceSIsWjvakOhknJUubHlKWRCQrcJAIYxTvYDqDAHIoRgIkUemF3Nqz\n4ayz4JFR/EqouDhGx3+VVrU3BB421+kkwSHjur995IfD3vbLYE5dg5muf5gL\nbba90wtO2qWb788LcqRuMRtmzup+IR/zRTOPw3/yY2HbsVo+faJ5MQqklO9z\ndbvoT6dC3j71gZjyIXfI4oIe3b0PPuHU+CZ0bPPZIp9ihZzgMiRixUajSZYI\n3yJVi6tQr5d/wSGYaFTEcK10ndlyFaWtxhmod1ioB/klXq4RxpXf3OlfQrlM\nlsCJQaX6WOJ+UZ98yLivJUi/nd8K91NN7mEtusgmmMPiB7dku+54/HAcdmix\nFJcFOKgfNHm42oYzrGPc0KYy90APhhpATQ09bMxz1tbj5CW0NQ8cB8r+EKPJ\n4tnEfafYFFm7xAzOKmDnh6JlU3eXByFLHJBSP3MC/2KUwNftGKK0XIBq9oJ3\npLbxO3ShtBOME+9LwEKdK7Zj7EY+aEkUk+/o5k5foqol28RrgxCNRVffU+5n\naZh4YCvUx5iFnlhWcHCmUrYwM1FCJyp+AFbrPzsTid2r75pao35KXsFmXAKg\njxAS\r\n=wFyT\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCblJAvfh53aysp7m0CiXnLe0zJSQAclCiN4GC0ve3o7AIgVFTeYkiq19AUyK27Nzh+atgEwDaAGoSNF8Ya1Z7v+JQ="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.f608c58.0_1566938238581_0.2744494109781366"},"_hasShrinkwrap":false},"0.0.0-canary.9d5ef83.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.9d5ef83.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.9d5ef83.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.9d5ef83.0","fusion-test-utils":"0.0.0-canary.9d5ef83.0","fusion-tokens":"0.0.0-canary.9d5ef83.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.9d5ef83.0","fusion-tokens":"0.0.0-canary.9d5ef83.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.9d5ef83.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.9d5ef83.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-Eoa2TUw3xU/GN3LVUZKkJt89LC6IOO/yD3TKy4VPMsf0f0WBEAPOhEqkd173rO9s3cTEouyUgnyiBBopu+tAng==","shasum":"3057b2290755f674c2a004131cee151de4a4c788","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.9d5ef83.0.tgz","fileCount":18,"unpackedSize":32877,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdaAvaCRA9TVsSAnZWagAAZPMQAIUcSPYYES1GabY1gehD\n0iI4QPRG+khAGN6Z8H7VA1dVl/gcKsvSsMBGoBQhlFQf1ciTrOgLFMUWcoC0\nYt4yuCdUv1mhXImeuhoty8zmQ6haXrYHr/tJxKsriS7NvDaEGIjWpPWpQWZR\nCh0qhrg5et4VTSeU+Vkklqhtx9QFzih+pRXmaWrUFdY3fuF4RJh81ko6O2hM\nTMaPrmn36nmTUfHVWsVVYk068oHlqUVv+n4ocmbN3Nx6H01lvkG4ZP6u40Gc\nqmq9WPBNDz3mfPqy5GyU7qiI1EpVq3MzYpOIVa6U/Z1JKoeJZZH17QOa4gO5\n1nXPIgIojlrYsH/H2wv1B5WS76huMTMLvLfI6xtt3QxeJSJ3LejJnehgJQUn\ncxY548jfP8DW2wGWWNV7LOUbBLfwEsth5pqvFfTNnh2WSvTpYFVSw8BCkaYN\nrjd3cfGFVJ5nnGMBa2MAhSvHqRlmEmf68u9av9LHxwapuZ+c3/KdFp4xcTPU\nrQr2vh7EJhhhvt3itPVgddqdugEQRyLvjYcW9Dw5wA2D1caLtKpWulRflbYV\n2yxMO4LqcjreTHn5dVWlE0LXIowQZ1SAENcJm8KFBtHPtGuvSXqkD7nwWAuU\nr/yMwUvJnXQn03ZPbPEi7AZkq0zmLrhtzFjnmqM9/2jZWMdg6ulxdE83+npy\nYQIi\r\n=qUYj\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIHNynRK/vpqDTZG8vAoAFlzaOlRzndOjbyT0WIGoJaXIAiEAs3w4MTLL9IsjHG16FUl6LpCZ17jfsPDbuMrhLzWEXqE="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.9d5ef83.0_1567099865730_0.0027183516422628617"},"_hasShrinkwrap":false},"0.0.0-canary.096185d.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.096185d.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.096185d.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.096185d.0","fusion-test-utils":"0.0.0-canary.096185d.0","fusion-tokens":"0.0.0-canary.096185d.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.096185d.0","fusion-tokens":"0.0.0-canary.096185d.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.096185d.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.096185d.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-KUA3JzVEoW58jPqVCwRUvNdIr35yrtHKgnCQA/nl5okjJD9HtTRmwHdSzk41oTfQP56fxijeXWDPGq4WD2N15A==","shasum":"eb6a2ba5ce060bba4cc7a7442a6234a8963d4e1a","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.096185d.0.tgz","fileCount":18,"unpackedSize":32877,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdaD9JCRA9TVsSAnZWagAAcMsQAJqWChi8mGRSOlenp/n5\n2/mtpdF/Nv5Szc+zVpvEDWAWRWb619ubP6m/KZbeVtg9m5BNCADKNBXYoJI8\nHy5XV0bhS7l+lloMqyUGXID2Iw7cV4ByIIfSwDvZQwdyQqdF9lBpkgE5zNWD\nzAKAKw/rlnMVeXicYOGebswqrBXfWX7FpKuGRetXqFlQf9MSAoppZ3EUX8jA\n+I5z0Q6R9orZv1bO3gpb216E8eQDG7+kTlrkAv6FXuRKaAb4+iqYgmH/Id2j\nqU4V/Whe9cgnPuvuPAJ5FwQfJT5qZOQee5dcKZf3H7+KqDRif/l+XtNDQuIO\n0ozwJzjkgQ2gtVSxzxsYAkF4DSyFboNsi2Jp5FVPI+kWbDdzN4Bt8GToqst6\nhQpAoCaZYfTbvq7ci3j5DoTvKPzx2ZxZKiNcwy1A4cQslo3macLv+V2+HYIM\njOjOe7nHcYDrgCshSfrbv5T7jSbsD4cHh824V/OJSkavUqfo6ccYLBvWu+oO\n8YQRcY/fab6+7bBppnAOGgzla7OhMXRGcnERTbmadz6M3uBg8prOys3SM9vq\nlM7aDAF14+0GT85PpQiAM3RohqSTFyBqBg4J5jjjynCb1PjtqBPCR461vRJT\nSuDfNywsy1rPz8HoCTOcUW5vcoRi6dC03792g9vDH8ZJ1cAJflpHi7zTuBiT\n9ZHz\r\n=HUtP\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIF4f7usmrZJVU3ivYZeFElkyj5MoshY5WXv5lwG/mfsyAiEAi1jrlAqA7MeOQw4BxmqeHXD3M97JUHCvjsxDLeuEswM="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.096185d.0_1567113033358_0.6100955744674705"},"_hasShrinkwrap":false},"0.0.0-canary.d78b7bb.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.d78b7bb.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.d78b7bb.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.d78b7bb.0","fusion-test-utils":"0.0.0-canary.d78b7bb.0","fusion-tokens":"0.0.0-canary.d78b7bb.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.d78b7bb.0","fusion-tokens":"0.0.0-canary.d78b7bb.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.d78b7bb.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.d78b7bb.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-R5jygmGwTgat60uBI7J3OBX7zjFA01qfT4hTjgCfwP+Djc1t7zmCDhIhgjqFzYCXl8J/UU/774taKL7iJKviXw==","shasum":"be583eb3a114084ac0b1df473700424144f5ae85","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.d78b7bb.0.tgz","fileCount":18,"unpackedSize":32877,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdaEdGCRA9TVsSAnZWagAAXEIP/1/hGlA+YGSBSxzU6Eq/\n8AQfXeTCbLKEqoiEuJBnjcjCpcv2SrRoQDAfcYsP3JROjBngR1bfaBYvn+HB\nEG9KNnVBRRHa9mN+UI4wFkUf9KhszpkAvvzu/tH6mqkxK5ZPhhyXnEAlJ0T0\niKTialRpUYAahWJs0M9k5g0xYVaYiFayx644mBI673Sr2Q4HBib3r9JVwi0q\nEHJlynIjuVv/OauSTPIUOS2sJ3VAuqBG8uBnKALL4OhcVjtmPz72qAhgRmFc\n0naU8rfV7pqAvuD7Ih4AyZsvDHKUE5rz5/TJLtmL4tGTxPtT8W6N7qM/wDyS\nHWAvj4kYSYF8TeLFdGDC6GQGkSgHa+nmNjGh75qaG4Z24/57NT9j0CQ9PfE4\nSmpE58HSG8mcG12YVPZtPu3CYhc48uBoXp55yasLNRs3Oe2UGmHbha1Rkrwu\noTdWfa7/ySbIsI1EgJ85uJJs8AjnJ5SEgPJ40dedBWoXRhmDspoGUt6l9rJa\ne+k06bLtt+VxpNXJj+kKcpMEjXk26vuXNRk2eN8l59eLab+yneNyoHncJDyv\nXGNoAX9E64k0wayCBkQwz+L2Jti6RefbfG5dJLgaYVHwfauUEzvj+t2ffYcP\n6DOH2qjJMyHQzwSpQgAEyd0m0aRVUqUHOO1qQtx6D3PFouab6qHUzfSSfo2l\nn5rn\r\n=5+9x\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDgv/3CVOWBj+NM7IsKsCJX6l5UiGFQnEhxcVrqtlBKXAIgOVS3018LHm1j76eGbtKkfA/FkpZGQn2cciMdcdy49nc="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.d78b7bb.0_1567115077544_0.9593015210182243"},"_hasShrinkwrap":false},"0.0.0-canary.2a2b83b.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.2a2b83b.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.2a2b83b.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.2a2b83b.0","fusion-test-utils":"0.0.0-canary.2a2b83b.0","fusion-tokens":"0.0.0-canary.2a2b83b.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.2a2b83b.0","fusion-tokens":"0.0.0-canary.2a2b83b.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.2a2b83b.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.2a2b83b.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-VUq+wZSY5OjRiNL5BMh9IhFkrdz+jtNeY6DTP5fxHEUvFb8/MhZOtoApLyDCLEo/Wg2lnJkNCW2NVv9ec8Dx2g==","shasum":"14409fee6028911994fc03be1292b4b8b346f76e","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.2a2b83b.0.tgz","fileCount":18,"unpackedSize":32877,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdaX8qCRA9TVsSAnZWagAAIkUP/0/rAAdeovGECikoWZtM\nPqJqYGJlB9W1KVCWZ3KHPmvNf3smGoliqBwFErA2PsK60wMDad9kG7HvWAR1\naS81k7EfMS4WBWHeby0cB1ir774hsNAbiS0sBFxqDSRtJ5uXkBPFaCgADtbV\nAs6c7DBTRrccEfX8LPRp2ZU3Dni3msM/3UXrmQ+WOfYkY8xrD60aNaz4ces7\nWMwkXPQkJrTNCIJsDoj7HAVUEBRRggJidWYl80eNUbgU+4Uo4BYhw7Yhr0Mu\nph/TJ3jZCUuLZDQ8//OYVm+Km7xynoFM4d5uhlyHd9e3Hx7ZzbB5IeL5izNm\n3EzUUgC8D/wcH0XEL7U2QikhH6qz7fLB/Y25pnJ2ytD1JFKWUE3rn6EXWrvg\nH+q8kFLc4H0DSKsEyr8NsmQtUoSes9yIGoXOWEwPuGFGYg+kAHDsUtF+V3Z3\n/0cbCeM46CLA9G/UT3TJ4SEpOYJAsB4WkH42oDGx26a0+CgwMEl+d2RSrNg9\ndOpr3zYeRrLMgpwIO+pXv3IvwR9LamdbPGRX9hzitn6oZRqskUpcTxrSvsjT\n/Y3b347a3cESJenEbAs71OmQAjrBywZNyEhQV/K+Gb/NXYbynY3ZDYiIy92r\nw7ZyglvTbQMgzmutsUe5JxDLIlesQv1kuUhVt8L5Rm3PAzCQEcVNmlyMI7FM\nHYaL\r\n=G6MA\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCYcq4MEwo7eRSlixBW5Ej7k2J7FQkentiohUcc0VwLygIhAL7GYw2zH63vV8J88yWVQfeD6m+PqCfOJE+kNKnVsQL5"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.2a2b83b.0_1567194921992_0.651787500728082"},"_hasShrinkwrap":false},"0.0.0-canary.a0f0132.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.a0f0132.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.a0f0132.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.a0f0132.0","fusion-test-utils":"0.0.0-canary.a0f0132.0","fusion-tokens":"0.0.0-canary.a0f0132.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.a0f0132.0","fusion-tokens":"0.0.0-canary.a0f0132.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.a0f0132.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.a0f0132.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-K5R/lkLEj0yiYYCvHJKp9phH1QRQ6lBLVJ9i/RN+sFYPocFPXDIzzjc0ysMmyB+58sBsUBo7YBVIh6F+lBxDJg==","shasum":"207463e3f4b349c33208610512db86b2c575492e","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.a0f0132.0.tgz","fileCount":18,"unpackedSize":32877,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdcECDCRA9TVsSAnZWagAANe0P/A+yp8JuRyXLU0YHT8ff\ndOF6d14LRMCqs1m8RCGoPlefwYmsT2uJU33Ss2co+6zamcpROsP1EonLJU8O\ng0bnRDlndvRC32pd4oXVXqiHjWle7mFH0Ml9iZNqIzYLPxuTmQvUWbS5Xr1S\nzjnd3R3vKEb7PRUbSx8nhXjp4SsLj/quG0f9H5V6DHeFL1mf0hLGFMzoE6j6\nrwB+7NR2Dg8pDGY2S83UGNRVRQqnPNfqI86Fu7wK5lw1Pbix8TWxlmnFkb+c\n6lQdLQChsnd2BIviF6zufGEl4o0eByqY76a5Azam75XTvL4Y97qs7NVM9a1H\nA5Y79TFv0cAdK8I4MX+BaJ0XXsCnnHgicP8+wzpwUHIWPr88CSBc5ZsSAAR2\ngNc7W/3QJWNhqA9MP6YjOuZ7mZX98hcU6ylA/TImgEzoviKLTXLp4YdhmBrO\nYurbQbYNJtAJmk00Ql0+k2jmW+C+QbikZlczfc2kUtj6wgC0XF1+cQgHU9HP\nEXzov2Pe7tKMzM0+rfPcGfor41pSLY2H7LuP84Yx+x8/P5undiipCa9tnpDV\nwV/+2ifPsias71+wWJ1G02LCR7/TUKdE8SthExmPEAcmqCITSumkKS3E4L/2\nAyGUY4zILWp9+3NoGcMm/tUmoaPLwAPRA4mE49fs4t/vLDo7XS8TrtdeP6ZI\nJEt9\r\n=Y/uP\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCqQXZZE0wwtbZvtQKx6um66mbU+jCw1wF8hTMx+DCsZQIhAIo8Ho+AF2K6NVM2SXLZuaeOXcDnTaGGmKRKE1th+DSe"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.a0f0132.0_1567637635052_0.21463676880921434"},"_hasShrinkwrap":false},"0.0.0-canary.109b061.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.109b061.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.109b061.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.109b061.0","fusion-test-utils":"0.0.0-canary.109b061.0","fusion-tokens":"0.0.0-canary.109b061.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.109b061.0","fusion-tokens":"0.0.0-canary.109b061.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.109b061.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.109b061.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-EBT20UsPNfEBNvMR+3AFicMfXcl+nZiXgUoSS1Pl9SxhqfWQwe/RTmcsrHxWH/xtzDXdPZggq43FYMrRv4Ol+Q==","shasum":"fb88d1ce809a5299d58b9f14a83643ab3971de51","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.109b061.0.tgz","fileCount":18,"unpackedSize":32877,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdcTm4CRA9TVsSAnZWagAAxXYP/2/etm6gPt5AkSfIGo+7\nin61PvSEAkW87+yN0BjFfcgiskVzFgMIjXsMIhiAgKIFAXFVtmx2XwGD/du/\nhf9A1ySR8rYKQmrImmx2+bxANCdw5uhHDIL5XuMs6xdhNeAq2+FGe+lUgn8J\nHZG7oLQjnJkue26GmfJ+zpF8QWVHothEzUbqf46sbEJjiKQXt/EzurNNecTS\n5JsBOIhcs+VnLwxAVtZFVtmeK/0rsKWV0zZV2ixFGiBpp4JJUuuCW8XvKkrl\n1S0jjxoydu4j8iowLJRuJTbF5Kdt91omYrFzs6Q3TZM2IO7CH8z41KE67Ljw\nx/VigLu84XL8Zhki/URIYXZdKKwdwDhp54I9RP5rc0nM8LdXwFDVEDKWK9GT\nOsLI17wW9OWLxY0qLOZMcxT+r+3fwAaT8VaMBjlNCPiT7mLIyUaIWlx+pxq8\n4/CAdZNZQBpcRjwB27U14Tfs062uiQhlOg9XuvDCCVB2xNEnpo3PpWI3Uceo\nCa1/wksUpGrcdLoQ2p/js7G2/BptWIplxvVJHAGvsmCiSRkxgQlxF+LbNPtk\nE65iYnVv+PwJdxDnAhDk2aPv25EXZIvwXmMS0gvhvLfW9xsi0C8qUNuQuOCN\nQ3S/zvlV7pFirHibqoP4t0IcfpxPrHrAgiHzSXEczunl2YfTPsZZUcre4bMC\nYV5u\r\n=03fT\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCvBj//56McvQzNG5ZxHcZnQrKhxA371yEBJ41XnFia7gIgIZp9Ds6yXe9BJU0pFiV3vjBYjOu4so8ZFBNGtrNqtgM="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.109b061.0_1567701432165_0.6596347119511967"},"_hasShrinkwrap":false},"0.0.0-canary.66d82db.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.66d82db.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.66d82db.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.66d82db.0","fusion-test-utils":"0.0.0-canary.66d82db.0","fusion-tokens":"0.0.0-canary.66d82db.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.66d82db.0","fusion-tokens":"0.0.0-canary.66d82db.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.66d82db.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.66d82db.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-9VForODBV3hptEwVuXP4lj6Q6/XRpmULdcNEclToktCn9QQS0cdbHfGppFanZ6kAakpRSqJxIJDpXlrbq4fqXQ==","shasum":"3e226f185710e58664e7b744ad98e61fe4d27679","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.66d82db.0.tgz","fileCount":18,"unpackedSize":32877,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdcTnoCRA9TVsSAnZWagAA55cP/RphWFgKiupMRFy1beYx\neyN0zvD4MSaP4E6MDANO6C7G5FfBkZI+iAzqRd9YFb+EqAdhpyO2m9vF2WFH\nnkyjGp5PC/f9UYZQURz01/4ZdR6AMsYbOs0Yhoi/4ryJGLog3U5V5faT1ocM\n105Mnd1IUiSqAfIUv7Tsk+qRmK+WQBUG8lH+lYyCYF9J5615J+mRfFVGspyh\nImcDbUhVkfGxWFThSY9SkqRp9u4iYK53ST3h7XOQulU4VRDXodTyAoSjru6Z\nL6jRwDpS6pcV2lOSGcd67slkcWqjK6tZ7O7sm73BiLZfBAI4ZXdeV4gp6obr\nGzwJh9i06uorG7aPSNftSadEFEdnvcKdP6BhlUoKfpI85dOLAWLqw6lLOXFJ\ncWn7NT0IKAoc7d9BQ+8OjObCMlKMiPpuGIKJmZcfeaP6tGW+1kLSJLeCJTaW\ngt1BFMTOuRcQ45+8rRWSwnQHqbO2+VlPYYfhXx8V8piArhyHiCu5z1VEy61W\nfv2dLZZkWnMb5A70d7uBy/S1Meny0S+kRhAxGoTx6DloLjMIPr919s6VP8FR\nmCJg8ImIqXXimxKvDB1j/fNSeJ+d+lghI6Z2M7IkdWG757zkBYHcFpLJs0SD\nWJmrZnlR1AzxjCbFWdhS3f8R7CL17oTxVprtIKLccQ3rBEotmPoNhl1G+QGu\nJLh+\r\n=s2i9\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEMCIAofrIGBdTUjNUCJ9XHUNLODjS50TbdEUjbFzX4O7PA0Ah8aOfab8ECHO14J8YuDAjEC4+ytjzvVBZBhvtKW/snR"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.66d82db.0_1567701479773_0.3568290189949863"},"_hasShrinkwrap":false},"3.0.5":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"3.0.5","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"6.0.3","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"2.0.5","fusion-test-utils":"2.0.5","fusion-tokens":"2.0.5","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"2.0.5","fusion-tokens":"2.0.5"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-3.0.5.tgz","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@3.0.5","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-41tpKoXuoXIOvKqlVWOn0KJNvQkjiwQeJ12gIdi8SaX0jK2PvfhbSgHFJUbftNHLECG9h4CbM2FBw1uMsCJExA==","shasum":"7bd1dea91a49cb560ec8cf30018dae04131aa514","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-3.0.5.tgz","fileCount":18,"unpackedSize":32758,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdcWyBCRA9TVsSAnZWagAAQUoQAJ4xFP0CGcJqigttiubP\n7Fq44LdxZCITp/aJB5NRCvMJ0ejBJsuYAksvBGezJAtAIcBb/t/TE0ZY+5Tx\nmsiQL0XhgjiwVdg+HYceyEfGhjsm9HDVdjQfsmzVZ5y/C4kSO02ocBVOqGSY\nNPEEhOu9XAU+ZNKdxg8jD28HB8XRvB2ocHAUn+xUScQj5atbCAAQn56g5bY0\ncc2zIiSHpItax5juLkZ0ZaftsHrZfzOwoZ4R7Oh7oiCfQwRqWGF9dnVfRKEk\n0nKuX9MnVDeB2o5s5xmfIQOSxP48JAm43aqssoClr7p8SU9wz9SmywmQVW2p\nDa4zUDniUKpQPiNzn30VDY9cGrL7/l3R280vizNSy5Ws91agpKMyxm0t5nXS\naGRD3cGM2OjCHrFofRtmJU+jWux9M+WxVJOvjVxK3tsfrvNy9hWgiDL0iz4N\nTldDGbtKFFxPwCRwf/qgB95Ljn9pWKi4xtCojxh8p7YSeLMJht5UkTvm7PoN\ndQCAU98/jbrJIZyv0c+XtJFXzsBbOVgzBfzPGkduDR1ByNh8+aIy//7WLqlz\nZ4uwdmT+GP2JkrIEemsyU2TUdzXCmroGGUE//bw7km/I4by/ufW+Dedlnn+g\nAmIWMmP5JAt6FegugOPpgQjapfBgPI9Ohx2seFT+3Em0VpkAxfUdTwF/5VYe\nStvW\r\n=1PzL\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCICI/QRRwH2Z5MtfNmIYJEKbciLykbn584B7cfryb1OUgAiAq1V/CdVosfLoHBwX0d2cwUGbrB6eSgHrwltxQe2+vhg=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_3.0.5_1567714433283_0.10336948700678406"},"_hasShrinkwrap":false},"0.0.0-canary.413f404.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.413f404.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"6.0.3","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.413f404.0","fusion-test-utils":"0.0.0-canary.413f404.0","fusion-tokens":"0.0.0-canary.413f404.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.413f404.0","fusion-tokens":"0.0.0-canary.413f404.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.413f404.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.413f404.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-4AFjIeDfSyvxrymDJnPDzhGwZzho6jAzyfvK0pba4im7Y/C49KqZoFqMZfUnhYYPVqTz/hmGniRCGCYBh1rvNQ==","shasum":"427d9dab0578645fe29b1beca93e1e21e013f2dc","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.413f404.0.tgz","fileCount":11,"unpackedSize":17024,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdf9ZiCRA9TVsSAnZWagAApr0P/3TOJfXLlSjKNDmxg4M+\nNofcFSPUAqi+qt/FqQYq8jDX1MCcK3P5MO0OyB1eE36PfvhE8Nvf+uQ7uV/r\nyPOcQ5w4401bVkzoNDO7kiA54dXJpYXhTxtQFlGaW5LftRPJG0fkXkUxthFN\nDRt8SLqPtSh1FWm+SoQJOSfnJXvipHAv0C3reALMPXqmo4ltwvVTccVnqOYs\njS00NVm3KKlkjjSPqog5LK/KX3YdFCE/kRyxUjxbjibPgoNnVEJvaMrYbTDW\n91WNOfjaw3j3r1doBR0DCO2Fb0A+Jzb7lZXjil8nyDsC4QITabmfhpNRI+Mp\nrNfGotLaoTWNLOM1zGKJhxHsZ66IFdNnxFSrrpullMO38QJKVtsmwcQmOfDH\nPSCV1KC7r5O2ABIxCvRGXRetrXa2X71optlUWv2Ejloo9kiiy6uS9uxG6nS7\nsjnILR8ufFs5tqLzW6c9/U2Z9EDiFE6mQ/hg4G8m19/wTjVRKSKkvsdczOaq\n62wrtCeXfSX3zVeZssu77AC03H1d4+nsDncfcioDVkX+A2FGPvaRQ5jm4OeY\nfBnp1kG2JAGBTcMpHTGSHj+9t7jAyepHGK/XOA1eIWj6ccPPiQdZK0+gViur\nwoMwOEY44y0zR70QRA9/ykFPledev4Ccs+1ZcxuJEMdjCqgj9L+MDcayzWBb\nU+yV\r\n=TziT\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIBZVomVHQGp9GVDM4hs7UqPAalJxPyEeCr/RHSEffJzSAiAoV9juNGkKelWaPCcP1dTDhJ+8+W3eaIMSelp1pDtAKg=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.413f404.0_1568659041924_0.5060504494209916"},"_hasShrinkwrap":false},"0.0.0-canary.c0ad947.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.c0ad947.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"6.0.3","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.c0ad947.0","fusion-test-utils":"0.0.0-canary.c0ad947.0","fusion-tokens":"0.0.0-canary.c0ad947.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.c0ad947.0","fusion-tokens":"0.0.0-canary.c0ad947.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.c0ad947.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.c0ad947.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-3ko8hVir0pw28AUhv3rEBLKJ9QfLYBsT0W2kCfSJBaEbI7ohHM5B19GH/jlxI+jFuem+vgNAgYHpO2s6ks5Zbg==","shasum":"c9611d2ed336cc67712ce1e0e42ce9b959302d29","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.c0ad947.0.tgz","fileCount":11,"unpackedSize":17024,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdf/EXCRA9TVsSAnZWagAAggAP/R6g12vWjEXiArO9jsC7\nMGWQZ2vnrBYC7MOd/Y22ROmQOicpCQj9zxnvjPAG0j0e+9JG24FW/WgbxToo\nKL2JfCCPWgF0EEtZkXp64wNuZYvHArzaS//k/5ZKGMQBr1XDghCf93XciDwp\nTZ0hL/2058z/WCD+BDVHGixj5bnqoU4aX3GQwC31NulJ6UnLhV2HBKf4liLc\ninUrZUeyK8cfNXfYI7UMKBlxuE4TGOkcF8n90JhUQlJT1UMRIdxsQd/+JJXR\nelMl9zBHcOKYJ5vXUArUUwCA8t+RNb5BIFHoS0YY9TaxVPb7arMSt+JJr9y7\nzIJgouZuK5uKPfVPzTbtr6Cf9JdLZsT38la3atVJq6GST/ZWR+0PkmH1po8A\nBaNbfI+xQWwBjASH4GRixDDPa4L98jPxdRFUTsHREz7muFmhy1/zeZlXGmAH\nweDS0Mf9wSt28G2hgLThDKUvDjz6WPN4fpZi00IxohRjBpw074+qdn0oUxBI\nZixDnatbB/IvZz54LyjiHbJeOYMG+TDr0zjw6vM3hEBYi3fdWwev346VKVop\nDNAjJmUwLhkU1VREJTYhy00js9b1Bxnehkx6G8eH8QEv0p9Me731qnSMkcWC\ncRaar+7vLXPNBhtvyh3cGh48hMfd07oPQbJAVV4sMChvFdH1BT5BZDxRolaH\nkGNE\r\n=Z4w4\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIG/v6KHSzZrmIVzQn5FzIktX59gqRSKbP2icyAoNJaW2AiBbrGIRz74Bt2OGYoRxIYo0N48gvKf5E6/ExacmQ+iEJw=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.c0ad947.0_1568665878552_0.9694718339963135"},"_hasShrinkwrap":false},"0.0.0-canary.08011c5.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.08011c5.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"6.0.3","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.08011c5.0","fusion-test-utils":"0.0.0-canary.08011c5.0","fusion-tokens":"0.0.0-canary.08011c5.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.08011c5.0","fusion-tokens":"0.0.0-canary.08011c5.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.08011c5.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.08011c5.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-ZhDskExnZTQUUyxkUoLIvPonRuvXypMBC8EqZ5J1fdMfxu5gsOk6WMXwbFBpavnDRn92yo+DFOXAhTGcpSNDEA==","shasum":"4ca12a79c8198d4a26c3163cfd4359ad3d1f25bb","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.08011c5.0.tgz","fileCount":11,"unpackedSize":17024,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdf/a2CRA9TVsSAnZWagAAfOsP/1OBPAy1ZltyIVgAvRFw\n83553o1xhqVzVqv8iUGRWdRH7End0hdP+oIndH644TDOwPhqFI0n1XvKeuvF\nOcnz7Ic0998RvOSji9x9TEkh9feKedibaKuD7uQUvqrf51fcFvnF/4GKiNOQ\npaF5bBGzhrJuWrwG2ULVEI9PBeEKAMFlII802RwdSbD52UIrS/5qyXnbzurU\nQl1clWfCA2COy5QXShXHfLkgPzjNxBqEgfTG3uGrwSMWUcL02Q2RnmLCr3NU\nE+jMukaoqR3HPGP9Tjd86PlbiGkQQEOU5SjmjmDIVQOuU7uE6jZi6cmny+j7\nWswPFAn4x5zgMBYo1Tx0GvMkf7OIsTvdHO5T5tmfQ9qxq+H1cvQJFhK9ahNb\nHoj2r1UwRVnDvLwngRwd7zV2tZgqmeqvivV2R/TYfXG46KT+r+jYyfCk/dKU\nKgOtfaJkdvjJkJTxovl4c2G8AHk5pssFAZ+KxOhNP0m0gZZ7HcFVxgheVRNF\n/IitAN6q8xGktzmhbX7I7ZSYPhuavtt4oTStSwcCyDg0H/e0eJLSqORAEzUY\nUqTG0PRhKydBtyR8DsXT/1zPW5XktOgC/uRH6TgXhQoAYsXzsGD4DviopTeB\nFoCUbbsxr/rCPosqXgj3UJBxHw7TupMcuLkU1KeOxMZQaQdRJTrN33TbcPsI\nQTtA\r\n=fezR\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCID1DE1//0xVVnMnGU7VlyPavOS3QDdtnoJMRfHMctRTZAiEAnuS+ulm+HurUSzgdtulSfkN8v39Og4jha1skcqZBNgc="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.08011c5.0_1568667317064_0.03402958155330804"},"_hasShrinkwrap":false},"0.0.0-canary.a27ac53.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.a27ac53.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"6.0.3","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.a27ac53.0","fusion-test-utils":"0.0.0-canary.a27ac53.0","fusion-tokens":"0.0.0-canary.a27ac53.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.a27ac53.0","fusion-tokens":"0.0.0-canary.a27ac53.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.a27ac53.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.a27ac53.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-d98rGqxAZVLl9OKGuIUblr8ZCpIDu+Ui0G9N5s/c5rQtZI1a0pCG+c5G5W3y4jyE8R2fRAq2DJDpIlOxTP9mxw==","shasum":"065f871853fa0a58f66552eaf76e0f66597cef4e","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.a27ac53.0.tgz","fileCount":11,"unpackedSize":17024,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdgAsWCRA9TVsSAnZWagAAde4P/Azny9caZx2j9/xML5yz\nZC7KT+Z/ljmOIMq1Zs3QFvBxkap9XZHr4E8e02/lbnxo3TynM/+HLQdu919X\nkXozje4Zd0pHUUcj1QDMEKBOAWgvmALFvV8C+gyteDJmdbHKiN34vxIywzk4\nmz46Pbm74ydCjma7+a3kwJJc7P9vsnlvgtqg03rUlt++rZ6eCruMHJ5iIILA\nHiByPFqKRRGjODlP0XSpuhdyXuJxZqAPwlfUXJxAxvm2GU4cgfxMRiGBndD4\nMSdRkv/8Fl4kdIkYn9oO/itssV7YYBn/5C3esv/OkeONXtIp4V7W43L7mrfj\nwVSTIuNjNK9OuUp05wAuO8+iki+59VQQhwua4gCzIBynWy+ZCNiG+BczlwjJ\n5iUjMKlmWswgz5Wt+AARJkQ3QGVvAhps/A+lAandYwKOvmw4XqzGyqoKJDsw\n4tUdTAvK46HW7IXzrFpTC+wT68gHdIaciJjFlZuOpIQm1w8UjEUlbYvET0B3\nItP+L/SyjZK6GrBDltL0rj5e5S0g72NOyIQ51LHTVBe2bU7ucdRCB6E3hlDn\nHLZHaj2mfRmwpbxpIZCnDhcaAxKn/L24sDv6Q3JHptoZgTHgI1IQP6yb8JmL\nGgEM2TYQ93EmfR6AT6G/bQYl5S0OgPz6q8fQX5xbexHeUJd0tnEmzeBB4o7i\n6lQQ\r\n=GlU/\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDw7y1ISVoc2rkiMfbACm5+mGsfSUMYKzvVaAn6FYb0TgIgd2vCt110d8djRGGCMn+EQ/uLDeFQsK/ocZh3hx30f+U="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.a27ac53.0_1568672533490_0.4761615564834878"},"_hasShrinkwrap":false},"0.0.0-canary.ff793d9.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.ff793d9.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"6.0.3","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.ff793d9.0","fusion-test-utils":"0.0.0-canary.ff793d9.0","fusion-tokens":"0.0.0-canary.ff793d9.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.ff793d9.0","fusion-tokens":"0.0.0-canary.ff793d9.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.ff793d9.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.ff793d9.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-wn7Gl6ONs/AfaucsKe+IApFcPZrYO68mAvlTFki9mZRDVFa4+t8rONPaajCrkBakVIEsGnkdKTdH0KFT9/IJwA==","shasum":"45f8f4239586c153e479200612bfb67de3125256","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.ff793d9.0.tgz","fileCount":11,"unpackedSize":17024,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdgCOQCRA9TVsSAnZWagAAzK4P/i7h4eYX5E5O8D9Puc4Y\nnYcIqDq9kFoypfG9bKHhWaa5VZUtPTGZCwzk23VXzfWXBXh9mZ95ZuwD34su\n/T0QdelSuoomJlTCYeewRifG8v8/8OVnjwgMUUJW4+jC65KVb96zy7xgzRcs\n+LrCz18rDnq9g8aYJn6XoTEF/Cj6G1AE7wsJgEreVM3GuPEerwgSyLXNZodR\n9M2S9PZMsiXL58z6JyRoTMOc8ACyI0at6VfhuwbWcJKSr8H07j+JHd+lAswE\nRvZWGpPBKCV/0cxufc9enlwVNXwvQh5XmjwxIMFQtSDOltIrn5fPeLm8yZwA\nqY/ygS7xopeZY2kmPI1l6TLeV3LWtzf54tphJ8nJeeTjufAWfteRdlgnpSm8\n/EKwTwqtrbDaigYvjJq8gP/B6a6OwqkzhESA21D/KFyFlDRtW/axpZQ8eVhD\ncPqxdiFSjfLUW64Q8/Gm3ExkIx/uuv+MYv0C8GAjgIB5GjApGXa0O0DoZess\n6h/XQx2AHgyBc9F3WkymR9vo6xCqPNVzOKlFXWJazed+4i6UHOpGlQ9OVyOu\nd99JRj//Fw2VtKi87yg/o1zj0rV7HfCGfKW+1v4fch/PfzYebsBRhCogIqaM\nUKEfQq4Ky9DcfF3W8wELhfyY9yAsKzOYGRXu/Gs7AAP/qVkQQ87z+qOg4Umm\nLZbR\r\n=Sv/m\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCemeyg+gMIi9hVjRBc+YzryUC6tzm7cAfnUGQef5ArzgIgOichviGyB7VxoYuoenV3xJ30ijWrPGoaZkcyyu+wARw="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.ff793d9.0_1568678800368_0.7074084424058336"},"_hasShrinkwrap":false},"0.0.0-canary.2925a25.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.2925a25.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"6.0.3","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.2925a25.0","fusion-test-utils":"0.0.0-canary.2925a25.0","fusion-tokens":"0.0.0-canary.2925a25.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.2925a25.0","fusion-tokens":"0.0.0-canary.2925a25.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.2925a25.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.2925a25.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-uUlwkONmxdotzNwdk5FQaSkMrDd07adPX7iNUPutRaL7+P8pxiiwnUQ0TxcVnIp2wKhf3kwIb7KIXJHSbERPlQ==","shasum":"fab474a2297c81915fd5daac165eb56dd8786c67","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.2925a25.0.tgz","fileCount":11,"unpackedSize":17024,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdgbXHCRA9TVsSAnZWagAAWCIP/0D0PDX2OdfDqnIbtt8S\ndZKaF+S8pWbpSLCi1EnZvRt6QSVBY0nRPrWGvyrOoo94ZDjTFxx0VK7VljRr\nbrg13XkKsu4Y51AcY476Xj6RqQugp/eD3OZzJ+VcbXNVUNuX7ako+DDPxEVT\njt4xEq3m7CNviYtfMKx7Ys3csZQR+vrRCwPKn2e0lVvBGsL1oc4NJ8Rm4Ns2\nWRrKwN8ZrF3wrrzF0rFJVLHMDsbv4a5Fxxsp7+EYCU+YaOvmeML3ZyUBUhqt\n9phGgKYC+B9j/2utLlHoQQHjMpGPp1S1BpN5ZJu1M7IYjXmjGD9gZosBYBVU\nRIqNApnfjmH8iCCQBnFIkvAE9PlFa+QwteOqcZq1dsaRttQBI0W00WWAlbeL\n0q3p8a88XbilNa/PHKhyf3Pv4E5KkIU4WS5wIwcOKFeMZ+TH1njNowTkRovi\nasyUmB52rAriXFz3lB/bIc+2yFSYoFVsn11ztW6r8979KSyHEPqH+uCgKLhD\nWyGFMixEi8PYZFdmUiZDwuxj4ogkn+T4kLJ76dDNKNWUhMbZON3Y9bTzLbJZ\n882SU6Sm4MjCT/Gf+IWfxFt1RMoFA0oWxfAYw3XW6MusF/WWcSbl+glZpOhT\nRZV6MzGvlpabZhLOHimBdh+bdE/q2I6mwWlkb76BQaR4dKxGE/0JpAnTp2vq\nDzJp\r\n=iAGV\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIH63XsfqE9/dxtk+0J28yH8hEjybtao3yrug+DDLXAZtAiEAliuEUZ8U0RhEfVQCpZZ5vr/mwunRQNIhG/Dtxr+7omw="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.2925a25.0_1568781766620_0.8032324397465083"},"_hasShrinkwrap":false},"0.0.0-canary.49d4d79.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.49d4d79.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.49d4d79.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.49d4d79.0","fusion-test-utils":"0.0.0-canary.49d4d79.0","fusion-tokens":"0.0.0-canary.49d4d79.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.49d4d79.0","fusion-tokens":"0.0.0-canary.49d4d79.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.49d4d79.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.49d4d79.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-pXnGdLK8hQW6jzBqHinNki5bO6ABkILY2gvb4ciC5RcnpzW7DHNpQkNfsR1eQfdcLnsDxvu95Z1O2E25U1Ynjg==","shasum":"d9b8c1c9dab53b36696b744fad01bf1832ff596a","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.49d4d79.0.tgz","fileCount":18,"unpackedSize":32877,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdhAgzCRA9TVsSAnZWagAA/j0P/jhdWYqbWbbABMKUpGRY\nuLfTTm1Ptzx66DhF57H1NDrpiMdtiHRXCi6so0G2ZRGs0alCG/eKESDOYFMk\nWc7GmwVtEvq+OVJr05HhRwx95rlvLBwj3diAQ9xzBzZiVlpmmQwK2PxR9G2O\nDO3MolUCOqh7iXFnkF3By7W+FOBzj+GWY5C7+1Fl/a555puOXG/YRKrqacUG\nFOS9hSn7lt61hygMVK2pfEckPeHtu6j7k+tpqFMhwm6qBfexxgJJHm5yIOlm\nE4PxENGFndxfEWUCFXZhjO+8kMP8Z6ikPbPWZ/FHtiASwKy5lZZE225NlpxD\nxsrLV7Y/gMi6HTKY7S20mAkRl8CqyZkdL3UoyvEEtpeOxx7AG0l5WlAMCCV+\nU4OSEzFtD70FVuDWJJmZqRQynbWw5bMZGz7pnG5/BnfYMVOQ2U/GmBs/cRKR\nHgADroCtmAXXIDxcXLOnjRzExw+H5aSXbkzfCsfD7f2j3pYgJyVlIyPLZZ9/\nJi0CcMMpC7OEYCwTeMJJajObdo8ppqxN03ceIgHkSZK7xrqCOGWrPWPT84lM\nzsIpeZS5JY853BF5tWwdnAzS5qGcoO0L+Ru606h/hPyhBmwY9fhdLyShQ34E\n8BqDaXXXCdMYi3kAmnmaDXDTyMWhN5sxDkYVgOX5kwWV05aqAHw2qI1X5z5q\nCMs4\r\n=x8Eq\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIC0kayMxPO6oCmguzqwqcGVFFrfp4ggq86DifdaUgAyKAiEAhT/bperpVxZ6fW9CI7Sf8mLza12wUutDfA4DOl//H+Y="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.49d4d79.0_1568933939025_0.45428988875186205"},"_hasShrinkwrap":false},"0.0.0-canary.d4b0b6c.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.d4b0b6c.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.d4b0b6c.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.d4b0b6c.0","fusion-test-utils":"0.0.0-canary.d4b0b6c.0","fusion-tokens":"0.0.0-canary.d4b0b6c.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.d4b0b6c.0","fusion-tokens":"0.0.0-canary.d4b0b6c.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.d4b0b6c.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.d4b0b6c.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-U+Z1uQYqUO6W6EC9b7xCM8F1bZcRX4OeiqlgJ6qqBmwN26ugut87TOAfnlVtfBJegnEvLJ0cQBp/D0SInhxxPw==","shasum":"cf5be89868605fdb20b5ba00573694da6582c09a","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.d4b0b6c.0.tgz","fileCount":18,"unpackedSize":32877,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdhBNhCRA9TVsSAnZWagAAuR8P/2qaVyxmDpfmRROnpQUm\n636Ceyc1gQjJLPnblx8LrQ3ExD4cOSxT9NcCdKTOaq5PQ3tLtGmRigc4aW8y\nZaaaAoSHbuBv3fgdowMLpe9s9vKeNLEY75p2upfVeZ5iyDxjS3JcuppW33g8\nC4/TFN3URzY6o2nfnn0Z9keSQYw3YNDUrdUycyinFXY+t2dZB2wvDe8g/otP\ndv9syukLn4ielP9DnoJF8nuSAqfB3ldeobbl+SpCSHDr7RIQzygyz6f5XsRN\nyMdmL7xK8nrgBVyR4LHJSwDCkBPxpecvWPA52i88fyqLdvgYmQTVRV6tHIsP\neWXvjB9g138N07RYpMbVhk7QpdgAhnB7n0lv8T8z4b9s6nShlZ8wgmhzXvli\nPLqOF6B2zHekt56RGDZ/hhE4wR1sN5QJsc6tHDa+9NQELNrL2egXRPCoWNxP\nsPsz/X2YIibXhomMVXz5LBSTO4ubMaDg00n+sV/nyHoCzRQDMsPDL5thJmUb\nnAZwUUXusiydN1BmfJI3nsYN+Y5oFvc8Hk3TeullM0R0Cr3G4XqRepCoS0nr\nRYbigRnEPIfum1JpIczXNC7yY97gj9UfPquFjd00p3Gvioz+xpmDfmFb6D07\nimpEfIZKsN0gMo8Or2t78nhCO0YgH5iZ9j2Q7ISdud/HvBy8a040oshttRdX\nJrwc\r\n=tBsY\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQClQYqkq9r6CLSaflU3rhXCTmPqCAF/6NCUA35JxCYpRAIgXUeVSRB+hK9QpIX4UunLAdohFUZJmNPcFJrHfYtdSzk="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.d4b0b6c.0_1568936800744_0.5255536777481018"},"_hasShrinkwrap":false},"0.0.0-canary.5be6a00.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.5be6a00.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.5be6a00.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.5be6a00.0","fusion-test-utils":"0.0.0-canary.5be6a00.0","fusion-tokens":"0.0.0-canary.5be6a00.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.5be6a00.0","fusion-tokens":"0.0.0-canary.5be6a00.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.5be6a00.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.5be6a00.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-q9DAeF682HNWZG6oWm6OmOQT7nPmTPr3yRxsYSemHrwesimQOeO73dIZLKE9+hoUxmaZXZivaNI5vBRa9AMBRQ==","shasum":"6ff2e42b1c4702f5809081ae0ca9aed67f275585","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.5be6a00.0.tgz","fileCount":18,"unpackedSize":32877,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdhB0QCRA9TVsSAnZWagAA7zAP/RO7Y0v1in0lL0g/8Mwj\ndLqk+OUtUGAUJM3aA7iB/YUqOSEpX4HgBFPTjlmWpdLpXqYDXRfywm81RTKh\nkfCwXgsb+MM+ZvBRropzohjFhAJQc83/QzAqQh/JIKlGyPu2lfpHm7AGuxYp\nIcACkhfi6vWFDYmv8LD4Jr6EfAyHX9GXyHguHmHlSjngP3iUKB5vl0aUZK0a\niQrQidHMXnLpGnpSvP9wVK9QPA2jLK4wHBgKNWtyXKJm0ZACkjZlDiadavyQ\n9syrAeQLKsmSQaOe4meALK2gykynrxwhdlNucrxBeRgwvGOU7ybSEZ8gdZJa\ndQY04pZkgMmNvRdnS6fTl3wIx+s4yvZ0meD63RfHt2BTREqRVEr9XRessgZf\nDZMALtQDqcMKm3Va54/yxH7ZGHlf/n4Ct/yoz/t4JtmuMrVguN8qsD3GEWE9\ndRj7Hs0qzD6h4fm8tv3kmBj/ZZRbrdcoK84AngwDi7Z18Jb31ToyM8ADTwQp\nsyg4BI8tKTsPgRwT/0Mnyq7qps7a/TYO3zFeRytonn+8yPA+wr6LtOl4PIW9\nTYoQW7wsS8oiFnvUdBK8SeZ67RFq1DUBqppSQXaJ31iO+8dEgjtzKEDQ0n+3\nNC4m9uduIoajP2eeMfYNKCyv916cPLzCh6bTMgAhD4Ft3DEuRyjSo8obZNao\nl/ZX\r\n=dbgw\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIHL9YAa7zUDo3WzYFwhT3sdblVwSYMxMIkNaimb0VyrtAiEAhwVMhxCodn+IeAuXo3Ez1tug+bFBx2Ao6vCJ/YINCwQ="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.5be6a00.0_1568939280071_0.9681427944626997"},"_hasShrinkwrap":false},"0.0.0-canary.dd07585.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.dd07585.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.dd07585.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.dd07585.0","fusion-test-utils":"0.0.0-canary.dd07585.0","fusion-tokens":"0.0.0-canary.dd07585.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.dd07585.0","fusion-tokens":"0.0.0-canary.dd07585.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.dd07585.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.dd07585.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-+5siRo8K2GWa70KGvrJxitEzEfJ4gS+dfiVP042fJbF+5AhYAI2UYVPe5ziBGfOYBdFBnsjO7ZpHqjw7EEBnTg==","shasum":"99218785b5fe1df93e48c27f16cc0d9294e52106","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.dd07585.0.tgz","fileCount":18,"unpackedSize":32877,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdhCahCRA9TVsSAnZWagAALeAQAKGAif4b2m6/94IrH+mN\nL+moMswcvDExyLnIKKdUV+d/JUOFq6IsgCHHv4wgl3y/YW+oiaVjKXXHg0zC\npgQuVLzKTrjahjaHcOlCGSVQHCkJinDTF0MUVFk+bI0IT0xi8IfH4HxTn/tV\nUjm57qzbvXKjPE5nkfkRfhFvhS4/qcBpZcgxAz2sbI/Zm3vhxklpfPIOimpU\n5QeI8JzET+jj1Di/AqPNFOMJJcQFGgpKSnOg1UTuEu2i0Rg/2JkM2JxFQctG\nPh+6f4ZNbv0ela9ZspdxENcMdD6QcpnmXNqrx12MT/FP/bR4n4pJLys/Jnti\nP+caH6vvLdBLDaaUaTSMDzk0bdFD3nb+AasGHzee0T1a4z2yB2i25DXVxXdK\nYrCX4MUGeqBd34mvw5y+cVaeTHD49rfJQMpuCTKLw4PT81mC+epslCwa40vV\nflIMOozu+UjU1on6glZopON4L1B0ytHryTjYZs+0ZE2gdhxfospzBbf1xve7\nSiv/E4DrSjFxPejt1/dHbzFzJ0XldpIw59Ulotsgs5/36mXyjrgmejYUCuX/\nl9F2Rt62QilaYT94gycHEw/oWEP9ID/f+jpW2BjJW9N/HqoI4ByzhgEmbQdL\n5rVeRTKW3noQQTuK741nn6uIRPfMtD8FU1+9IBqbKPCAe+eOuBO55cHd3cRq\n8qiB\r\n=kNEV\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCICq2hps0INQlFaj9hK7onB0FviyFzASBQnUr3qicuNAgAiEA3e9gCR3rGqFA2TKt4rbThvJacXWXhWIDZytZxbLlRi0="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.dd07585.0_1568941728655_0.1266645208046493"},"_hasShrinkwrap":false},"0.0.0-canary.22593cf.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.22593cf.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.22593cf.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.22593cf.0","fusion-test-utils":"0.0.0-canary.22593cf.0","fusion-tokens":"0.0.0-canary.22593cf.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.22593cf.0","fusion-tokens":"0.0.0-canary.22593cf.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.22593cf.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.22593cf.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-ks/f3F8+awR0PDE5mNPbqKJOGUIeNCyO3JOQV17KroFrgibgvdKfs+7f83pHMD101/Pf8wmRdVR1vlkLHeM/Uw==","shasum":"5db1ebcdcf8075488f2eddc2317f777f64090283","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.22593cf.0.tgz","fileCount":18,"unpackedSize":32877,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdhCgtCRA9TVsSAnZWagAAqYwQAJrnXDMUji28ovXeS/Sh\n7rzcMDnx15/TG1ARxK4Fm9wscgA7p5yNgRPcE9LkugIW33osfTz1MIZE9v7I\nY/zY9DbBAYFBPODp1vCirYjr43Jhebu4qZr66GaBQiLBc4eZzmbZKqUibNSZ\niIAdR7dmG5SOuJX6A5nSXlzAYCFgnlDebXx+XV6o0JYxkoAela7iusHyP38K\nmxXxC7TMcDAFtPZYDxzMCLop7SZ+eRIyq5gxJpSLtYxTPJ6jI4X2oF/7imcX\nMYmyeyzzUSL7tXC2ietfvw8onH7WgxTZsIvMz+qF+mWhz/CDB4UXdFG9cTMW\nzccJk1qjXjIQncf/1/Acky3BQQnpi8a9Vq/AiHrh+OxwJSmVdycVJhMZcKQg\nYmbSmNMekddeyFN3TGnQtHuI7htjqpCjJooJxapf52aDp/Md7j1MntEGscSI\n18335GpvSm5jxuRi2bCHB78w0N9oeVb6fRtaf9BzMJDYRYc/nAjoLnoHvwSM\niLCet227d/4UPHzDjSdZJPov8gvXEFbcNyebO4U4gtum8EHWVpnUaJi1T/oY\nItGxx3zjuqhl6I/SX+Rlx2IhO6zRFHKgGdaffCfz/dthenoGkFGbSSjlDmle\nDDDN6+QpNgvVLF4Bh4sV9YjyUM2GUR8uoXNMdCTPG6rvwWGl6/GqJ52YJMwZ\npAqb\r\n=JNph\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCICj+vbgSd31f/QpTL5QySxCDQUjGFoxFrKnE7gdm6TR3AiEAjO8XL/qBNlBlUvIQXf9Hn9DvvOVz2PSqfjemoO0P8R0="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.22593cf.0_1568942124582_0.42862562450724506"},"_hasShrinkwrap":false},"0.0.0-canary.a911dd9.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.a911dd9.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"6.0.3","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.a911dd9.0","fusion-test-utils":"0.0.0-canary.a911dd9.0","fusion-tokens":"0.0.0-canary.a911dd9.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.a911dd9.0","fusion-tokens":"0.0.0-canary.a911dd9.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:public/fusion-plugin-csrf-protection/fusion-plugin-csrf-protection-0.0.0-canary.a911dd9.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.a911dd9.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-F6qwBRIgSP91bbDvIlrZRdzC/1cZMM2YFDiknyrvqtKgsIy3pARtET7Xps2nmf6jbEp6V9QtsxpZdwxTBmHi3g==","shasum":"f4b979d9656c11d6b2c235a0b03f51c24d81d036","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.a911dd9.0.tgz","fileCount":11,"unpackedSize":17024,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdhQpYCRA9TVsSAnZWagAA4NoP+wcUxt6Fgr8AQQWA4eXU\nhx56oYKkVMvuPY/3YyzK/pHbD0b3leKabh4fBRu3vvqY450GHIX9sH2WVR/n\nzhw9LUaZP+304pr35JxF2Rt7bVWxV6AnIjGNqi6NswQ3GAANsMDBrGrGkZ+x\nlxZnsRlHXuS4LDTvravCfuom1KtHiz2FC3aRrxQQ5moOcZL7px1U+X2+oF5b\nuCrgM2r0nToPKDvLMOfPk9hbdtPzEOLjsZW8CmwblGzrLPpK3CkkNkY/hc3m\n4C+/8+4D3Rlu/sn3Ak9WdLF74Cvn2tpzGenc+rBlZwdl6/IRJ9yNncFvTb61\nOF/g5vZz/LbSsG8qdO/rHgNwOuqPiyfTQJt8cVZXfBAZNaJanWcCf1xvY7Hc\ngzmxHxxaeBVx2yhxhoskerIGFLPHqnUG18kNQjuqPwrIrV92MA9inzo7ml2+\n6VmBRdd3Fqc8xh9bgxGJf/OFrzY87ePMVudbrBTPlxHHkKdEDFcacCBMtPBM\nQgCPpmw79+Ck3SfGqxxs5NcZ/0p+9dL4ZQVG1Jv07jF2LoLW/TXvgVNdZjvk\n/R+tYcOI2gObUYLoc4KLgbcIzBxob2O6LhWVgML5rVfDFLUUVeaa/U1fuESW\nx1CvLFRxZtgR5rIzCR+sdIujyMa891+myvS3voL6jeBnSr+w37FyTx618LEq\n5rSc\r\n=NKNk\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIFE9u1TwCmhND/mopaR8z5DdBjKFeHcScApcX7jSKXSBAiEAtEP6UpuQ9EAHw28XMBmf1rGXUg+yPDkEHbN6i+do5AM="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.a911dd9.0_1569000023867_0.8750101307445037"},"_hasShrinkwrap":false},"0.0.0-canary.67e33d8.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.67e33d8.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.67e33d8.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.67e33d8.0","fusion-test-utils":"0.0.0-canary.67e33d8.0","fusion-tokens":"0.0.0-canary.67e33d8.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.67e33d8.0","fusion-tokens":"0.0.0-canary.67e33d8.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.67e33d8.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.67e33d8.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-4qSw1+DAtdEjxlWMj5HjMVAFfWbUud4dOfgWJheV9paA+ci1jB3+UFL4xo71YbhdIVjsfxpeVrCankKRmYyWPw==","shasum":"1b3afe01ec3b4658ecce7a0265baf90303f17f79","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.67e33d8.0.tgz","fileCount":18,"unpackedSize":32877,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdhRrMCRA9TVsSAnZWagAAQOEP/3Cdr6ZOL2qjlIagrYha\n46Zlh9mGoEvlnEYokEtLpNG27rb8vGrLBNvyv/x8eVc94h2ifnUAuc8v8V6S\nn2mCa6GtdQk8TR3JMC+DlVA5nQAq5F/BlGgORYzbMNMfooQlfLsOpwQdZOON\nIO4+V0haLZ6VzDif9WJ2Zd4Tm7+Nut8mwZFVKoHGElWH6yyo3uEUy7/XAubP\n0hJuiBLlGLKW/+hSS9PiaGJYPEfUEF+bzlCyxuXQy9UOmi+/HTmhCfkr8jQN\n1htHYH/n1qqwFXlcvLQgT75mV1XybCaKk7ipqotJVvqjDZzOJB+DX9GKz/gD\n8JlPMgmVWGwly8GHKrhmsPQ5fwamh3stLD/enKrnAVVl6y6G+LqDH86u3ata\nqsIyhe6ShJFkEAosUQ4j2J6J+E2HdrCMrvEYLEgl59cBCAQSDjjpnBQZzvFb\nJss74fCsrrn6AquEIzJEs+MpCN06HfpxT99a282mUu1xo6J2GQdwY3UGsocC\nDY4gIXq7ya9sG+XN8OYKNMPEWcLBCv/92KxuDZmXL89kMhQg9B5PGyMoYoPR\n5H0yYK7zNQWKgkdD3BaWgNxtR5e4NGFOSsVegP9vgKs781ZPCBN3CeQXbvbS\nFV9REhAAcez5SrAJy+f5Q9GZKEsFFnitjE2pvgHDnrSs0wErjK/U/Xy9maIE\nDZQf\r\n=PDv5\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIDOQQGPqGEXzCOAL1xbTfZtnepFDeP5UMZINSQ+8giKpAiEAiUC7q/HeuOeY2+K/XZ1e96HC2Uh3vkelpVHTFnHgYt4="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.67e33d8.0_1569004235649_0.9896275984156275"},"_hasShrinkwrap":false},"0.0.0-canary.d787a1d.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.d787a1d.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.d787a1d.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.d787a1d.0","fusion-test-utils":"0.0.0-canary.d787a1d.0","fusion-tokens":"0.0.0-canary.d787a1d.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.d787a1d.0","fusion-tokens":"0.0.0-canary.d787a1d.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.d787a1d.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.d787a1d.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-bH6AttNYuaiho2BRT+5Z9wKDiKgb4FyScgAppSg8YC3noypO9IgNK9S1fC7Zm3pI3Tc2l4Gj2inyfj/na7Zqvg==","shasum":"1bad30fa01745c0f80a0e119a6a12edc47a444b7","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.d787a1d.0.tgz","fileCount":18,"unpackedSize":32877,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdiR3cCRA9TVsSAnZWagAA4woP/0InNOWEBRAxT3hjZiih\n/pddCaleI5B9zBfDfyierAnh6Dzjj3PbbYcVRpTHzDBJtJHiJrhZINlwlGjL\nT4hJ5e3j0gRcc4dMLinmqZ/X2qpP2XbIqPyNvttO59iRx684iaa2jEo7FyAe\nyqDf63yHsR+HQXKrt5CwNsWDiBKHAwI201QKUriknK3qMgCt+Raag3YRbDFK\nBrT8xi90uej9qI03wFH+9mogUFt6PO7dSYMQRhS48dGOwNPbrPZsFy5HvUED\n738XBUUZMYPzu4kxXek/cB5uWPK5zibCFfmK/LIcWoIJheiHWvm7s2yX3vWE\n/3PjXk6PEoOj06GXIjqzzaau5bOj8E5nfXsR9MQgn34hMBTjeOjF4HghHfHj\nKxQZD+FYUMAR8SqBbadL1QoI+jYri1KKFBAWWAdymVhiZx7WKJXzNreX0amw\nWiNo80bjue6ZnHG7f+78OcPi3xC0YZoMsXx6910DhlX2TpJ+Kty1xXRDOAIO\nPxKQv334VvGYySkIRquNZ+C04fGkkv5NWkRAmso6S2QtaTAke/oign5uae7Y\nb+ATSt4FhcNaL7rxKJll4xkuTtlMfo8vNvJwy6ImnXIq6tsJyDYXzAJBhpXI\nzX8mee5e/JFq8a3ZZsa7dGIC4rEFJJzA+4B+Zp5SKrcKHi8bEf9QIyhhZSJL\nQzX4\r\n=wAUE\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCidkhRBDEdxNhyB7fNFDn6apGSqQUbpEF73Tc9qDQMcQIgHlWdfg+hWebRXG2Lfj7RV+RVeVpZolvh7rWQmrd0n10="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.d787a1d.0_1569267163752_0.061115461207712274"},"_hasShrinkwrap":false},"0.0.0-canary.a399454.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.a399454.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.a399454.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.a399454.0","fusion-test-utils":"0.0.0-canary.a399454.0","fusion-tokens":"0.0.0-canary.a399454.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.a399454.0","fusion-tokens":"0.0.0-canary.a399454.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.a399454.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.a399454.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-DX5+dR4LOEyzLUMydS5W1rg38fw1ID+TVS9BIO4djph3iXNhlraf0LNZGBbOzjyHB5tQ0DBeqCcsO13clahh1A==","shasum":"86e79f7a7cae02921ffc2c17f56176fd66e79d98","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.a399454.0.tgz","fileCount":18,"unpackedSize":32877,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdilPxCRA9TVsSAnZWagAAfLEQAIEKr2ocYtXJ4Lwy1Zj6\nVRJWDSDduW1007Ywk9A9c4uK+SFDu93fBA+BzA6PRJXxl9VeCFSsoffQmMWA\nZUk8wJaBXvTG3WPIg2mzCtFvV0dCqT3WaIzt6NOLFMIDra9JSIOwhlSOroGv\nXwqUjqsENqv9Ticvewt4/wap7Rai7gHMidilAgGrWEFHUtwFmCxlCatfhoH1\nymk1S/SvLcHUMEmHjraqRzqDI85Z4MiYt05rs+F5PiqAj1/BZ9YCBfj7Hygy\nSxoge2suXY6oU5KFQlC7YdiOzXOpfeqGDj5YuFrx7O5MEMhuEGMa3BBHzkpj\nc2usZ4qo4igWfzXgT4BDA871+9tMDSSAuA0152H+oujuNrzC6helYLZ6Qb2O\nfzYWXQ40LZOLd/7wlfBFbWRXZENHim1IAaihxU3W1dYHJSuekxKfzlpvlIWE\n/0EfIMzE6Vv+YgX5tORjYMSKFSXYo47Yx4YnDkymDbTP/roqJt7WsKyViVeE\neJbpt2t3/r12k3rhXG3BfEUnRTOM4vV6KwDfKSNuIxkFpcy2jx4JbottHTm8\ng+jEAA0RJOW4r7MaInVIzFmICnhjCbB5N3MqnAu4bD8bxWqR1AHIB9ctVgRQ\nGyjC3N3KO/o5QOn2SQqtrKmaEArATD63IA49GPG0Yy+8Rn3FLC6dKnbGVbWB\nUEuZ\r\n=fHcn\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCzTlnvAp/tQnBwtNXBq9l81TFCOqyI4naiVmtXehh7uQIgQ6+BQOxW5j+iy1uVfS7Wm4FHqXb+QbAv8vvmpoWKK0E="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.a399454.0_1569346545103_0.2514855317348186"},"_hasShrinkwrap":false},"3.0.6":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"3.0.6","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"6.0.4","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"2.0.6","fusion-test-utils":"2.0.6","fusion-tokens":"2.0.6","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"2.0.6","fusion-tokens":"2.0.6"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-3.0.6.tgz","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@3.0.6","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-yuOhEKnnAcu3/3ws/0OpR8ZyR0LhFvSaxvT/O9Wbif0adXtc2NZn07Pb9J4jz/AHnNxCJcivPkdQip9x+yGjQA==","shasum":"2c772f15d10828d0283f5f744cd96f7a233ab6e2","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-3.0.6.tgz","fileCount":18,"unpackedSize":32758,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdimKvCRA9TVsSAnZWagAAyNQP/j6o1X1JIwhK6HAwfIL3\nhHEuz5xwWH0oB1gpIYt1axUnRNCgBMag+tOGDfeO2fhGIH7FSK+vxtpei0Ns\nYkOOXYSfYGwIPRgg9B1ReMGIAQqjcwtebI5+4mmB5vmr0UIM4xJNo8MqfOSX\n+TaNfzHoO9ruEN82W3vZjZBhSVbmYJQCZU0AeWFyKVnkzerR4gwT1or98DR+\nK9hEgJnlY+EbOhm4/XK48wbvqDr9VojNb2nVykuVW0yDHN6Ib4dy0fYerfjV\nBTOmhLyZI71Wt2SwrdmGKL2P5JuKPTFD5hEQXO5XKRBTpVDOoaswmLXNrLoz\nrX7h2kfj9M4M3yyGzH6HqT76j0zYwyFqQQkcP4nkGwoq8CRdjyulcFCi3idq\n3SggdACJ0c5IF/2k5tf5GFKeEbynXl0CoKHTlJM6uMjMMT7K1uXuIj2cMVWu\n0lHMC6+ZJEDhwVBoYz+KpOQzCin7lFKLvzUzvQUJDfdZwl/ySrnYrCIiZuUb\njF5XcQ6YHb4XExCb47APc3j9GYhJ43ptyWfMwHEVaKyUDXGLamrJslDDpjmj\ns+tuq3VH0+QxgmIcYI/DWSXz5O4RRV6TFm92Zhxqm3WcWGkKp88+/Rd0dq6O\nOwfVHWBoS+PG6SngiRgPoh/7hLcgp9+WCznAo1MwlUBS9vEuD6r6u18hJbKQ\nwFWJ\r\n=Zxc8\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDl9Jiqs6IfYazpEnR5zMrGhBAeT+u/3qVcy+Q48AgdGgIgOmVOXUdNA4f+zNWb5KJ9AjJAi/FXQiGyf85z46FUrx0="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_3.0.6_1569350318436_0.658845475576785"},"_hasShrinkwrap":false},"0.0.0-canary.acb5af0.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.acb5af0.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"6.0.4","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.acb5af0.0","fusion-test-utils":"0.0.0-canary.acb5af0.0","fusion-tokens":"0.0.0-canary.acb5af0.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.acb5af0.0","fusion-tokens":"0.0.0-canary.acb5af0.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.acb5af0.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.acb5af0.0","_nodeVersion":"10.16.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-673EBx2KuL4s3OYekl7DrBDy+NiSxyn3TYF32F6jF/C6P3HKFajih3qEvZRBojXjhDJyNVQtQ1DrAfEXNs4Eyg==","shasum":"e44a6789125a72830cd9d431ed3da5a3a8970a3a","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.acb5af0.0.tgz","fileCount":18,"unpackedSize":32860,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdi9i/CRA9TVsSAnZWagAAn4gP/ifiA/Mti20oGR0VUb9T\nRRJP1Jt6Wu5R4vVW7/F5NQL/GfQHvtsrAayriUs985CFK33V242aYWWicYsR\neYip5NMmzxnkp2MOBcQ/KIBy9KLdAnp1RDxCpTOTP1lhwGZLofVb+YaEn+Qj\nqkhLb3xXd+bm/3G0ky5ObL3FyJChzZD9RBymbDRCa22RPK0DaMrdQkx/9bxU\nRSWFINCaiSuhfUG/jRzsylimjfC/BXKUoY6up1RjKo2oVgPnSubxxw4CgATd\nZ98ezbIrRYCAIThkptu9iDyZ54IVUtFiDpNwSBm5Ma6dZO9cgArIgA+g3QYr\nxgfLb+kfc08C151xaTvZ2g2CmmYALY/mdAyLWKtv46HTIQhFUZe+VXQRMPom\ngA/RwFqbyJcZk/wSZVpc8P8i4wvavdeyWyqEeNikjN/RHCJf3eRjxtFZ4lLP\ny7QfYXnDldGSz2Q6W8vn3XnUNcKAjpQc70ycn8ehzjyQjq3J4lFr7IhNs/Kp\nmDM12EkPZ9F9MiHbc+OKgM17VANntazlFlZbSXdiLXHQQq82liM3xq0CniAQ\naaCspiYm7jJ+DFRTXWvqoi2B35TkIESxCe6Lu0+y5PKuXBZDceOhO4l10dkL\nDb68Gsr9xLX8ZC5kXXT59rfAHfRSlowj+KWS+6h3v47vGO6ZOojNPFQmHsGS\nj7qj\r\n=kD9o\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIAnzD+GV87nG0Aw4S8RZLp1yj1DO8Iwc5SSWqPVvwbZ3AiAwLFFyldQGoBokBvySk+8m2+8M0luc+25295bvMO7JNg=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.acb5af0.0_1569446078598_0.005510147001417387"},"_hasShrinkwrap":false},"0.0.0-canary.d7c5910.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.d7c5910.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"6.0.4","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.d7c5910.0","fusion-test-utils":"0.0.0-canary.d7c5910.0","fusion-tokens":"0.0.0-canary.d7c5910.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.d7c5910.0","fusion-tokens":"0.0.0-canary.d7c5910.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.d7c5910.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.d7c5910.0","_nodeVersion":"10.16.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-FNMkhNLAkpPuCyPmJmOA3LJpVl6ZpXrRuGALBuEbCjKbKKtZdQwb7AfquTbS6ddY3THC4yOwyhj6NStSAyBJjA==","shasum":"72bb310445dc5966c79976879300a35dd5a5eb33","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.d7c5910.0.tgz","fileCount":18,"unpackedSize":32860,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdufZ/CRA9TVsSAnZWagAAehMP+wZRRtX3QYSWwdoJZJyx\nWb+PiJoBVX1HEyzsT3HCmCIR9Wa8JwPlqJLxnIv7H7QrxPA71yEwnWPaqUkM\nq1FSkWjlgMU7aGUFZdXW6WdTE/DWqlVk12pzvK3HdZsdCIXf859kkWxHTaO8\n3W1h1Jo6wXcEMa2DxnpnTQSR3IiN211tlzfZFUeywcAhIWNO90kl4FU4X0d8\nhv0FWBQeaprUg1cSKC35IJJlS8or+jerBtR6mLWS40PJPTPW8WQ3hto1mzCG\n4Nr2PDF7badloYFFgCtca6MCJinM8u+AuP/2MMOuojvml/K4A3LpvGE3olE3\nO02qDFHs9VAG+rsBAR4z5BLdQFlssk2EU/uNadcoHT/x6XTUrQf/pRI3EuMS\nSDAtnig2DvtbycbzTpbLwo9WqeqFcwUeg/UcUMBrUI1x8AlNgAngknHaaPEn\nwcKhiNUvTDjZaWc5+4xWJZfhJcXpnzE+VCsti+2El5oUSSlxa8MHPYaab4Z2\n+/7w9iHtTN/js34Fm8h78Lw+Gw1v/gZvtfDBZPLjX1xzTeAcB7amWpxl2Sts\nqZgjJTCcEUpKErv5cYuxLqOKCX4NFI52ieJk/8ducV7lGol4EV6anLx8gzgw\nw4ZAk4ZLNsS8Ob7INUqmzolP7+z32/9Le3wpzY5fQNHU4Rob5tTwzHBz++AC\n6yNL\r\n=s2ej\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIF0UaeP6xEFthNhgs9xuyvaqNYGDIhTC0AC+G77xWz1BAiEAkMKPd39JJFOwYOi4hkFgc1+OPP7Nw/8rY8oxkhEWO+w="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.d7c5910.0_1572468351389_0.7264982498870303"},"_hasShrinkwrap":false},"0.0.0-canary.f12f055.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.f12f055.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"6.0.4","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.f12f055.0","fusion-test-utils":"0.0.0-canary.f12f055.0","fusion-tokens":"0.0.0-canary.f12f055.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.f12f055.0","fusion-tokens":"0.0.0-canary.f12f055.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.f12f055.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.f12f055.0","_nodeVersion":"10.16.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-mtSRt5RAU7ijO+6/SUUUNFUu9pTsrFhmzZljaLh7WH9LTi0bpgETU99IX9xVLqOoSAtC5k6rS7l43OzLdxka4Q==","shasum":"d390ba22b763fa74d79c5a13558c2fb9880ae150","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.f12f055.0.tgz","fileCount":18,"unpackedSize":32860,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdugqKCRA9TVsSAnZWagAAXZsP/j+Ubj0dY5qmSmYsBgyO\na3hUK+VAIRVaxU3Zb2RqSRHNimX/DS+sGu8f9LHMwTcXlnypR2aAmetad4OT\nKQ6UWGx2d42hfFB7o1T3bAnDcPc9J6Siw1vxBE+hOWqAm1YbXuJAKHfjaHHC\nQiEZQN/xTVwK8GN7jz6Gm/4vL6PRe4Wfw3jZMvIs2mVm3H3I67oUEv1l3naO\nd5M0/0biDmZjMfnK/vqORwhpCiZAFp5U1l0nBR8J2U9q4MO7Efxj+DCyzrrg\nT32xPeMevrL67iJdbuG4p8nDNS7HUuLG8NWNSk9ionBWNOD5fRINz5UUmdsW\nJLkywk0yg10KV3DYaLe/nRsi7aIM5ZCdGMG1oYHg/IPRyTC2kMdeu6UP+eoE\nZ7BR/0H1nBOCGosJjYCEyNxsQgpxIIQf8GPNojYp3or15iV3a82j8f8P5gRS\nAX9CH7TWTTJBJui9AGldAmFk0Fb84btSptrRVxmtdjFg+UGKkpFFdBIF5bGD\nUpPFLWp5yIjHKhBcTsf5buAGyym+eOe+hTKD0kHLO5mP/KGlnDZWosQGcGVJ\n4fS0NffSvUgzfGcK0VWemoeSDn/t1bvZAooLnweWltbeeAVh/Vomk6/4uP88\ngTTA7S3h37maGGmOPxO3UJXXpMmYmLtqpkHzrmZfxz2u6GJ+XGF6mAH9prOG\n5bE4\r\n=nWY7\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIDQ4dEQC0C3JRKNfa+E+1rfeaXetaXiCEKttxUTQEbnTAiEArmzNXG0YVTtzOQmoj7WPFIj7ehrFn3soOHb5UtEqHxU="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.f12f055.0_1572473482520_0.33756101121322546"},"_hasShrinkwrap":false},"0.0.0-canary.0b935d0.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.0b935d0.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"6.0.4","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.0b935d0.0","fusion-test-utils":"0.0.0-canary.0b935d0.0","fusion-tokens":"0.0.0-canary.0b935d0.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.0b935d0.0","fusion-tokens":"0.0.0-canary.0b935d0.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.0b935d0.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.0b935d0.0","_nodeVersion":"10.16.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-fNTnlZKAKzhpCa5DKVVJ1WBC/u4IHiNZXSnVwYWtI6BWaFDP2FTgpFeMFpRq1Zp7aBGt8OAeo3ayaEmTluHMVA==","shasum":"7824ffd9dbaaafe29ed38135910fd60f53e4a1ae","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.0b935d0.0.tgz","fileCount":18,"unpackedSize":32860,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdugqdCRA9TVsSAnZWagAAVrcP+wcjxj0Ayk87w9bcClGw\nF2FvVNjjiyRMln6Jl7kaaL8Ahhgz0LlLqSXx3lea4Y2OSgw5Q1HFLMhYzeDN\nnrgk71BA9I5w7evKXmEiz4e+Jc/LbtwbZtT4/MjWXH0y6MHlcs0qLeKB5GS0\nL/zBD2yajb8eQLLHdgEDlbt6bsenvwQ1T0PMGsaB5QkZbcRtKWWgju3OJG+Z\n4Sgq9ieTR0p9o7eYM2cvPlkUwztwZ4bRRMneTmgC8GbSz7ZTiHec0B5Xhnp1\nRRDle4dsG8F9lnbdd7+PShP8RrOG2gWFOlUXhOvPzM8JLDdUQonwpv61kpOU\nCE2eio1guav6/Aw/E0ukuyPRYFETFKZGQlhq9AfRW0vQDDI5ZblofC1qtORA\nFnVxf6Fso5qp6AWPMFWTDIT4avFHOMAh+jmc4jHnfIwnC/KDmcgautr6I7Qn\nJodo+qwXtA/QPVp4RWKy6Uuh6JTfwtQsS2qYlS1SHMYIPtysDFL5aGWCVPu8\nkXx6hn8alMCccKm3tH+jJEITQaOuLOMHk2kpF6oLSnPJ8YhbiKXliNNmEbtY\nl7W5EBUJRnfR8u7TdtWtpRBPf7mLQHTyHMWnDerea6lU4iDSa/qL9AKV2Pz8\nR9MHVbP2QkaSjcCPTgsajmBWQBQck2dZH3dsJ/DlantngWQt1oPeuJ7/YqdZ\n3ATU\r\n=R5bc\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIA2aPXFmVQFqwk8/nrLVKoxjTsOCI0VDxNTiDqzjB/rbAiBRiEsSUlCA+Cs/MEWBuaALsifj8VbwBwQQOnlKxmLb3A=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.0b935d0.0_1572473501216_0.4008161636028684"},"_hasShrinkwrap":false},"0.0.0-canary.37af1b2.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.37af1b2.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"6.0.4","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.37af1b2.0","fusion-test-utils":"0.0.0-canary.37af1b2.0","fusion-tokens":"0.0.0-canary.37af1b2.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.37af1b2.0","fusion-tokens":"0.0.0-canary.37af1b2.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.37af1b2.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.37af1b2.0","_nodeVersion":"10.16.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-QMTXG1Igh0TZkDVeWkdNZpYT2PXkKYMyX7aBTRbRaQ4LgWB4WGz9OiZx23JEvfCXnIO8enylEiJRqqGEZLigrg==","shasum":"ce453226e547eae4b50c064ea54840072ee40fa4","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.37af1b2.0.tgz","fileCount":18,"unpackedSize":32860,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdwQhmCRA9TVsSAnZWagAAvHEP/0K7C9c8OlGh6bX2BwB1\npEEJEX4jl/hkdkPAtdWzVKK7ZHjycGmO5Yhci2epzHiYo7lD4D8mqW5n+QS/\ng4Xap1MsvrnsOR+1jNsnyIz5U0nEIZiDwFkkkVlnPNTZ49c265RAqPzeVM5U\nkWjA66/TzWkXfLNKPFQseujiivzPy8O73BqaM1ZjKzMbOOlPeh4tFxZm4ckX\n34qzcj0sfV/7Okp0a0BQlkr5upWfKI2x3jRQnxfngMC9H+FLjiuAbJhrdjaF\nhJaD6mBx837IQVLninunV8t8lTnJQqtIq4YWwQKH5Z4WsqjfX0HiIr7SosYr\nRs4O0BiRK+opmiugtFGtOxt/SruuVcw9ikQ4r1yoLr6x56RvFSFNYPq/3PK9\nS9gfiz/ACZoPk5J0OVANa2qSU9YQBuaQ5afQrADOoan0+UQijueAzIl1AZd8\nvEulw8Jadfdi5GaW1Z6CVNzkQKAHeU+XmqWy4GvNZufqLUbZViotibXNOHkf\nDF+xtH+jp6v46A+OFfPcfiW1dcNAMYELdGmpR0T1Ko/gqlUtVm8ZsvGPgxX1\ntLh3ZmVybu4b9otozM2wioZynKbH5hAOqgVbc17Dj+ccYS3i2NOI/v8heZBO\nrayfqExPnNVR4/mTA0vq/7on4j1OT4kia1qQHxktufZ3x8V31FeVd4LJpKjS\n/yTD\r\n=CfKO\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCGnvVT/UICoDHeKWME2Hn1ll90IfVNOyNHZ3TRNl/X+wIgBZun7voa5H5I85q4LwKqZZojX8MGjlaDx4GucDauENk="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.37af1b2.0_1572931685981_0.23127032481963994"},"_hasShrinkwrap":false},"0.0.0-canary.e3078c3.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.e3078c3.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"6.0.4","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.e3078c3.0","fusion-test-utils":"0.0.0-canary.e3078c3.0","fusion-tokens":"0.0.0-canary.e3078c3.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.e3078c3.0","fusion-tokens":"0.0.0-canary.e3078c3.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.e3078c3.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.e3078c3.0","_nodeVersion":"10.16.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-cd/aAGPNL/uyZnm8R08C7+orPlLgnv3B4+S6tsdbUnbw9tmZtTIcLQ/brkoew++jhgyauNTCO3odrj56PoWzRg==","shasum":"9f345725201a87e4c8ba5ac39343a96686db25d1","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.e3078c3.0.tgz","fileCount":18,"unpackedSize":32860,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdwel3CRA9TVsSAnZWagAASH8QAIasqy4tIfd0ZW2SnNrz\nN+iJiCFW32ZA/38MAg0RkKDdab454TDug5TjbAuQVkeXQUqI+y2DUUQ5LmQA\nfN3Z/b/7ux02QXRfmo0nnnWTD7vz9V3QNlCqZFVZzf8KUnw9kA3GR3qm9PBo\nQlALpxGqo1ib2tMVkNoN0M6tqzpk/ZaPBuZyHs3WUBXVCr+Da+9OqIUYTPhd\n4wbIJvrHlrusBik5ErUPxzH08Xz0jPAqvTcoEAyDpnLAZbvfvpBOJrfVhtzz\n/ccs43Wbo8QpdKgYWz/vPtu/t9uRqj1kYi2okoj3oZXmlfxeXd73U4UZ1WbD\nms0JVCUp7C5FkXfECEWKLVKcdDPd/I6K89F1EQZIFYtrsqXA4XCFvyZTxsiq\nFnLfJa8h7AZS6wlPnRDLqXfcFERCMhS7W+hjjCG+50cWk+CF/G73GxwRZcT2\nDuWrsLZRjzgUCqXZcRKlI82WTOog2YGZlz+SS9pizX0gkapnoanjRpiEUvU9\n7aJVsau4btc6g6u1eEVjchcphhNc8HMqdv/wrdhOmcxnKNgXuQW9ZitjiTMI\nMd5kr9kkOUGCduI7r/1akP1MM3gqkLnpILLNC5GDlbqKZZRVPILVe4G9GrB/\nxgHVZJ8qwlq7Whyu5o+I7JzNOOZmAaiSlC0gQa9KZSQf9q+B0Rl6YIdKMe/N\nVEZx\r\n=4eGT\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDz8hliXPUKeNTzs7OVp2JaqN6ICU5buQx0k+5b7NiGwgIgMJqL40YuJpCNP3aaY/Frrplu6IHLpJ8YSovXNUUIUjU="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.e3078c3.0_1572989302696_0.31567810969911814"},"_hasShrinkwrap":false},"0.0.0-canary.f8e4f0b.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.f8e4f0b.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"6.0.4","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.f8e4f0b.0","fusion-test-utils":"0.0.0-canary.f8e4f0b.0","fusion-tokens":"0.0.0-canary.f8e4f0b.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.f8e4f0b.0","fusion-tokens":"0.0.0-canary.f8e4f0b.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.f8e4f0b.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.f8e4f0b.0","_nodeVersion":"10.16.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-nQHUHrB8BTQrIrc4NJLloU6y6avumORV6ghFsvufD0CfG1ysA3kGusBAknUbxRqbs/EVt1Fb8RSTnZa4yjuqOQ==","shasum":"c0ca5281247bfc22296658b3ec6be890fbc8ff26","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.f8e4f0b.0.tgz","fileCount":18,"unpackedSize":32860,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdybNnCRA9TVsSAnZWagAAHlsP/jUCzZBe7hr8Aq32ikuK\nwZVhbxF8o4jAuWZIX5zkVlrcrNfAGv4LxoTc3CNvDp5xfU2ck/oXqcTD4MzD\nzfHWkgV81E2p1PxcFZ+VqNoccDzD1PaJF2WouCKuOxXyjknJqOWzy0riuvjE\n26sEzHkRlwYHeZvG66asYMaXUR8uzghbhY+Oqy31oB7sqablHpZ0NlMWEbao\nLtE6GAIRO3VzM6AeCcFj6Dl+j0GFMS2viJyYYT6GwvI0TfljbDMpF4AqZAqi\nK80E+uz8kYQPRHrERpKBuLB733FCCAAFd358nOhXBHk6K4nmTkD4R4qnOK+m\naj5X5RNlIExGc0lIF2sqZ9rXQ688BUYhg9randfDV7x0PCLGUQj8Km5aApI3\nJCnuHoBwWP3pKv222qBna/rdKrsKoKFp/22s6xqSHpR4YLcZerQQ7EjFl7NE\noBwnADNTjns0FfvaC932AcxWLgj1yGDXUJOSoch53H5YVzg5AGsGPHkDEIcc\nNnQqBQ/bcX0VyvXBLvvzPQkcrL/2uzcUxMFV9lUoOXLVhkuhjIIe4CYuovIT\nWITSWM31cBtlFuR96xbIH+P/LufypGgDT6e96DCwjc/lr9DE65/rtveUAmrK\nWP+tUtB+m6DKTkq/zZ3Kl5jWot3LVKnY9CGXbkwZcYTjVW2UvrhzmWd49l4L\nTVs1\r\n=JF7U\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIAUm8EqcWXAEdZoojxnKAR4lh2n2L6xALxpSh8qWV+TIAiA5ss+CpBV5j0bxindkrgbOJt14E2SXaP5XgiwTnexWkQ=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.f8e4f0b.0_1573499750741_0.8072296816088373"},"_hasShrinkwrap":false},"0.0.0-canary.0af264b.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.0af264b.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"6.0.4","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.0af264b.0","fusion-test-utils":"0.0.0-canary.0af264b.0","fusion-tokens":"0.0.0-canary.0af264b.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.0af264b.0","fusion-tokens":"0.0.0-canary.0af264b.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.0af264b.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.0af264b.0","_nodeVersion":"10.16.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-PTGK824kzNegCocCL+99c5QzDQjiAt6I3Ip5KKwvrt+Qk1RIaB6dYsqIiv7Z9CsogQizj3ObRCK4r7OD+qbChw==","shasum":"0ffa57e688f19727a6b0f0bd0dde2daaef59ba84","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.0af264b.0.tgz","fileCount":18,"unpackedSize":32860,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdyg2DCRA9TVsSAnZWagAAYkoP/Alb+vXud0jVW1Zcq24t\nwmLm5ezete4dvbpVMWbjPS2obi3Ptv+UXRUw84E7xzuCSgna2KsGRihW9hNI\nUI46hWrSoKE3Bz5UHCWhUbD4eJQMwR4zrYqOcE1IGEFcwnchQlX8NzZdc70f\nTCSNEtGrR7rbAHSAI7+sthY5yuAOMCQGQ0HSQ6cmjEI75iVBRXBU+QOOHHAG\nGF5etgbfbG0m/LtprIiao/vnlS0yidumbc2DAre7SC1FEsLK7ejGtir+XJ2c\n0jpK9KzFXVa4t6YCkDRC27ur2PnB3GtDQi6c5oI9OiA24TQQVVcCdOfsr7oH\nr3sKA4iMtnA/Va61sXCp2pjwvO+QYbc3+dEemK9No+cQ1ItUpDNG8lWbswlx\nvI0POlxdE/xV6rk1EIXQLwHXyBvjgOsWX8p9pNwmddRUKO5LEuLgSdTU1Qyo\nfs/P5fldx0i17f+LKcOCulqeXe/KHQGZSpDAN3beLvGK01sZ25kd7CwaHFP0\nfxLVZ8Ww3bGXW2hlkUyiu1dY49pLwEw6aMGa0eaoUjLrWsLEcCNfql2LQaUK\nnwvGbtiQjFcxk2OE/YyhR2ZLWf4eLeJcCiEZZvh1+IGijrZgH+r5Ow2uawvT\n0CTrExEMmlRolQaXiPUVVmcRxYF77EGcezcl1XuDZ0YubwHGm5CgMecpQn/l\ncicf\r\n=vWSc\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIGmKdkMjBK36Hv1PM3e4BuMzrSHvu6lwP4wUaR5cruujAiEA5NHrm1c53Hp1WIGYeCXS71sNP+C250oJpfNFjTQYOXs="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.0af264b.0_1573522818669_0.605153188885218"},"_hasShrinkwrap":false},"0.0.0-canary.78c977f.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.78c977f.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.78c977f.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.78c977f.0","fusion-test-utils":"0.0.0-canary.78c977f.0","fusion-tokens":"0.0.0-canary.78c977f.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.78c977f.0","fusion-tokens":"0.0.0-canary.78c977f.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.78c977f.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.78c977f.0","_nodeVersion":"10.16.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-5cI8M5KAAftbZAj7YJJVXt3MLixUkAetFwdcGHcxI5plaDsgdU7DzorXHFk38xAOd6+XT3tX7NJKCw6C1UpKOA==","shasum":"f93860e77e228c05692d44c1d85b0e21b8b3c2ea","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.78c977f.0.tgz","fileCount":18,"unpackedSize":32877,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdyvE2CRA9TVsSAnZWagAAYqsQAIjIfER79B3HOq9cs7r0\nAk2f1h7pW35ehUTMIkcWpMBiKEgSrD7Et7tYvLSppv408213atPVJgUUD2gs\nWZXtMmTBRgFGvoZp/yCZt2X0MK0viXhc85E04eMa0uehcejPPauTqzoE4NlK\nBghIS2B2VePrhLtSM1PRP5+Xyge+QZbIVqjsg3wbrhueFyC0iK09YEcqkUgn\nvTDVzFGut4e4fSdTPz4N5FS7qcuLuOytC8WF2daUTmHenzdmJFSnoCDyUV8o\n7zBjBF5OMYCzN/z3tZsV2yeMybMSwhCin69w12+vn3XuBI0699OhXiD2zmir\nKxUgq/9JIZfzRfjb8zSFAIt6WpSwH2Q5X67QEH7tdfV37xYRbzrq8irPgCa/\nPjvVlRMDQhqll2Ehb/vXn4smhcW1hq2gw4tSirGxCU3lZeYj4z597ozVeQr/\n2lZg1qCay8izJ8TupLWK85JOFFDIbvm5Fx1EO8RJc7xbIu/OyjKn+HiTKI/P\n7DtSCX8HabjP3uCQ+TNRGtq0VnWkqlhm3P38a76LHTSBgkp7chF8u9mGPAG8\nV9BS/282jC+Ru5hY1f+C+eUMs0cvdZpIl5y6ovjix0qpMKG+y7LyRsbox289\nAB+mxUp7xU+nN3ID5SZxKuYx+6wE8/ahwqsaL9q+pqE8dkVHOX7/+cnz/OVr\n4vn9\r\n=eUGq\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCICw2Tcrhg1aK5kxspKPphWn9AoIc6Odxk28eAq83Ejn5AiBLGoiavObxQYwGeG1eiA1G8S3CqV+oG/z1HswMQEt7cw=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.78c977f.0_1573581109461_0.8198986287386751"},"_hasShrinkwrap":false},"0.0.0-canary.0af264b.1":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.0af264b.1","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"6.0.4","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.102.0","fusion-core":"0.0.0-canary.0af264b.1","fusion-test-utils":"0.0.0-canary.0af264b.1","fusion-tokens":"0.0.0-canary.0af264b.1","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.0af264b.1","fusion-tokens":"0.0.0-canary.0af264b.1"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.0af264b.1.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.0af264b.1","_nodeVersion":"10.16.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-+5e2HL5/KPKfiCn4h39rh3Pk8mP/4P1f8hHdI83CBuxb//Y63KoS+N7ojoxMj5UNgZyCSVbHQLZpYM1lrFTZiQ==","shasum":"92ed28b47712f7a90b168a28f4741425cfd64f06","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.0af264b.1.tgz","fileCount":18,"unpackedSize":32860,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdyxWwCRA9TVsSAnZWagAAeVsP/21QpJPFb2xrFdSY1uBq\nb7XTPNFzbIMdctRLdT5aKfIghbp3pGlCHgqPfhAXuCrjiON61Lw67s8E0Ozf\n/PAMI5127Esoy/YZ7zJNG2JSa5VvwcbsQOozWH1dqGh7BQAkRJRmvE+QY49N\nMfdELN0cS/hxWcKY3HXAKeNuArDrV+bTciBCxR6ZqYUQkE7PMN7/TYL+pzAi\n+sedZg8DCwwfXk+V6WatlyvqTw2BUwk3dCjtlCqlXn7cpepTx9LMc4P2Fxt9\n5Ld8sGkIYHtJkM4G+mc7gTmOn8iXuILpjnDLae9t59lKMD+gwH3NgSWvPmAL\nDLdixbE706LrFvHmDKSe6rBYYTFuR9/KHdEvjXAHo/yyfRXIIhSTk9wVIBpD\ncKYqkV/oEt9L3QtlW5vAijhCX47s/J987A8fJP9UL4WA4Teh0kE6ChnvDKK2\ne6Hru1O3alshT7GBF60sqrQKZq/STbPoQgew+gytVmvbsASHr9B3B+jLBdjN\n8BdSn2D/SmAPM87TbCK+5mAIwTV8tfJVYKelZsB7ZVGCBhvIjZC+JKJEGFEk\n226yOVn+02d3eboNpo+ZlrHmBRTc55c78JhPQsHVjJLLSfS4kAcdpyIyWQRo\nBD75m4aQT6s5EH+9wGXMu64gEPXqRSKBmm1u9GDvRxf+tBkgehNnUh0oYDBB\nsfoX\r\n=/17b\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQD9AlSAQQvg0qOQPNr56n2jhHZi4oxO0NFUPZvYilXoAAIgOETiKDAikLb0R6sbwNWhAHYFl9HOmasliDwDMIjkr5U="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.0af264b.1_1573590447729_0.6106907579524894"},"_hasShrinkwrap":false},"0.0.0-canary.cdf3e91.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.cdf3e91.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.cdf3e91.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.cdf3e91.0","fusion-test-utils":"0.0.0-canary.cdf3e91.0","fusion-tokens":"0.0.0-canary.cdf3e91.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.cdf3e91.0","fusion-tokens":"0.0.0-canary.cdf3e91.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.cdf3e91.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.cdf3e91.0","_nodeVersion":"10.16.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-NHwEp4uoZXIP7Ply5WL3VLUvN6niFqwRySHlGIylkC5si4LN70gpLQf8lJxNq6EAC7JqSYvp0D3bnY0as9ZMzg==","shasum":"db36decc8403de7cd890d4118177a0f8f4ac18b0","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.cdf3e91.0.tgz","fileCount":18,"unpackedSize":32877,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdyx8ACRA9TVsSAnZWagAAJ9QP/2MC68Xgt++l5zqCA2cg\nX/E1yYFaFtTqBVvwhrXvJ8WqgKGFOWwWCuTMVNYkKpLb8Pnw+uhhTLutpjf6\nUWAJPT4Chho2sounzpZyWk2DFOECDyJ4WuZH3INP1X63yESKA5ue3tZbIRbO\n9mgcamW1QzHPoCAmK3Kh20qW3M9xTv23Dna/IDrWjmPnjtVxMa+SR90IPB2G\ngaoG14u2LU1yaQb00HlsK+WfsidAeU9RiajvJRzaMc7SLSkDJYSeKGwrnez6\nge1WSvqjVXfyaIkHGUCxDp7T29JeKIzo/56F4zDP6tJZtBydIsdB5XgRM1Hc\n/m+F86F4b6L48Ap3DTI1ZR03Cuu2HgG+8ypYDJPAuBxsCHEKI0G1gSMQKBaG\n1wFgpp5SHuBzYtDHPtXK8WNg3oRTizsmfNrCruC7TmPAkktWwRcXAEaY2yEA\nSC+7oLJyOwyP+I0Vtx47+5rZfucszXemwQYQptC+ScK6UwrzNdpUCCpoNg54\nJQKUzYZec8l/g2eK/BpemZhXbofi1jxKZjH0YWyySc2wNZQWEOXSfjEhzr7k\ns+uWyee66nXA5irZdNQMwfx6oYkBV7Kxqj7Khtt+Srz2s9B5lwhJ4/elu/vm\nhf1vXpcnuv0FKCNYkQAtztT2sVMA3+ls1Kd/zmcJSO9w6GgaQm+OEP1MZtqe\nbeMc\r\n=VZMl\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIAMDKS9zrgXuT0dL6Cgmae1nXatu6rLRvPRX9arrzeMBAiEAwwT0b7+vg5cFqTjAqouPKyZEUlA1Uhtb2j8gs0qQegs="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.cdf3e91.0_1573592831689_0.12821889953297316"},"_hasShrinkwrap":false},"0.0.0-canary.55945c5.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.55945c5.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.55945c5.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.55945c5.0","fusion-test-utils":"0.0.0-canary.55945c5.0","fusion-tokens":"0.0.0-canary.55945c5.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.55945c5.0","fusion-tokens":"0.0.0-canary.55945c5.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.55945c5.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.55945c5.0","_nodeVersion":"10.16.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-Newn2hjPp2Ki5xCI7qXszlTXMwjOpAjAb/ygZpA7YGPaBjBK803BSIV80p4Hd9UrwXWPhVWXQABsgYjUdudaHA==","shasum":"deab86e87301258519aa27fdbf257f48af2f4ef0","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.55945c5.0.tgz","fileCount":18,"unpackedSize":32877,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdy0eBCRA9TVsSAnZWagAAf8oP/Rs8aOZYdkR8wF2eVGGp\nx4FqnQVlaLlKYFilxPyma4QciSNPdSrN5HJF5LAECEAwm2zIccbtmYU3wJzO\nzrbGq0WA1Pa2m9YKqu7m8fDZfPGyKJYwrSPcvB+u2PbicCf+gHknHHoeZB3Z\nO/4zfBUhwjGdEhL8+f/lewn81ztK55HoE0B82t/lJmWD96Bf3bU11oFDZlgM\nAFSZGlfHl42qHeqIwSSChWxqZ+bx1UYygh5dJMV0w7ZJv6q3PPzcpi/SQxKa\nbrTcif2/WDPhZcli4OCaLDWVgt5+UAJpUfjd4F0cILr3OSNq56rdkaUOqVsK\nfGrwnD7KoTb74bPLHQt7zmktaLRRfKUwRwKZ1FyWHlmfBMlXp3IxC8YhLFHZ\ndb9Eji1eb97lJ3ctx9sln/24sSeelR7U5HCphKljCzVMtxDyaJyo8jw2Q1QH\n19N/JKRwgpaJhC6oamceZftjUvoV4naB0ko0HoN2qbMwfaOFOtL3K33pCxzH\nGATuGwMWKmtCk375GeEWab7kJ3LLkx2T1/v+Ntq4iN/SL3IWgNHgEPlnYhed\nKl0YljUJLKlCRxlXbuIZntsOCUPUGJEkTgia7GoL26Ad7yJtHxvExZkQNYyy\n3yZ7goUOcJ/v5s/I7IKsLhmjTBvKuf8+Pl1TLcRKOpC4+Vj2lA4VHvX5e1qO\nHaaH\r\n=+rW+\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIBzmHqr/OZ2NLdcqyJTxWPhDCiX+Ul+zZmhIN+CqaksHAiEA4HnvHGSf9OEEMpmPBbCuHoMBTKbQhOSLbVAtEqkkm+E="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.55945c5.0_1573603200504_0.0416551771233733"},"_hasShrinkwrap":false},"3.0.7":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"3.0.7","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"6.0.5","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"2.0.7","fusion-test-utils":"2.0.7","fusion-tokens":"2.0.7","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"2.0.7","fusion-tokens":"2.0.7"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-3.0.7.tgz","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@3.0.7","_nodeVersion":"10.16.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-kZYwQsNsAjIoN72iwlAYli4bn1ey1L2UGeCLHX6eIuz+crrgrlGgImMh39dbI8NpvkF39fYgnQtuK7J6B79IwQ==","shasum":"eb45817d5c68d4dadc50e8b2d1a6d1a9d81792a6","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-3.0.7.tgz","fileCount":18,"unpackedSize":32758,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdzGedCRA9TVsSAnZWagAAwqwP/1Ybl5570M9LnylvsyxT\nqkBzLmbtzNfOqcJKJGnrV06nqhzeGsZS1Cf8kHLqzxkifJbdTh5Y0sZ4F9+t\ns/1vcUuIuA+SVKE31v9Qjy5gY7DTx55cVZC3Hj/Zs4vWDe4JpzpIwfBpis9E\nE5XsEI8UcG6J8P+vVO92NlQhe7AY6u1gQdjXjypmotoDTkpyjglhzl4EJNx2\n1ZYTm7/GWnq4zv7n6bMXBrfNmUf7eH6O2oq4bWtE+DNbfA4GYVGSQO3ldT4G\n0PpR5ja+/erTPBo2NItBfZ58B88qG72L9hse3mAY1MIqC7+Va4I5jLPBtJt9\nwoRKNygjV/zOpM1hYeUV9JWV57z4RZuPOwWBDawtKBdlBIkoFzOK8w6Cdhdm\np3WBAz2+YkgpUR0r6nJVxXTEm0taBKhHy7R1qMHxwGHFKRwkzPH+LxkPFPju\nzvwbe2UV9/pfF5OCZDYQl2ylzKO71hvgi5uQOgA2f94MgcapxR+VLznc/Spq\nfLndygrXW0TVfoEHDvDeKWPsSQRyuZzetx16xOBYyp2IezZxg1CRxIE1cadV\nJQIYbzvbXhhd77UI2rKIQ0tq0DGZhCzTQait1hAJln4BfKsVlZasMSq9Ffeo\n0Ht0we6NDRZydcKhIGMiQ57buDLL34M01FWaruCy5Puf6cWf86u82GG7LvkK\nKPhB\r\n=EDYJ\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIG5jW3drpzPhqlmP+chlbqAPOQcYhmnEKwK7zvSAHKxfAiAzujSWkvxMvf2ISbUKvxdZxHbv5bz8SeDEHXCmfTSMPw=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_3.0.7_1573676957155_0.10958154677274079"},"_hasShrinkwrap":false},"0.0.0-canary.08a30a3.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.08a30a3.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.08a30a3.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.08a30a3.0","fusion-test-utils":"0.0.0-canary.08a30a3.0","fusion-tokens":"0.0.0-canary.08a30a3.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.08a30a3.0","fusion-tokens":"0.0.0-canary.08a30a3.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.08a30a3.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.08a30a3.0","_nodeVersion":"10.16.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-W0EXSscV5YlBR7Dm2FswBHSTTvD7faaWNRc4CRBqbXGGMT5qOMu6oo/UgIZFmIqB/0e30gEmiVlCztgZukzPAQ==","shasum":"b5b51bfc2b2be2f3cb3882319570d05658ccd771","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.08a30a3.0.tgz","fileCount":18,"unpackedSize":32869,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJd1EuaCRA9TVsSAnZWagAAJbEP+wTGYktNuQkvuBTKLR30\n8hJcw7lu4t7SDviRfJ2rGM3U9hgM2ynNgzxb6WI1TYUuRBo0LKlwrH8MqDap\nJ6+owfH+L0iDCxe4FJdvwQdXzSupUdK5NixP5eQIpGucHk+noUudrPVhO8Y5\nqwpeJZm1e/beynhyK6+zx0nmgqJkjIa1oij3+bHy7nHSlnIgsRb52cI0bCBM\nXhQYBCKKyAWrMt1bZ18aCBuDuWL5LbOEgpb/DQbHIA9TNPgBZmJraWA/PxNx\nB702p7+gstfe0r286yA2Di8ztj9ietLZ+o/0eufyYHDbax2gmQ8HcQPlK9/z\n08F9mAZcVxSemGtQKIJTP3BJCVId7uMTLI2oXbpnq8GXyrIIacBU3blUsF6I\nt/VuvpjKlhD0AAj8HMwTae3DTO9RieqhAOj+ai6KqK2vDANw6xl+biYwCX05\nyQHBSS2C04zRNxZM00OgEbnDh03fDfRYt/Ly1XMQyzJk55DeXdElClX5dcsA\nn2lMuFuc3X+KsP+RmzTITVUNbc1sFBM8PnZbRtGMfKZaCUMk2BfBjhWQQ9Xt\n2VFBjIhUV2NwJo96gcSAqaUbCIkA+h1rmaBdQyWjFkrMiQdK2P2OhuYXvFDD\nn2nuYD1S3cH+azVsakw2iUXJe8kT2ti4gj2WBh8qvTgxA0Ris0HhEJKBdIVB\nL5Gi\r\n=fmWi\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDO4KFFuEcosv4QRYAEeK9WXCD5DicnHyYgdSI9AljyHgIgRvQHjJ7vqEp2LNple5YcefVmFiyms73Iwf2W05pmdOs="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.08a30a3.0_1574194074261_0.9260651015394017"},"_hasShrinkwrap":false},"0.0.0-canary.602f682.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.602f682.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.602f682.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.602f682.0","fusion-test-utils":"0.0.0-canary.602f682.0","fusion-tokens":"0.0.0-canary.602f682.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.602f682.0","fusion-tokens":"0.0.0-canary.602f682.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.602f682.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.602f682.0","_nodeVersion":"10.16.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-mC6oBDABuK24Z09/XiWt5pZx0bIfniUOcnJnMgGZj2TVDIwg9U/sojxZLaCRexK38z1vUnKaTZV4uPHzDOFvCQ==","shasum":"4f497f9336bb9d60a590e05703e8d51203c32028","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.602f682.0.tgz","fileCount":18,"unpackedSize":32869,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJd1c1GCRA9TVsSAnZWagAADs0P/0RdtP3hWowEZnU4tMLF\nyzwykRIZZRuZV0tQyDVJOEGOQhA2t/1xvxwobapumN7q3W4cD49Fbzarsubh\nfkNCS2Oh2pYU6iDwtqXO5Rr/EgNyOnR1SVp/97VWp0N/Ruj8Z8OkpZ6okJyv\nVY1zXNVipfNmukjRr/vYj1coULVDswOtCQnY+KyQwhd2IGxTQZuN0xu7otNV\nTehK7BW7O6NVxS+8+nbZa6eNkT7vgiP34Rei2tLO6MINHh9RlKWRlNvKtwyk\nHWYNLOwIrKcA6Ox1twBZD689TUBkxN1QLSZxE2D/ITk9Zh/DTNMAIlIil9MF\ntfjOrQw47/N/jGkF2RKzH6RlQf/RV3WyyAzdM8Ee2L9b93ZIJ5KMFdhinpU9\nhPg1NfOAp8bZwFkZioslWFj/KJ6cifXQjbEQjyClC21Axn81fFA9ZxAGEvMP\n6ED7o5iJukhOpATvuGz4vbrfKTsN+qkdM3RmWNxK26R1PTDgM9QWZFg/1HPm\nEU1PPf+y7o0BrWI6vRd++5/5SISyc5sc/Y8DFDd/luYFtQJ0MQHjKgbttF76\nlP5xTZupWZBJcfo59Q7mWLCkS1gIVm2t9SH9P+52ScpbPBpwCPJTIqzH6p1B\n7TVNl5I21Xyf177Wk5tPGAXyw4XkU49WE2r1TYHkFKIUVphKnpPKhz9ppVQP\nnVT3\r\n=GSXe\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIDok8qWLOJeLKck1V62CDU9A1tH0GT0NR5BsX5g8Z+chAiEA5YAK3EjRTDDuNjeJzjY0/Nl2b1CNmTlQL1ju4OCGMTc="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.602f682.0_1574292805825_0.6710124553263321"},"_hasShrinkwrap":false},"0.0.0-canary.b4d0561.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.b4d0561.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.b4d0561.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.b4d0561.0","fusion-test-utils":"0.0.0-canary.b4d0561.0","fusion-tokens":"0.0.0-canary.b4d0561.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.b4d0561.0","fusion-tokens":"0.0.0-canary.b4d0561.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.b4d0561.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.b4d0561.0","_nodeVersion":"10.16.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-E8EUNrbwXvNKh9nbsCfHfAndXFQUQpHlvkzIEGmVOzptcxAoDL2wB7kxeUYJe9OHeNsHam55NB2Cg7tPsuLIHg==","shasum":"caafa2b4fb5b34e54bf1ea77e38f5e6f434a98b4","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.b4d0561.0.tgz","fileCount":18,"unpackedSize":32869,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJd1ei8CRA9TVsSAnZWagAAxAsP/1gYi2cWYJkJpB+4Wk7b\n7zuKc9lQtPxkkj2VjeYOchWvVmpZgf7o1rSLVqANvQ2lkQovcc9g7wpUVzAP\nrvZ5EKSRZoxgCZaD1gcYbAgDGE/t4iNwZS+j71yd34SdoQBmvbl5ivzRt2t9\nPbkmCRXS9JT/Mnur71/8JeExrg244PC3D/MilnhHuANaNp8dd7uCMhhbe2Lj\nTw7/83O4QY9srY26iTekRsj62xTcrCpzlDXvaByK3oqKWjKsN/SkMUd86Ydg\nPcAeRokShPT0P5Y/29pphsZ4TBTVhjLRe+A9wFw353OkKVe8FAnF3gIIP3uX\nmxeUzn4i0CezmcWZ8j7a9S1zEjjOU4X/2FrNbxcU8I3WS/uvHmm6P68EuVOc\nQnDqfJBx0tJvlmZeTVyWMpTnt6avZ55kkFm4OQU3psQWdQoSt2prgBzvGaP8\n3Xp4UXGEQQ0bZBPDN43WexDRBGozKyUkA5MiuBZxx32Gwaf+u9Y+sncxv2Gx\nPkvaMT13GRErx22jpnOJjJ2ocPEEJ0dSxO2pJOnDX5pY0Uwci7z+spXRmk9G\nemp1T1cMH7o+cYEKVldWOssLrZC9uW+fptUDQ1ruDWtjNHuEkKiQFBIgrHpx\nYtdflBgGLjHXIZG8E61yrfXt6OLRV/N8SPrsgpgXVv8wrmIRE/61F/UAk3a2\n0u8S\r\n=nhYG\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDG1hJRCGvN4oyppDjkMf11+oyZdYsygUA2CXM2Vm7B2AIhAPetKfJWEs3yjqUX0m+640tzWdcL4pkJs3Y/0Klu/DTD"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.b4d0561.0_1574299835991_0.05129851429098431"},"_hasShrinkwrap":false},"0.0.0-canary.f16f299.1":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.f16f299.1","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.f16f299.1","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.f16f299.1","fusion-test-utils":"0.0.0-canary.f16f299.1","fusion-tokens":"0.0.0-canary.f16f299.1","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.f16f299.1","fusion-tokens":"0.0.0-canary.f16f299.1"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.f16f299.1.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.f16f299.1","_nodeVersion":"10.16.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-G5b9Z7oqAAU0/KqUPkFPIwoL9CBuK1hpq5R70HZLuELMQxHOwDti8p//XCZlh1LqOP2MvV3HhhSloVv5hxDacA==","shasum":"cb1eac549331f52b3b890a62b72e23630c87b476","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.f16f299.1.tgz","fileCount":18,"unpackedSize":32869,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJd2D6/CRA9TVsSAnZWagAAyv8QAJtUpSjtA5GEfbpQAKXA\n3wN0dc2fJsWTmgmnuOFF3PvSQdrIVuzHCZ+vXZAwhGePQxO4RJKHpe3/4j5K\n83xabK3mearqSsa9O7URf9FlMtYqEi79hmLgyokIYs5Gd6hvmMYVwKg2pN2L\noV4UgX/ZjSdcbRjtp57nOLroIPjZbfi9ZxfvWQ24MaQnJztnoZUqOh4Wy5Pf\nKPdUnIDkDJ42LfleYob/RI/O4n5FhCFV3GzFoT1l80eSxouhmXir/xgb6pq/\nUdEAZFfymSHC9jlGbpOLhWkclDFuLUWLWGjCw8Oq43IMGN2RlGmBpvwL6KKE\nPth3mq5dTScaUnkbte7sddAxn3n0jJSYPH4m68FPUVWt4433IFtSk1QIbyxl\ni8j4RHk+Q84buwszlxTYxDQ1tcw0kVr6mdeqfrslcv2O4IMDks+uH2pz9dqh\nYeo+eK8Y3plZQGaUEFFNyasT+L4s2G00nvLGIlEbULukabeSQgi7x4LkkI9G\nVvTs0RBNnLW9Tbep4um9CTxcV6/YZknffAJgMrBQyiEHgxLB9WzKuzznWxL/\noSdxqmvCeFqta5KGfKV/z8tVcvOBSSjE7RhwxL8fdeYEyf87dsis5rqpJrpF\nGerBeFGdJdtlrO864dhobK3ts9CKGT4rFBb/+XWbI5y5pOtqf63IdaRaJofF\nB4+J\r\n=UUQf\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCHTNku+cpk0qyEeXlDGTqbxZXrqHAiKjp/HjCgQamhDgIhAKLjXQOIrLAQLdLQgsV6cCijvBEZocgeCBlMomvL/0L6"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.f16f299.1_1574452927102_0.4137758377397889"},"_hasShrinkwrap":false},"0.0.0-canary.9dca7da.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.9dca7da.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"6.0.5","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.9dca7da.0","fusion-test-utils":"0.0.0-canary.9dca7da.0","fusion-tokens":"0.0.0-canary.9dca7da.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.9dca7da.0","fusion-tokens":"0.0.0-canary.9dca7da.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.9dca7da.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.9dca7da.0","_nodeVersion":"10.16.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-7xN6pMgpCck1MhthcZFgsML2UkLxyNnXKs+b7zm27PBU61IzqvVIS9IfPJk1ol/QCS/pXO+2TBjZeG6XhtbwCw==","shasum":"a07995e8b0bffec17df1b3185c6f805291cf16bf","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.9dca7da.0.tgz","fileCount":18,"unpackedSize":32860,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJd2JC+CRA9TVsSAnZWagAAm/EQAJEnJVq5K83fWUDKnQ4Q\nEVf4wc9yClpQ8aR53UbZK1Age11y4XfJQPjZ+ow1yCcGbqPYQ8VZm5tpInas\nKOM1nbFp1cLLFroATmpx31CSxLn0UZM/UkxV+h1ihKm3sy7OcrIeS4jUmWIY\nw7VSmXeA5rIr3pBovuy9jdS3xUiLLFiNJB/2Z7FIk6ZkfRYk85SzqZLFwFkG\ns/Syh8ElHg8TCzpFxi4eo9rDQoKjc1azGPzDa2uV9q41LZVCvrjFMvD0Q/Rp\n40j+JChWO9/ZUsWUwtIQUObHN8zRU+/BiVlPcgvbotOAM9E93fWg4tkUgjyT\n96ZL6yG5FjuD5yDjxn4Tsz0s9tStQ+SUtDjCzv4dr4mJNiAMaJzFavGei0yl\nXJ4Fl3lwB8Xwv/pHayKNMgk7yAQu7it2a0WMX606OZI4FYz5yxxaQrH6ezxU\n+AJyPgWAFGHgZxrTZWg7H/EgGtKo8ueJFLub8VBEZGsIYfj6oycPEd06mcqX\nfYtwZdb9y7X/RLdVoYdFQGVhlRJtQrLcZRbnM1tMAFuA+JgtcuY1CWE6DT3M\nL1fnMq2K71aP+nJYghkofYmjtdfNfQk+IJ6O7jgATN417P0i/H6dVsFE8bCZ\nByxe5iEfXuZFIoKXp/T3MXjRoAo+SgnocK+5epMjcIJodNTpe4HhkZKq1HrQ\nCW26\r\n=BeQb\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDfX5QjrlIwaQBPnw49UqDejmDcOH99g92L9my0lXVRjwIgfRqIh0av13+XW7MzGSs3zyPO8DxiDCXLMCkvwfcC11U="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.9dca7da.0_1574473917685_0.4567416718519286"},"_hasShrinkwrap":false},"3.0.8":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"3.0.8","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"6.0.6","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"2.0.8","fusion-test-utils":"2.0.8","fusion-tokens":"2.0.8","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"2.0.8","fusion-tokens":"2.0.8"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-3.0.8.tgz","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@3.0.8","_nodeVersion":"10.16.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-08zRErVRHrPnfZy9iISp1Q012UXTAiTwmU4LCwslN4XSH4IPKgMw8V2L8cqCCASoEE8d1t6w9CjG/aek5jwK0Q==","shasum":"46eafcfebdde876a3bccafa875d96c2263845e6a","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-3.0.8.tgz","fileCount":18,"unpackedSize":32750,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJd3DIOCRA9TVsSAnZWagAA/oMP/RgmoWntaoABrbXmOKH5\nI9R6SO8owVxnZRLcuHJFZNlnAxQo0kQILd303yWPOCSA5FxALzc80vL8VbSa\nIRD9zoZHnigABth3Vq9ET1Dh4nXpFQY8wSPCreMvIh9oMktjghtWWAr/6uM2\nOlw0V6IRCti3U2n5Kgy1v9fE/Gh6FkVwsjW409yB7cGg5coxyrhtNIxg+xN9\nZOwDiJd2hOPoyDrtQk2SecxqDT0zlsn27XdFvb/y4maSMLBRFCBA6g5q3Atk\nQonaO3GBVTdRrLxG87RzcupkeUb5tK+isd6/y6W1oyxne+0/5/A3kHnDYzRg\nIYmyefdmRLc03zFj95xjw8HmAfWdiX9XXe2u2DxAG5m8NYReQJWwdm3Z3uig\nvRNCVIbap0aVMciAq/a6u3gEWnZa/P2X0/cAzs8lkSlKTIyD5M/ZpDUnuQLT\n4j9G1r7F1ym2b4qlo516yzZFTtItK7fpvwQwTnzrW4liUevNDcHSGzmmAZeZ\nIhSGJLHGcI7UrRF59Q4nzw1ivcB85R5yFq1jzeSAmxn5XZBs9LBvFrRQ26mq\n91SsMms75AR77B9omME+xMsCwfGnYQIyBVokCB/5wZ1k3XM5SlA+gclifFfh\n7/RxSNNkxFVDz2GJcNqP+cZuIgLsrTt72p5H+0lkhGIIaRw3KT3qww+Ey2TW\nd30n\r\n=EmG3\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIB5QrHDq6/HW7FlG29DnZJrDed+1vfJcqZTV7f40GaQhAiARgcxttfZLHAxMpZ1lqRe7sweYGo2Ck2vx7XENNFkYsg=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_3.0.8_1574711821604_0.5066175052072097"},"_hasShrinkwrap":false},"0.0.0-canary.2dbfb1d.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.2dbfb1d.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"6.0.5","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.2dbfb1d.0","fusion-test-utils":"0.0.0-canary.2dbfb1d.0","fusion-tokens":"0.0.0-canary.2dbfb1d.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.2dbfb1d.0","fusion-tokens":"0.0.0-canary.2dbfb1d.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.2dbfb1d.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.2dbfb1d.0","_nodeVersion":"10.16.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-rr6XXiiRRk28IwLc+iu2CeDLfSVZmd8ODChbZ7Xw4pL+qiO2R5GjB3pMyR0QuDEPnFBOve06ngoNAt067vBosw==","shasum":"0afaf5a14a4b393df4585e04eb7a900b1e473e2c","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.2dbfb1d.0.tgz","fileCount":18,"unpackedSize":32860,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJd3FrbCRA9TVsSAnZWagAAWXYP/RWZauaf+3AIWkuOPoUm\nKkARQrxSD9+9dMntLhe82bjnf9xcXaOtS2pWQznVaTcYn65kmjf0lyMPaL+N\nFo3Qf8tdf7FO3Qa1YSlMarO/hgX6q1brmIdErSwoMzfZw/R4raWpDmoqhNDW\nDROaBh4CA+t9kXp7B0RSFAFkUCQN2g6Mbn+q/PGPS28PqZ262fABQbKrhovn\nCXPVzprqI9pOrt8/9bMeXfNVfq+wEI+G1Hq0Ou0jKmR+uEKPWP3x6+3AvGSl\nar6tIbHKVJBU39/F3L9/HVx/XlFiUCnP5FFHArsFndyeHcviG+Zwx3EISxTX\n7kJ07QZhMwPQeYRQ+zszj6RA3fHc7zJM6hAo3R/utMJKcKe5Gf+lC1XFJ9rx\nny5anRedCZhgPN/pnT26bryYJH6uC+/b5GjOXtCuN/IwAgHO2zYtyvP5V4zG\ntHaqg2/vXQKPUFvkF4P7gaf6ZSbwY+B1gxiPxHEklauxpHDT7pY4ml+p4dv6\ntg95FeXXcF73l3RfJe32Zhw4ri3tIufSYpNXzBVpyc0GW1tZo2a2lj8ggCIu\n48okSKks2UKSfEQ+0AnHyTngNmjXKyp7/Bd36eRbnYacckauU0JYtYsEwKjg\ng5xSpeC7Nspjac+7jzJaxhm+QdQu0soWTI6w6kxt031AZ3b/POH9H+stLs46\nqoye\r\n=HPO/\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDMB2RYJlrnosL6Fpu37InZI40LVjnGfL4y/k5op/7unQIhALsYLhUUO3LA38MpWUMOt6vMlCTOR2z2hFHTdbduPg/1"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.2dbfb1d.0_1574722267505_0.41618949841448294"},"_hasShrinkwrap":false},"0.0.0-canary.777f2cc.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.777f2cc.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"6.0.5","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.777f2cc.0","fusion-test-utils":"0.0.0-canary.777f2cc.0","fusion-tokens":"0.0.0-canary.777f2cc.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.777f2cc.0","fusion-tokens":"0.0.0-canary.777f2cc.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.0 <11","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.777f2cc.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/4c8b6bc04b61175d66d26b54b1d88d52e24fecb1b537c54551.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on \nrequests for non-idempotent HTTP methods (e.g. POST). \n--- \n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n  \n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API \n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token. \nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',  \n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.777f2cc.0","_nodeVersion":"10.16.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-dbkz6K5yNuhMp6Kt2eIaDI8AX0dKg0p1nedRnDvKecI2LR7T1pZs8J4izWeq/i2EW8CpGSva/JEMQRy8kKDIbA==","shasum":"dd66822d5efde7a630a1adf43e234444a09a5d21","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.777f2cc.0.tgz","fileCount":18,"unpackedSize":32860,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJd3HOzCRA9TVsSAnZWagAAA7wP/0U8PXiQdo6Jy+jXVL5D\noNW8uK403sMwhljOqD4p/3mOI2qOsKMN2lymKFWdhDqRvaqKH9BdT7oc4FMT\nZ0ru310VHukvM+3evJXv7I8fWRyYz5mE8g2p18FsCXAhw77e8NyqDTUXVSX6\n9PAyR45PUX7Blv26MKCtAmgVSVYkc1XD3nAvhzcV4pDlDIdrImTBjJxxQd/y\nN3tBIGflwxVsM4OMfd8Heoe+Q16SjGnnTiZaxmoaDPV2cIR5M7/ptJrYH/FQ\nruDd54X0731XardtKz5TCPH6nH+qwWoy9WIIYugXz5k09OliF+iK5YDpxClR\n5QrSvMSagY0lhxx9Noa+qrHGRR87ig+TlGRHSclN5JKpb6rJSgfDCF3EJx3g\nabZEEvhJq6Pij2XESW5tVsSPuIOzL0zqXyGFB9hQFHP+3bsHj0YaOMkrBLXp\nMnpBfgInPIqUc7KQXxZwazp9CTCTSCgiIyMvQ4aRNx3+j/vuBCJsIzq85WvI\n/ew8tdXiPT3tN+svF6zl9u/LaBqs9Yh0r4aMbhFOVS+4vJJyw536WuPZrWnL\nk4UKoiMGYagr6eSnTlgmnNQ00keCxIBWF92LKJiPna1G8d1qUYKBnlO+UnND\nOgHV79Fb1mmSqVq61lVafX7INJMK3gUaTCvw4VgLOhZmxHbzWtUPSa8Ki3dl\ndgTS\r\n=K3GD\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQC6MdFhKx7rj0FCMd+fzNLJ0UZypqddSCXrFY9AIWVPcgIgJEvONrtNsTMALeZFOYYfCPhPwXg85x72cqXfp8sBWj8="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.777f2cc.0_1574728627212_0.4031727865458796"},"_hasShrinkwrap":false},"0.0.0-canary.6e4e073.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.6e4e073.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.6e4e073.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.6e4e073.0","fusion-test-utils":"0.0.0-canary.6e4e073.0","fusion-tokens":"0.0.0-canary.6e4e073.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.6e4e073.0","fusion-tokens":"0.0.0-canary.6e4e073.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.6e4e073.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.6e4e073.0","_nodeVersion":"10.16.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-FX0p6BUCERuX/5ne2nCWv5hXJqgiq1lPLdrOQjR9Rn7M1X57hQrtGJ5UaoEcbC9ybozfazsnJ+mnziK2Lz85Fg==","shasum":"f28f227a50dc1bd1222be18fd7065245e32e0123","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.6e4e073.0.tgz","fileCount":18,"unpackedSize":32865,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJd6Un7CRA9TVsSAnZWagAAdeEP/RyhPXB2srg4y8FCQp9A\n4ew8dr5N8hIRIS+iUu1YIeDNUPzVheo7bEN/Z1SAeY3WKZ2SNGYMmkqSoNnl\nVYv31lfqU1vgCnr+aPHUELBcTsKa+eh2PjCbzK5QlOi3K7pE/kN2nZEqzg3U\naw6bVLIPn99LoIwviJDByDfdCQsfL2R2amas3klXjWqtNBh2eFZDagYTLwd+\n+UoctIzUodi4N5PeXRnd/85p2gPYkYSyL+dcHWErL0lEWK9L98PvAxH8Rgpo\n/G4V8ywZDDM5sss/3m9cg/Ylsh/NGMZ5F8toGnsT5WCrtPTPPM3lu83faShJ\nKW92f+9vIA3tLlmH15qNBVjBiA/itRebes3GoxAMO77msrazOxCmovsQ3RT4\nvBZkwUXKBAu2FvuLeU+513FzsRs2ioX77wtgoxnSo+RQuLzfS83YDS4NXZ4L\nysgbg3EF7oGAQqA0WPmWaaU36osJUEMdpUdgsH8g8pKGzsntY0SIldlFGUWq\nyYBX1A/MDQ6sdsGox/BUf6/MEuM6B+yXXwnbFGOJin4Vp03wX48BXI3eN4D4\njQXktUan5elqOER+xevuZShVgz0h3uGL9W33Z1YAQ2tgQjSRkkjaLz8PJ1sa\nJ4J5a/ynP3y2eOXAC3oUIY+puBBl7R8CrWKLhZg5Bj3tvg04J/L6KjhRmz6z\nMH0Q\r\n=Wmu1\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIFwZT0bpTzuMl+ctuYC+fiXrelnXzuFjBV/A0O5UUKFEAiEAja0SUu18KRTwetFZ2qflZZrHf4RzpT5LQu5TvE6Qyj4="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.6e4e073.0_1575569915229_0.6710704041941036"},"_hasShrinkwrap":false},"0.0.0-canary.b7558a7.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.b7558a7.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.b7558a7.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.b7558a7.0","fusion-test-utils":"0.0.0-canary.b7558a7.0","fusion-tokens":"0.0.0-canary.b7558a7.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.b7558a7.0","fusion-tokens":"0.0.0-canary.b7558a7.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.b7558a7.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.b7558a7.0","_nodeVersion":"10.16.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-NgmH0vyDUs358MDMPXO34i1GJGb75ks0Dif1kv9dL+6EEkFII4PLuB9C1uOBE2XHxtGdfCnId3g1ewSkatOQRQ==","shasum":"4432ff1772e3ac3b7415eb39ebce9a4aafe05d12","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.b7558a7.0.tgz","fileCount":18,"unpackedSize":32865,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJd6Z0FCRA9TVsSAnZWagAAgosQAKNAxoJaXVMgm2i5xrre\ndngR8wbb1p2Uz+Baj6IL7SpZ+/PV3v+TDQ037drZpLM4pTuoh5gwCWeAb10y\nyam3B5SgRgdoszm8CeBjp+zUVtz+FWXFJUBXNOtp+kwLLnix/t09m8Rz6VxC\nPPaVXofpdG5Gi6fTBzgSDOTMDgdpL+9rhKfqDE++QiccbBIup/WmhaQW7+5O\nDnmE9sWEet7MQrJKwWlViFiXJ0lbayZX5GnmvbgbNys/92ZmIUhDydmJGwGT\nBDwmrL2qBHQg817EXgz3XwOiY539RJ/WZgsz2IK1JZdWd0t/hFxCX4f61mZl\naNy8kMQSOKFuNf5IWA0LtKIDUWglRptRKVgj1b73n3C+QG2NFaVhE2CsNhz1\nfxgp7lPlCarRBp8Nl9bHiLV+gV8z+LbTyQYqlSeLsEqdFkOgsqd5YyXsPGUf\nIwRlMtKpEm1yVSgYql0PgznO/NMUOTR9uQMqgq2W1dy9Ex45sho/zU+/uxOK\nnX+KgwhzOV9hlfWEwDiuG8rQg2XlHEyza4MEh8C1JzkcDgHlyvuIT5YVLOvp\nEaR0p+nktH0H/Gau0/uxhOyskL1bJ8VqRoiEhIcIm91PX4i+xc7ZtsCEN/xh\nxAyq3b5xqKnJUP1QuzMo9JiF55EpedqKPlWFzX0S4cdnyUhQgQ5BLBl7DkhI\nmkWf\r\n=NyzU\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIGxtFzrODnTgl3C5ym8o3V7UpFH29RX11tGYe4/+n3GvAiEA3ZzjWyx9D5JM1CYQnCWY5bQ0qjCum8DhwZ+WBtKs1Jc="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.b7558a7.0_1575591173108_0.9522790937935652"},"_hasShrinkwrap":false},"0.0.0-canary.f55f645.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.f55f645.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.f55f645.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.f55f645.0","fusion-test-utils":"0.0.0-canary.f55f645.0","fusion-tokens":"0.0.0-canary.f55f645.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.f55f645.0","fusion-tokens":"0.0.0-canary.f55f645.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.f55f645.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.f55f645.0","_nodeVersion":"10.16.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-Efw2yKP9rm4/K0OXNhaXXJzUB0vOI9hvzIzEudswCCRJ2vnAFOGXtPUXwnieDakPo51kujWVOljHYsgt91bphg==","shasum":"7a027fa75a41ee92f865fa1b560912b1393e932c","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.f55f645.0.tgz","fileCount":18,"unpackedSize":32865,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJd6pSuCRA9TVsSAnZWagAAoOMP/RV+1P7WOWCExiOrEUEf\neCsAPzow5gDzVDMSTsO5o8AvZpeAA3UL+pB7IvGpYSKkYR7UL28s92yQbZBS\ntvw5NuMkYV+Dxj44ghCX9yTj7ZnzcV2zMPFXnDA1oKb6YMrjdkfkycz7HuFw\ntGsJysXUwx5Quo2qMRzNzF//1mcgJP40k2ikJ7JfnBnrS8GFAvDcrOCnWKHN\nwD5dc1geHcq9BYJUSI+TN36jSRkrhV2gKiaNIT+j2uzmpT9jx5V0wQLcxHZi\nK5oQz3ZTL78MQccxJMg9JHb2qgew9ZMwKaojGbLpfXygAN10umr/uRa3du7L\ncnU48UcyQUwTOOpLRF9ojNthk4zz/pwbQVmKqYu02arctvs1dgzAM+g7dlIA\np/0Dz/593k7LK3DLfBQmO9p/tOwblqP0NDkFW0AXGyPPYF5//i1ZPN04WBeu\nwAhLfjWRpjgKs4M0ao4L7Sf+R/mGFZagcYFRQOYDqHcGw05fhVA7bQ+eXwXl\nALMxfZk+DWccUyUcKYXybc8eP6QvqFWFCQpHrX1CpRfjfhmRdv4hQuCF9Pnu\n9Dab/BAg61XJOU8N8itgDMZfeA00FJCwhDYce43hPPvt6wPT7DxmSmVnpbsg\no4bRAAiP1ZTUC2KtNisWxeM3nKywLwL5FkmlOV9D89zLNyu2KR7S1oovEkv7\n5jWE\r\n=ERKd\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIEvOkzC03jrk6/2cEQS6HePobxN/fvg+0zRpiBKYi6r6AiA22vfJtqsXBiJL9SwUMsGa93WWlO7FByM12fK066/rIw=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.f55f645.0_1575654573663_0.7487914803631743"},"_hasShrinkwrap":false},"0.0.0-canary.a1f34dc.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.a1f34dc.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.a1f34dc.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.a1f34dc.0","fusion-test-utils":"0.0.0-canary.a1f34dc.0","fusion-tokens":"0.0.0-canary.a1f34dc.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.a1f34dc.0","fusion-tokens":"0.0.0-canary.a1f34dc.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.a1f34dc.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.a1f34dc.0","_nodeVersion":"10.16.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-PP1JwcuO6eBHJ2W08AUIXArRnunrZ+nbc6RCJz6Sp27okwzuUDCZCa0rhKKnsz1D5xeZGwIFQDH7LqXcP+ikGA==","shasum":"7448c2e56889984d6b00c5da7195ffb2c7a9e1ba","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.a1f34dc.0.tgz","fileCount":18,"unpackedSize":32865,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJd6rDoCRA9TVsSAnZWagAA25IP/2ByGYLsaw3MORiuF9ll\nIF0C7AD/p0NeMfsc8ADARHj7Kk/eBzm6MZfzqVhbbhQCVeiS6zCfAksrsiAw\nEKNfcy2v1ALxdHBkAYg6MMEJkOoCCSw/F7tc2NAP7H67iKW68vb1bnwsP+ZC\nArQW3c1F0pi0Y+HBb/ZDVsuszq1D5p3zp0B3ZjQRzFF3n/5Mq2FzGCjZPEk+\n/oK/jpdoV+D6h0Neu87uUR6kB91RNcfuTpii96ywSkNAUFk4OyotGw55gh/a\nNn5gc/882/jRk8VKIOCBJ/JnzeWdvvOvS7Wo1xEGA3rqrNaj/xJBlHoRke5l\nM8ILQ782P2JtGd7L7nFClBEFYwiJ86x12t+ae4dwY1zr5rAQleq15HPgNoky\nprLcjiTCgk9jzYL3Ll/W14kXkdb5bL+4UP/V3Sj6CzXoj0rw3l/5zW5kPGA6\nUmiZJGv0COxpNJdsGtjdJxjzyxZR5x+hEcDgwUD05M7CBnSxyFAcUO+atoXc\npddJ+aIjNNdYS1PTL8C0PAeKczxmiRHipd4RtzqhBUZZhdh2IETDsXjXgmDe\n7gwAmtEnkWeV16bYCC+rEGgTj1KSz1Zdgwq07/jt27AGAajiSIV6d9Al0PWu\n+DFUo+5G5CrHd60UoSIjvQGW66Mn4ftUtVCZtA0KxcehlI2zW/OcAf6b9/dj\n7RGP\r\n=O4fX\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQD9vp9qohy4Huygo2iwHPv5QaiaMsEPovqrDVvir1TzvAIhALy4h9ojMSaT/BdYM2ozg39FiYtec6rMnfKRpLjq5H7G"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.a1f34dc.0_1575661799701_0.08637726243890453"},"_hasShrinkwrap":false},"0.0.0-canary.17b7929.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.17b7929.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.17b7929.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.17b7929.0","fusion-test-utils":"0.0.0-canary.17b7929.0","fusion-tokens":"0.0.0-canary.17b7929.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.17b7929.0","fusion-tokens":"0.0.0-canary.17b7929.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.17b7929.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.17b7929.0","_nodeVersion":"10.16.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-a05odGvoIt1zLU5nJXEJc+jieEzj2DDy0TeVrVzMFDitOWLzQAX26un0G+8DydfFcLuIZIU1oBXmHvu3biXbqA==","shasum":"6d0ab500a42408cd8011bc37b8eccf2868111c7c","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.17b7929.0.tgz","fileCount":18,"unpackedSize":32865,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJd7rsOCRA9TVsSAnZWagAAqA8P/1WZhFii/Z97uohsMY+X\nDXaPJ8HHkXSqes762SrEyFFWA3qY7sCcs4shWhEx4bi7RJf9hl6xJIrrVOVo\nQO/FeOUqfkCsWqvhN10no7fueeispnipWkhRnktc+yaFz/QK6dhdKsnvSXmO\nR5/eQALgH1EjfxJp+7TsEjMurV4LCwB5Q+YycrboBmQTUiaTiHXTxyK89oDF\nYXsWN8hNvE2GSsLgzkfl9F/Ik1NqnBPeWkPMOEbNnyNmuVvKlyJnsDPqcyt+\nXbPhtqmWjKtDnkQrk/78xDnUZtfvZHaA5nrWR1ntB2YAw4ySXVQXgIjd9f74\ne2owJkgv02dCRe8cKs4nPY/Sie6WIBI4xxpyrI3ftJe56pE29Y7CaxMUg/2R\nuLe57r+ssgCyVz0k/Ilv6r+K1uEn0538Us31PktpBLppIbbS6+VvQwQaw5zr\nGVA3KDwghustQQcFdfdGqfnjXoT0cksBfiPO8GbGSt7bCb0xIIpoJIzU+Xw6\npSU+/9KWU/XBOPHEfD5o8wvDk9X+aeKa58J+f7V7qoCvgOQnSx+OYvla1hvO\nSt8krct9OCMNW07uVR6ZLM2AWVxDRr607pXDpB0Qiiuw78Ahm+LUlFG194cX\nSGVLgb8+tXBIvnDzRgh/bBmcVA7RVM5WJdS7aKGdMKmGIqzRJIuOAn0bYAL3\nMIhg\r\n=lulb\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDV6kkVebP3IeHWICkrPlaVkZ0xwarrjH9uRkwZ5fyWugIhAP1ouEqg8IjKpqqJk8kLDXCA53LGtM+hM8jeLnDz4+fe"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.17b7929.0_1575926542142_0.07709558900667401"},"_hasShrinkwrap":false},"0.0.0-canary.e266b31.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.e266b31.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.e266b31.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.e266b31.0","fusion-test-utils":"0.0.0-canary.e266b31.0","fusion-tokens":"0.0.0-canary.e266b31.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.e266b31.0","fusion-tokens":"0.0.0-canary.e266b31.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.e266b31.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.e266b31.0","_nodeVersion":"10.16.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-zo9ZWDcPTZ2x4pCx2yg8g6pKuixpPcXZ92YPdZd18kngMr7vlKJ/ZZR/L6mrpw0am1r+w/76BRyc7xKxKgjWbg==","shasum":"dfcb61e50c0dbeb8482388940637fbe18d0d9263","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.e266b31.0.tgz","fileCount":18,"unpackedSize":32865,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJd7rxVCRA9TVsSAnZWagAAlLAP/AtnhvK09fyjMoy6uC5H\nEWYiCpkeHrPtbytbg7bj4rdwIh/3mWbff+qgKyZvbaVOEle1LSC4vgvfSGT/\nLMxVazGb6rdNbXdcwqwnsGRQ/5DM5FWMiEleWzB+riJymxPkBkiTg9cNRcyt\nvsgpuuLiL78cRovesbBh21vAr14Kx2yXeAlKxIdZuY4o/X45Fx8/z4/rms+U\n4JWlxzIaVICpQH8JIKdTVo7jENUGe/fGd67Ah1wcWPwLfyARE+SzHIdO7Qd/\nxmmYw6E1croiDrxOYZnD+pR4BTiuP3GfoQT4WPaCpZNrtm4YDpzXJGgQwLe/\nQdCRTJp6R0CoFZhzmN37qb7Ri0iGACQ7v6YW9r7qS0JLHjLx3465l61CJBhD\nwm1z5328lPdu1wRVXFgeX8X8Fz+HgrMFKSVKJqQ/CEMQPeFaYR7mzqLShFV3\nQAfMrFmLI1ELG6lksGcdJIgN7XAT5FezsMcYj0RvXoWi1K7aouGM4iJScECi\nHu7NcvI9m6ob5JvFWNLnn4T3wY3mJuilagesmkgojc5JmftwbVSSSFfpu/43\nrfGKdmibBitDj8mEK//q2P525sd4hcuBhVAecY9USB3EP6hhbtZwuN8LzsDc\n9hzfZfkZfmBitx0gAORp/NgaqXiGc/z/X8nrRp64iMPDXBexB5J0l3+qf8k0\nOzw4\r\n=/cKX\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIFplY0tsjNUBqG2QokKj8oefLmlEHQEBgptPQ6bifsZkAiEA4t3nuIAIyk96dxcjzpU89s5SrQraH+qFcKEqkbyhXbY="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.e266b31.0_1575926869367_0.4586684840759543"},"_hasShrinkwrap":false},"0.0.0-canary.2e98cc9.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.2e98cc9.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.2e98cc9.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.2e98cc9.0","fusion-test-utils":"0.0.0-canary.2e98cc9.0","fusion-tokens":"0.0.0-canary.2e98cc9.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.2e98cc9.0","fusion-tokens":"0.0.0-canary.2e98cc9.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.2e98cc9.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.2e98cc9.0","_nodeVersion":"10.16.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-OAgpcZfDugtfnuA7+rS/yqoJcXtgoahR1gEs8CouAQPP0VMRVoOus6eViX6FZvkNkAYqwzHMV3ECRh8NsERKSw==","shasum":"f86697e44036bbe7055e3c8c30b57eb6eeefaa7d","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.2e98cc9.0.tgz","fileCount":18,"unpackedSize":32865,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJd8GXzCRA9TVsSAnZWagAAkBkP/3dJJpeniyGhbFKfoqeH\nWly0BPIg9WeX4kBSabr08zzD9H48bc7F7JyCshK5CNiRP9q7fCOw1Za7OlFu\n6Ax/+/gZzc2S2uE2IzjcAe1Z2krd4Rwcq7zPumnvvP2GEgRKZYg3CXP/FxjH\ncmXxjVVQvXVRAOpaBkR30wNA+UxtKzm3sfZGxFWUk+mjHG1eJ1qjg++S3jnM\nobYIBQlEPyHVlbP7v+Dswp0TxpgVMlVxruBZil7TuPnW6clYppq2o4/0aBMs\n3NXxpPjEwkUBvIzQrHmyaz+uKs6NKeyP3msddZLtPQ1ARMGI+WNlUl0mlwmU\nwd1iEoUh+vtcBObZouC68LFKh9013y19/CRqxS+NFj7AJl6n24Kw8w8G4LDG\ndDpWvFx3l2+/ciGnwRlY3KwGPNFfWL7G4PH7Z4v/ki+w3ZrAVqbC+YRckbVs\nZL+9JQzk+yWrm0jNT3d03Xub8loDYxa4CAboptVYtsm2K9AotItB4rh/CxtY\ncXjZMgkM1wsDSGoJ/popGpb1CKM2o6uJ145Mm4YY6Zkmx0KrpszGhkbosVV7\nI5XfLxxnfskaVOsrMNJLdUnfhMGjnFtTPiT2gc9q1WD2mDwL88kkvqjGSCIi\nzcG/MOC+fftMczYAxIkiKjIfTmd5vmq05Hh32RJ6nnFVpYB8eLSkk89Jc+6j\nPiY2\r\n=8yVp\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIEJMZAruSJf8VrFC0MqK6l1wB8jenN1iFpX0/CZzs9oYAiEAnn7uy6wR7kQQdqsPN7NkkzjEJQ3BPbzRAL/R+LifKzQ="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.2e98cc9.0_1576035827218_0.0004598707633480803"},"_hasShrinkwrap":false},"0.0.0-canary.c4b78ee.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.c4b78ee.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.c4b78ee.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.c4b78ee.0","fusion-test-utils":"0.0.0-canary.c4b78ee.0","fusion-tokens":"0.0.0-canary.c4b78ee.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.c4b78ee.0","fusion-tokens":"0.0.0-canary.c4b78ee.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.c4b78ee.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.c4b78ee.0","_nodeVersion":"10.16.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-zti4ly43CrHGv0ieX4HkpaVPQEXrfQLBth84EJaXRDNDoNDz6CrKa8OENLCpCn2baXJx20QL8e+hOn0cO/udVA==","shasum":"c776a9d209384c2a649c5fbadc971e6bef437253","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.c4b78ee.0.tgz","fileCount":18,"unpackedSize":32865,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJd8U/sCRA9TVsSAnZWagAA7PUP/3PHplC4oFRd22lmREap\n7iIivpmQHj3qDU39KGjjEYmZrrFp/5iGBZdAvtSD1ahG/81CKaE1Z4UYS3TM\ntCPYnBJOg8p6nS5iTMC+Rsy6ElrbZ9p00leYob4U2CLa2VfD6+Fv11+fwY/Z\nzEpcIXgW9CeJFghIxDWOgXmkeNCyeONI2+h3gxXI7S6G/eiYGvvaGwpoCBnW\nipoTQ51si8gCquTOlY+3LjEPiI0YPAzgNPg8kqer0ti8dXSRPeTXc+EaPeWh\nYihTjQ68711r/gKiPxMG/0gB99gd5gSk3Ay3MDXJOqnrGytm/coNAzl9cVhJ\nBiQW9OtwOVlHoS5pS2uiuxFbPjnMjdcA+Ne0/V6D14dRTNHH1awwviJoiMsX\neCoq3QBTADd9cZW6FglofVOBhoVix98bPE7K4qBGn4YMBJl7jMPJbuxutt7D\nfHgalzmzhlAEdkPRFJvjeiFy3dX3c74eTXZigrr/TYjMjtGi/LjpRLNPG6Nx\nMgAKuZaX7FY8/oraPFP0d7lXrTMBiqSGipgzkZpJCYufskkfCJA8mrL7Vrl0\nlLffGjnP9oN19v0eKWB52ju9BokSywBF4EmVr8KfyOM3FSPYItnrdxzyQRzP\n7G8WZ1Kd0lMwzmpIY7SfrumH/vuGjW+ttuHZd4KTmW1d4RLCfySoR1Z1rnJZ\nGSEg\r\n=7NGf\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIEDYAyu69askJjyQlch35XgdBfeOCQBQ/TeSTOcyAbnGAiAnGhuczJl1H7gH9xRqDG49TcW1Vtn6/Sh4aCakFoRQtA=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.c4b78ee.0_1576095724080_0.05428934353057335"},"_hasShrinkwrap":false},"0.0.0-canary.87d361c.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.87d361c.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.87d361c.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.87d361c.0","fusion-test-utils":"0.0.0-canary.87d361c.0","fusion-tokens":"0.0.0-canary.87d361c.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.87d361c.0","fusion-tokens":"0.0.0-canary.87d361c.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.87d361c.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.87d361c.0","_nodeVersion":"10.16.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-VpUC+4bkNsnF740X+i6WFw20Qxhd8YPlK9hC2Rq9MCzxAHfdUh8mXoyR3VipTyXEBrxpnFp0/f9Glpdq8eE2TQ==","shasum":"8353c588a2d62504e0ce0d0821b3601b1bb0da53","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.87d361c.0.tgz","fileCount":18,"unpackedSize":32865,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJd8Y2zCRA9TVsSAnZWagAARdYQAIh8S5P2j7zF8YfxkSrQ\n6DS2oQ2dzKDlXrI2BYzt4ib37zl2PvNaN7kJWVxCMG/90NbXkvA3fO4olYp2\nXa8TaS0h+1OKPagYKkB1b5JTdE/5dWF6xXj3whMWAkM/5ElZKGGnhXUylq4c\nTLjL53mW25WaPugyaq18nxoPi6o4PwemB80moMQcNsIw1J+ZnhD+5o9CeOx1\n1axVZnwIDdUOi5SvfwCFnBABNy2/jyvctSfKNp9NmbUTqvXccNen6fIwETpG\nLtz8ulN53qh0C/kPm3S1zppyR8TXHICgTordN0yOpBGpHi398FzONImrF3tI\nlkmz6Uam+PhITyUfOdYPqFX2ITg7bzu+lK3FY3wARR/p1uWyi+MCT4qu27Y8\notSSniU6mdwjAqJmuPfmgbnLzemNfTU08Uv35OukJ9yfutIHTE06RNj2Iztq\nCIPjKnpCcMPghOyPLWZ5qJKmwD1Cu2XTQSsizsJKd+J9vmwM0KJ07rlrvhMi\nMZGoEBtyOEhS7RktQDbvf6+MHKPROd3OD87fz3DzCB6m8iJmxzoKqNAdOjgD\nm9IN8szLiG9dvwNupRZjwCDwy2C1RiKxQjBF7ToKROrYZWU5k5wZ1sxJaxhu\ngdDaBqQv+QM5Nu5yDXKiDrxr416hsZETHcJZFzAgjeZFbboR/U2H/5JyHTEx\n/Xx/\r\n=XUGZ\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIAkCJg2T73uuRImh+sZ93HHW/4ljgU0mHFDrb4m21BNbAiEA4YRedMQKAk08xaE5/9E+s6fgAuaCV2XBTfF5IpIWXCY="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.87d361c.0_1576111538882_0.4922656590824581"},"_hasShrinkwrap":false},"0.0.0-canary.32cd5ea.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.32cd5ea.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.32cd5ea.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.32cd5ea.0","fusion-test-utils":"0.0.0-canary.32cd5ea.0","fusion-tokens":"0.0.0-canary.32cd5ea.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.32cd5ea.0","fusion-tokens":"0.0.0-canary.32cd5ea.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.32cd5ea.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.32cd5ea.0","_nodeVersion":"10.16.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-SVj1GVh6QfgLHo27o+Sk4aUMrHzzjAO+xXbn79Mz76pmxk0B003q9ZNCoWJXucjp5uYaumoW2nb1Ns1s9wGBjg==","shasum":"a6361485986c72593ea352dc2cbcbc25d0c4ed9d","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.32cd5ea.0.tgz","fileCount":18,"unpackedSize":32865,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJd9DkHCRA9TVsSAnZWagAA9fcQAJgS5KLiMMstO7xaw/Gn\nSI+K5IQVw/XhPnObVG5Rq69/651y214y3vuwQHs24N/LiBCgTznn0cbWhUwC\nbodENpG/fM+DlMTthu9/J173fn3QAZ331HEA45srTuYw3FCXWzmDpQeGXD8e\nkUANzq4UbqJ7IBV0do0ObVT8Bf1SX2+dcColYmFfTIIPv0/RRFa4x9nyvqAO\nUMFlq5N/w0QfuVNjtRYK3ChmGML1cMBSU0bmdtPht83hDYCMHzzlFK9D4LTz\nz0acrdbnEqgUi8rONKccE5n/PrJII54YXg1ObGn6X4h68RXhbLqHNxm8g9aM\n1bgswHxQmOaljeTznRSqOazIK6catx/ghVS+JbL25u8hBNMIrGovavJJljxf\nVtylQlhbOjL4TGz9Xiv1Ybswek2e2A7xJDirzIdY8RxGBeMIUO9YECE1jbeB\nS9dfh64ucXyu3SHqGemRerXbLl1B+eC8ELk9MGJbj0PE3UJsdYWQLDbPxixG\n4RrhKQiTgoDefeaPg7WY5t0p7OBTAld/UUWV/IPMKvcfh0Sd9GCfYeDx+C/7\nxZF/0w+tIzjrIsopJQiv2V3pbN9Noja3gm0+FicVW1mpfLQqKkIFMZMWiyfD\nVbVhUp2YOaILDeAYX8i80Lu9Cq+er4nVIkPUQm+qymMf7MExrh6PJlUdydZt\nOuVk\r\n=M7s9\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDL9eNoBP0mXUQE1TfCCBO3FnVtXKfkehVTEWUyfaHHXAIgZd/zu9Gbq8WHTleSdRWVyirJmQOxFgyu3UnBkKR/47w="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.32cd5ea.0_1576286470656_0.8281233540681314"},"_hasShrinkwrap":false},"0.0.0-canary.8057c37.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.8057c37.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.8057c37.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.8057c37.0","fusion-test-utils":"0.0.0-canary.8057c37.0","fusion-tokens":"0.0.0-canary.8057c37.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.8057c37.0","fusion-tokens":"0.0.0-canary.8057c37.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.8057c37.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.8057c37.0","_nodeVersion":"10.16.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-Y+GqNhLlR1MEPp2dWHr7ZEf89Lz5eD0juLtn8Gz9zF4GFXH9+few0n0bqbscNe3Yy0k5OJdxUMR4e0Q3O9a1Rg==","shasum":"bfb5a6cb12231697eae0b94cf9a18c9c425f6464","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.8057c37.0.tgz","fileCount":18,"unpackedSize":32865,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJd+RpmCRA9TVsSAnZWagAAX04P/jx7Ja4Z0InHPaJzaY2q\n9XCgWwf4zKVuEhMXStjZ2WZx3+gxcdCIkX75rPBHXmgzfVfRa2XHbYHaa8PF\nCzhL+cdKyswQr3pCDNxmWnA1wRIGVoLqJOMYbpKYFxoJUPkL34VTOINe18/n\nMB8qhBmp+gDoKVXbSJsibG0DockZX7sq7yBrQrIBnV2swXCyztqdXzZmANRk\newA5pn9yuPVMF48RMSGFhtsnmh/MTmBYVha7J1LVRlJ3b/thWAUaRRF/0DgC\n38IRwyqKPUxaWfXnrlRoxms33tQ4ZhtsbP5TiCM7jzRtSorAzR3FAuZsjDa9\nDHQrzNLvDlZSa75j586f/FZ5vpq/s98JdRLtb2fCWjsRw7spwJW9BlUJngAQ\n5YXXoSdEw5M4bqyhhoc+akQ3u89YbDQHk+YoTutz0GsUnKCVXSxxHmpbXDuG\nFHnMmZisij6arQe5sXKlctT6AbZ4ADjDZO/xBbYRWARS851tcYbMp61Yi8G5\nsAZghSghyZfVbRPKCMbf6ZcJohKjJ+HwURGKKlx52TYLUiux+HnS5KNIFdaq\nGBQN+90C0e15d+Fi/AFAdKzBSvqSGSBOJqwjNqmhyvGRunwvZX0dVrSZK4Ri\nfVU7OQKtlAKKqhiZ+dYiwHrJSz4gofYQFzfkLW2oMiaXxom99nC206iuNiFR\nQ5qG\r\n=ffrU\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQD8+lXJR8QMnnXRbVD5RUB4I5sHmIpkf/Nj6udGVYbX8QIgDRA3EBXDKmMfGP+BodHcEKcs3fnFFiRB+gEovetTG5s="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.8057c37.0_1576606310356_0.24775418280212436"},"_hasShrinkwrap":false},"0.0.0-canary.4d95fad.1":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.4d95fad.1","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.4d95fad.1","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.4d95fad.1","fusion-test-utils":"0.0.0-canary.4d95fad.1","fusion-tokens":"0.0.0-canary.4d95fad.1","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.4d95fad.1","fusion-tokens":"0.0.0-canary.4d95fad.1"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.4d95fad.1.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.4d95fad.1","_nodeVersion":"10.16.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-2haJdVfWwVQXXoDdIj7xGkFQ5ByYUeOftoGgw60y2zH6s+nrp+j0c2Di2gM7A3vfSQ+jMZ3RfU3dBYXB8hWo7Q==","shasum":"5c59a6b5f1b641daa48e9d92a5b4abde85b05ce5","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.4d95fad.1.tgz","fileCount":18,"unpackedSize":32929,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJd/ASaCRA9TVsSAnZWagAAVU4P/0XzzKvIiV5eoewcwJKZ\nzUUnl1tsKyRWfHtzJFimkxxZ5aoocNMuaKJeAYwr7aJiZeYlkVfFnQ8adINf\nVJz5/Sk0Hdr7s97bdBFCIDE6ix7KnSQP4+ssefwDTAkxMDIo3LxZ8/XWrW2v\n8aMlZ3l5L3/fjpFpAP+uRrqcQjAHVCihQsRq+DiTTplZWb0pQxkECQxzGA8e\ns0krFIYEnPDfvQBkNl9L9X/lGhBBmYPWgSfXqcku6Pd+JdPf/Bh708ipFsYd\nrcgMCDEY2ZO2BtQQRq4gyUeQY+YjwUVHRQNlQ79NgT/rS7d2xDSHt78s3Bby\nvzbGFBrqJQ3mAwTyGXMOGyTEeiS8l7WSuZnr7RKsb/d+QW6d6NGERvLjFEo6\nPr8xhq3+Ug55rV/rh0mjxllH3+t6hfJrNYB8XbInIpc+dWmGlU/GoDtKwpBu\njFslKTTGiOLCp+W/mNrYuPMBF7knPljPqSKhJtbqAxhJH/r/xJkuXS0JF9mq\nNnmlR8XIG1OliQyrEg6QQhA31qTN3NfDEQOtX0Xn8KHnwkrGYJntdcQFcALh\nKXPe6qsO1ZnRReKUhX6HOg38HtcvyAtuI0pkwwB5CL8nSZ8lVrMtcIbzk5JW\nZjWl3aG6CU0hWwPnghNffx0eE2MgcL6afU0fYu7tt/ePx7JeYZG77Wutar53\ntMjw\r\n=a2im\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDe2Xs95ehHNbGPnFyMRv/kaEPstPTq2Zm6qYs8pV2toAIgLOVLKWNyaI1Vmh+WN88gJAIkP5CNPT1NvYjfesqRsEE="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.4d95fad.1_1576797337785_0.3864101164806708"},"_hasShrinkwrap":false},"0.0.0-canary.39fc7dc.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.39fc7dc.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.39fc7dc.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.39fc7dc.0","fusion-test-utils":"0.0.0-canary.39fc7dc.0","fusion-tokens":"0.0.0-canary.39fc7dc.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.39fc7dc.0","fusion-tokens":"0.0.0-canary.39fc7dc.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.39fc7dc.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.39fc7dc.0","_nodeVersion":"10.16.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-bwh9Hu+c/3IcnTGzzjaKxo9ClkOFWLwHc9SpLd7vV3uS9LTS5iiM+pAEg0aRQG6F4Aq60AZwGcxvY2xkKqfBTg==","shasum":"24468371be43527e754709af6bd1981fa4e5bb68","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.39fc7dc.0.tgz","fileCount":18,"unpackedSize":32929,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeBSeqCRA9TVsSAnZWagAA9DIP/AwMpY44moSMUC2TrKE2\n4avpqNfIrGL+yl9Aao8E+akIEGKoX38uA5e22OyPgFpKFSXF3hacEw/Mt4Ex\nxG0RS2FcCsw+En7AnYUC6Icc0m2V04X9kYsivVZh3IZg8SEcFjqpL+NhKLw1\n3Rs1ribmRvBTHD5W+HGcE3eP+cIEdR6sdEO/q97xGIybFID4ufUWa3kEPccX\ng107nZMoRYix6Uba4jWYNNpEdiqtXW/XlNq21hLdZpwlMuIRKLb7Lr2MqzsJ\nqnAuRF5QyngmRcvJNF8N7JesIfF5fWEV3cHs/UYvjlq6YkEXnSHwWJKLdKds\nVEI/QTP+DApPE0FlpXDLULo5i3AH77ZoTe6sQ7ZfKVbZ6eU5hdtpyvzX0Wys\n3DQucttXgH04shOL9s2VfE50TdNnc8IXytpb+eXs6Tw9xMttASlYudX3Becq\nFcc5qZ4Qmla/6ORb/e28CWkcCvH/bk7UmBR9/cU9WephYhf0fF9oN6McJ2cH\nqykuWX2DigaIKXkeQaUJpqeZF807hAOwqkB0o5f3wA5g2guTOQGtWV+NvUpJ\n4A1XsKhrrtndcE+HdVZ4fzl5F/6Tyq5j+Qxc0VBMjRNodXDuM4Kd9ns5uSbH\nwFf1kdubigAu16vD7imG3SKcRDHvEp8lV3kYjsw5yFYXI1vhHqiBRliRnsE2\nTK8h\r\n=kkQn\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCLUFquQNX1l+7LGwaJwMgS197emuNej73fL6I7+Yfz7QIhAK5ze9AF5z6ZjDbkLjVtBIsZ/CHFDhXxNfQafHM3/9az"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.39fc7dc.0_1577396137924_0.9757792609360447"},"_hasShrinkwrap":false},"0.0.0-canary.549dba2.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.549dba2.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.549dba2.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.549dba2.0","fusion-test-utils":"0.0.0-canary.549dba2.0","fusion-tokens":"0.0.0-canary.549dba2.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.549dba2.0","fusion-tokens":"0.0.0-canary.549dba2.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.549dba2.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.549dba2.0","_nodeVersion":"10.16.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-jWSJGS7LHslkV8K8sVXxz4HOtlqT6/LUu4Dlb2+UreO+KUZyHM6jbTJbyOAPvp/oj0Zm2MB3SbClkQS4rX5VAw==","shasum":"53361380a34224a46184addd2ab80d08b35d52ed","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.549dba2.0.tgz","fileCount":18,"unpackedSize":32929,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeE9iRCRA9TVsSAnZWagAAIGYP/0ky85DQdspOHLMfVR+Y\nHEg011os1X0K8VVJjU1cvp0qNnwYqSqOgnwkSDSLIOlXB81RU6RjRva1VtIM\nXdp9JeLeY+LBMi7+fc1zmDgAur+pXMo2kdjRWAyINnMXGXrcy1G00tutyU03\nsrEjEwFH6/4INXfsgYXtANTIDixhvqCmiYQh2fUHXBGe3NvPnOe8FulM/RG8\nnVAXlqkgJU/8Git8bTgDdEz4/QgOWkAZz3MjOK6SVuAi8iCYcvqTDhWBtGwc\nSHsMDrs/LK79BiVdUTGLe6T6Gm2OtCxaGJtaFeWXcp5K4/mEnjyZ24vXeGGG\npHR646L2V8KCxWdry7RDsx/wJmfDFcSy19u8fDbKd09b/TfwmvT/XLtcMYWm\n7KOVhDa7NAKzFVF7r/CQeXVLCPdqcAdJv1YjXzdCHnjbfK+P0cPKL6DdkboF\nWUbjUBJzAQHWm1/GHaygJkWyMtanqKO3sD9sE3xfbvi2uhM0LYKqzrW5ER5u\n7e2ty9mjDdnOmz57COVBfDXOJB821YKRxbT2tEiKgRePnbKMJzqm3PB3lcar\ngb8UjsG9N9qjBW1VrnzEIHeTXPwsjcvVfaTnSfaWLEWwmrOyeWanTHR4Ji77\n44bWOsy/LQ+w+j9Gt3NPse4Fu/HXUV96xygW+lIqQA9ClGdr6TLPCvN6ixcp\n5zPc\r\n=jhtf\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCiKsQmNQEYHVtSSYu4iOIDNGFnaGos/cwYwjSxBfM3FwIga5VpRke1nAj3iYawWdyYx/Zcv5LQ/gxMCiCpeGP+oHM="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.549dba2.0_1578358929350_0.7060442824569577"},"_hasShrinkwrap":false},"0.0.0-canary.69f275d.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.69f275d.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.69f275d.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.69f275d.0","fusion-test-utils":"0.0.0-canary.69f275d.0","fusion-tokens":"0.0.0-canary.69f275d.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.69f275d.0","fusion-tokens":"0.0.0-canary.69f275d.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.69f275d.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.69f275d.0","_nodeVersion":"10.16.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-q8taO74QXObw4PaOKvojuI9apJETTgtuD6Kd1GnbLll9pA4cNI7ARoJEiwrfiesOWE0/kPJtWNSHtrpAhrFetg==","shasum":"2a55a401c6d60aa9e8eb5716702c9a7c714a2aaa","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.69f275d.0.tgz","fileCount":18,"unpackedSize":32929,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeFRjVCRA9TVsSAnZWagAAdHEP+QDgZoXsZvmQlzTbLJAx\nmo8u+IMMw9EDzXMDE24N1aB+/VKAJWe7oOI68QY5Q6m+UjXRSSM2wdrQ3H8W\nosUfiXV20bi5OsMei5eVTfDj2H+4BBw0HixrhevPhebFw1x51TQURFQsOhYs\nwWgs/q0j1T2QyKbwrd1Wu62JDLwAgwNkKy1kViwx8gfLJKkyi9fkTZrvjW2V\nDRtm0rIVItxYyQBivuAbn7WmKIEo8rU+qO/bZ/SEruxfrLPVqiS3li1HpQsC\nPirvgftMwoiAPnE7uxNT/H5jl00IlXl14YdQjaNLkkV40+CwNqw3YDpSdusY\n0miHdB6sXeiFtGG8ZrTF6/aiM43t6mh4M9VlJERidKpA6+f3H6QmLP13seOO\n6tF+Unbw63Xr9ucw934x4SGabkQ0lDJ67jpzCYnUq8j6l6uSflMS5FW9UGJG\njeNM1LFemSlDBnriXylx3giK+ntl2JUmx+vtQ8LAMKReH7nD3AUKTBeTvApo\njwKIGvweN7ITC/MX1C68J7uEwUgOINYLaOcztWKMrmASzfN87+sP6QQVcaUy\nRg02TLvGprPGgIc9B/KYW6MWdXkymUvX8psnJLnRvdr6SlaAqBNA4dbOWSX/\n+TM3scQ1eB/n4HHc5+3mnC45CL1dEICFj6TIqAZ3xEv3mj+U6E2BF8Xhsryf\nt09g\r\n=UE6n\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIGm8Kt11o8T9S+CvfZ9jDwEs5wTchMYiBMisgswZrclnAiAMFhSkVADA5ZaXl0dAbnRCSZdOFFf1EPOctoMei8VchA=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.69f275d.0_1578440917473_0.43675194594723643"},"_hasShrinkwrap":false},"0.0.0-canary.1d2aed6.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.1d2aed6.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.1d2aed6.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.1d2aed6.0","fusion-test-utils":"0.0.0-canary.1d2aed6.0","fusion-tokens":"0.0.0-canary.1d2aed6.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.1d2aed6.0","fusion-tokens":"0.0.0-canary.1d2aed6.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.1d2aed6.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.1d2aed6.0","_nodeVersion":"10.16.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-KNPe7/ZGHGKCv7LSxbDR4VP1SWrNilLIKyNbCYv2vjkg5MX6eYB36Ry9MJhWJdz5ko3mWJynnO0VffzkBL92rg==","shasum":"c67bb6795a84b9ad299cf58cee29a582bf7b0a59","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.1d2aed6.0.tgz","fileCount":18,"unpackedSize":32929,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeFm+SCRA9TVsSAnZWagAAJqsQAJMDWqUaN1Lvjsvk1QPk\n3NBlIfRmoq0cS7BLtpI6hj5JQ9ouhssWSP/TZmBwQFpg8+jahY7jn/ySrAHJ\n8PzM6hvqYPmsl87lxlF0NSY1rj+mH2uY1ow2w7T2rPT2kmjPEknOXrK5OZsV\nCt39BkFQMvv0yxiZoExT3ML66+lJyfOsgMrubzCIj7bhNHIGMMx0iNHqO9lT\nBLn8gxNnkEEcvN/1rDlyQGdB+dB0yZlpDOQB8eZadIePkAQMpKpQn/VixCNi\n/DaaDIjqI6nkjhNhbQkS/nNNhpzlFq+MTuUSaRKif6iKr09vssr7kqSyBkfg\nHEIdhl5ktOB1Q7s7fPQa1hGr7vJVDB/mXUFePC01NE3SXrCekg1Kb50sOWGL\nyV8QOpQXCui3Z8TIiB+cmv5LVTWkcnPvqigI/n7p3DrJVXYW9TzFyo5WLdCS\nnBXTcVK2uD66WBV+q1hFaaXZfRPcU7nV+iqQDgKj0EgSG43HalyHcys8aJsg\n6dpCob7c3NMgrdaX2wnetj6VJLfaOMQkaeGRq5phyViXKyo7WedBi+oX58RU\nbU5BOueq2+9xd7DX+vqbvv2gcEffojXpGUuV7+llXNsRwgX9IOEDVUqTedYU\numSdcK53e5Jz5LGk8DHfBFbLqzYfUo0HjMBF3g68mzN/hZA/TeNG7fknFZPV\nsOB+\r\n=370T\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCD49LI2OLUIp34q4OQ9Sd+bk9XSADqKxkgoI9TaO0spwIgL5yiJVSuZ8zUF+t9Ol8+Rh/2EzoqszAvpELAiSdMq8s="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.1d2aed6.0_1578528658161_0.6539341223451112"},"_hasShrinkwrap":false},"0.0.0-canary.7ed789a.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.7ed789a.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.7ed789a.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.7ed789a.0","fusion-test-utils":"0.0.0-canary.7ed789a.0","fusion-tokens":"0.0.0-canary.7ed789a.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.7ed789a.0","fusion-tokens":"0.0.0-canary.7ed789a.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.7ed789a.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.7ed789a.0","_nodeVersion":"10.16.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-Z+OnJIvyF58jvFeX0Yg62yy1q1Q+YXlOdjYVwZLc0ld4sti7pFFdf3lOA9egEMPUDzNOtn/bjurzdaOL5/rCaA==","shasum":"76b5bcea2c4a38fc72c196172d2662d9d04246e9","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.7ed789a.0.tgz","fileCount":18,"unpackedSize":32929,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeFn/1CRA9TVsSAnZWagAA5dMP+wcEHParEMX1LP1poBEj\nie2q0LeRBlLuz99GwuGqDVDOytHIUBVf1IdmkYFU2jG9wa6MwixFHU6Sjmq5\nZ/el4b1dWBPVfZUA44HTn1o1Xh9z1V7XF1V0bbuAj46GVYmytq+69AMko5bh\nxh5vtTL1lCz7UlWlybSG/7IUkAIqzqX+yv/47RnE6MApcm/K9xWe4MESlpKN\nsISn5XZHrNBolR6+OO6e+LMahrH9VC/Y2cpzUpf2w01QJAkWbICYZIP0CALN\nfLiE469NcgrQS/brH1fIVRFsrkvqXqjk3GHlzzTTGfTZr9yAsg8IF4GuBfV0\n5AxYXHTrx7tau8B+6Mo6qIVjr0Jj0ij1/XDucgV9PCLG9HrfdiV8ys24BJbN\nqzDIi5BL5044G720BjSzwI0BmS2L2wFYpFS4QquErOgBghmtCa3p66Zqz5Mf\nc9PMzWL76lxcvI2v6FA8UkoPQ0hToknONAnXb4piuOAefPpPjoARiWQYW+Ha\nM1E6q0HIbJvB3/1Sc1MtPq/22X6GLhbTY2hiaFLL8g0oX7kqY8lHxPTd8HOd\np8WfnAraYJcEWactr7EzneJuigMX24qkUZdkUhyPMPxEG0vhpOBAL38FdOAC\nozNfPH06qWCI2CgiN/CzCUMmqizNPaK/+O2mBmtMPODk5dsACZ4AGGfHrKKK\n4r6l\r\n=X80e\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIDBEsLthQGNn6MJMhEXbUpdhFavkM269EK9w5lW1GU2QAiACZN7ipVQi6Da7dQyFCBT10E6odhvFJdU0uARInSA/rA=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.7ed789a.0_1578532853146_0.45871789710691746"},"_hasShrinkwrap":false},"0.0.0-canary.cd789cd.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.cd789cd.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.cd789cd.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.cd789cd.0","fusion-test-utils":"0.0.0-canary.cd789cd.0","fusion-tokens":"0.0.0-canary.cd789cd.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.cd789cd.0","fusion-tokens":"0.0.0-canary.cd789cd.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.cd789cd.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.cd789cd.0","_nodeVersion":"10.16.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-SrgjppcuAbQHc6u73lY5QEqTMDGKmb8FANwssXtemjZUX+++I4N8z8O7ZMLeP+Nx7AsAonjGocUjdD92W0NLug==","shasum":"af92d5ac483a6fb3397d2edb537623393142095a","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.cd789cd.0.tgz","fileCount":18,"unpackedSize":32929,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeGOjICRA9TVsSAnZWagAAg0UP/1n+U+pBnQwUzx4nsUI/\nKyuyVRgcVjN53b2GhpexuRd3YPZC5mJu00twlQBUIFunggZMCFOeYGt1Rm0t\neR07HVzNxxlMMYUACnsOz6l99dTDzYjkzlyuI9CmCq70mpFSzmXn6OD6E/WF\nK0x9jlz6pLtJSAK8ucTKY8IyqkDOuXVJI7rVxrcxIrbBfOA41kWXRHv11kde\nNiAHrLe/VnN94SwNUyjvchbgiMOAM//K/oNXzZuyJCTfNpL91Xe/w4qMTh+c\nw7kM2IhL7CzOdyVA5kBI7z41+zx7K4QREoXnjn4laOP9vRiGt7+QqrBUtddW\ndW22xiQdQ+cJ1RmevybAuXRKqYBMpFs5QoKM/0vtleDxl4cxjukeHbRi6ho4\na6sRtoA7wSisxghQ6og457OFfaBwtASBk2yPhFcV7c39/ky/YE6nJxGhZZ/D\nJffWewpxIaqNCXQPjlq44arsjYINTkEZLSJV90dl8VgPiUueuRWL/G6uJ/st\nxeounQoO57mmMfRtgfbUuQiXVKuUoFWO6+M1iz2Hsm3WnCvcuXc0fClvX388\n2StSCZMtxNRYqB2rOzJQg7c2xlQM4Y+PBKu9ANaU4smnOuwm9lqOBHGBq5p8\njwzRxTc43+xm5aF9+3Bdh0Ks2UGlsbQhJccivz54G09mpaqOAO9uCXvohQRK\nt1Pv\r\n=o4JA\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCSXz6IIaZppbyfkieTX6tAhdULBky8SIs6qAI0XZ6gigIhAOyaM92ztkLobuN00W9xQfiYaW8LccGeiI9X16sEdm0x"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.cd789cd.0_1578690759724_0.8549728843631645"},"_hasShrinkwrap":false},"0.0.0-canary.ee6892e.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.ee6892e.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.ee6892e.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.ee6892e.0","fusion-test-utils":"0.0.0-canary.ee6892e.0","fusion-tokens":"0.0.0-canary.ee6892e.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.ee6892e.0","fusion-tokens":"0.0.0-canary.ee6892e.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.ee6892e.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.ee6892e.0","_nodeVersion":"10.16.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-mEL6WJ42MR2QP0GTt24pwedlnhLF7RzLRnQMV9vq8A82RShlUF/d0ry+ypzl/rpnihcVTJQhq6cDU0QdVZfRCg==","shasum":"fcb3bb208478b5d448c1549daf66b035144cdded","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.ee6892e.0.tgz","fileCount":18,"unpackedSize":32929,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeGPPOCRA9TVsSAnZWagAA2QQP/2/QxJNkto3IwWWI7DcB\nGomh4EwLVSmTRvaD7EcSUtP2RJiKyLWmXOyYCqjz4xOivgCghWsu2XqoYK5q\nUFpDkzFE5CPgzeJ92R5WuR9YerrKDemjxY/PrlqrB1ytpmzkqzx0ogEWUpMp\nlyMF616Xt0qaHrJW3yuTdnmJzfHh0Q348KTG6xld7Hv3WT3z0QKufZ/ZmcIM\nu3U/42TMyacQTWhMrmth1ZKtfhRJkVz8NIPut0mSt7xrCHde7EdBVcMRtyea\ntagdw8N6M4WHMwGDVmfMC4iC/80aRCgY6DuvJyk68EXXaSwYgfSOTW60RFbY\naL24L6eJbfI8fOWRT6t8u9EOMXnr6DWfANxMM6O3EOwHNBbfEdF8k/sDOWs5\n+/lsLl0KnygMLcicbln9ccvx8gvy8qkb5QVs0ZpYyYk1JipjZUFVLs+EIWFY\n8nsTjCh5gn4A2Ml10dp3vkvCXDRpAeUjvYIgBSBGQKclVPvzP09o8EcYl2rR\nuqN+pm1YOmoBNfm9c8EWszAwcdWzV01HME4yft2GUXd3cEqMt16sATZSoXDj\nPpL1vx8wCOh3Dk+E/WAG7RtAPslbemlSrIcJ7ZCh0EGUHldPd2BMZW1hSQ+A\n+yUc3jYQout5yNq2eh3WM+fAFMstKozb+9W+ITN0fK8ZX/Quur+Hcb5eosve\nOsvc\r\n=7gv2\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDiP8tG/7GLtB/VP8AnqWVtarFH9fLZvSoTuT4/YpSPOgIhALmqaEeYqKwMVaOdyn0ospb/L6RD2mLEip3oTR2T8zRB"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.ee6892e.0_1578693581682_0.8683464201055744"},"_hasShrinkwrap":false},"0.0.0-canary.abffccd.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.abffccd.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.abffccd.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.abffccd.0","fusion-test-utils":"0.0.0-canary.abffccd.0","fusion-tokens":"0.0.0-canary.abffccd.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.abffccd.0","fusion-tokens":"0.0.0-canary.abffccd.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.abffccd.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.abffccd.0","_nodeVersion":"10.16.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-cTWdkjZevXWH6TGawbXWQleBczQKQyajG3W5JIcxSbb1srTOUXFpE2s5Uks/RwpcVyjdh5DS/ZLnc/LbC5GIYA==","shasum":"cf6cbed4c1110a16e81a716470a7d4e5cc1874f2","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.abffccd.0.tgz","fileCount":18,"unpackedSize":32929,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeGRnfCRA9TVsSAnZWagAAqKcP/jyOoiVnqNULmRF7LbED\nNIBAwjSeI7xZGs5Ji7iOmp+TprVy5Zb+Zg/PqTzXD9XXMAcJquSRKGiu/to6\nA6nwtXb9rVhFOtMs9mA9JO7pR9l36iG5BdKkdhWc4FDF72IFFK0bIXKTw6bM\nav6sohtomxWDQGyaCh8HYfP7O50PrArMtciSGT0Z9vlNAXsMz+Giq/odTAq1\nmZXgk6+q6uH4Egbe+zB7uBcwwAN4UuVnlUBzaPKgglasioj4+DiKiEDpsRao\nrFznUp5fMiQmLtRjcmKaqpXBWYUhrVIZDjImpKNaGNo8FQXGnnKeyB3QZqgW\nSYEo+xAajOxv2WFc20EDSSGlWYDF/2432vIvQ1gZnlTZfCN2tOY16eH/vgPV\nA7FB+IXmprKu3c0auCCc2OV5sZDuCmGMyimnh5mSo9lU6mytkVZoHn99juMo\nlP03Qg5OrJ6Vk2kxaO6WPvT1YDVpvRVjtoT/N9IzTd5LzQQmDriJGL8/aD6A\nq174ouhdbTeZUOVxKwy0XC8pKvD36g3yEgVwg6Nngxl0ZaSCexU3lZq++16D\nq231xrb25yscFchoKEgVqABuAT5JqgZ2dwJSFEPr7S3q5MIXqwvlA1xfrrGg\nM5XoFoAEFj5NuUucPmNCWL5SbzCB83ivfUVK3xtoWTMyTIsy91DLgTs23+ih\n0MDl\r\n=8JxK\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIFfmn4tzv1Dp1w2XsvGI31SW0oRVdIQnY3r0pdL3ztlJAiBQVceuxl95AizWUTST6SpsxEp1jYOVd3Xv36GrTc5fJw=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.abffccd.0_1578703327117_0.34553296396525246"},"_hasShrinkwrap":false},"0.0.0-canary.b94debb.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.b94debb.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.b94debb.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.b94debb.0","fusion-test-utils":"0.0.0-canary.b94debb.0","fusion-tokens":"0.0.0-canary.b94debb.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.b94debb.0","fusion-tokens":"0.0.0-canary.b94debb.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.b94debb.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.b94debb.0","_nodeVersion":"10.16.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-8zPur297chz7PrOCQEWceTet+Y4JfkI/7yixnarqd/F46TxCajB4SIDMh022Sof0pPxecXZS8JL2QYaflOC/Ow==","shasum":"7de94d206191ec714787308983ee67c3d5f217ea","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.b94debb.0.tgz","fileCount":18,"unpackedSize":32929,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeGSNeCRA9TVsSAnZWagAAhb8P+wXmbnICbzFK2E7YwNnl\ncBAuJqmn6bbafG7LI7IO+X//GcqnIIqbeG41gX+x6avYlxB4aeb64A0RAD40\nEDhTWuKzejFZQLPfSEUVPnQwyzs+awF5RgPdRNDwJPoKTyscXBBjz3ReY805\nmdhw67TiK2RRWzrD7w17nAu9tEreeOFnFaLHSq+fzZtULl9MM89D+AflWm2H\nMVIlfHKReKmnVa8VRDyWH2d75PqalU9Jl+LTOki8NRu/A/FWRLtAC1Gcn65F\nXUUQ9HdlrWnLa39aqP6rYjg57/tEL6K3puf4T6xIzaWE7MNkgEIsRaFONHaA\nPVc2cJc+s3NREVyzS7Z6cseCDwTi1vrAGRQrCqd8akljgbq9uxjPbOf0d3X7\n52RrYz/GCucdpCVG7ZimPra5QyX2Q7F04YhKK34AWLYFY1LSlNSp06A73X0P\nbYcLHlAHbIiEJLyYwnenIs2Y0tFvi1IjENlbSV59dkYnKJlqj4G4rawA9SVf\nv3A4XkdDnlrnRF+Aak4cBOR+GcB1xGXlNZ6eJQjOB/TDhGbvgc3tSK5IUsyb\nl1PyE3AXPwAUgBrRWVL3RR6+DaqsqmsYQVxIf0RxrQDqszAI9yew2W4Ko9aq\n965qwlBcJfSxYnBDrJDADNUacBS+nLkmK/xRp7WYRONqLxNq7SgFEyzlMHYc\np+XT\r\n=9D8j\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDsbde5gnFbCs9to/V0+P/zwfLdRxzEsS2RE+3eLvP4tQIhANYNCMb70iH0XrMcw1vJxIZ+H0X599yMsQuzhakXPpfG"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.b94debb.0_1578705758120_0.8225775968839377"},"_hasShrinkwrap":false},"3.0.9":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"3.0.9","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"6.0.7","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"2.0.9","fusion-test-utils":"2.0.9","fusion-tokens":"2.0.9","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"2.0.9","fusion-tokens":"2.0.9"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-3.0.9.tgz","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@3.0.9","_nodeVersion":"10.16.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-HtJLc0hcVTGnXMs9R5Vm+Fz/V7UtYp1B9zr4ovJqA+PhmKocyEr+3Okcnsc4ApwHAUWnQB7nGrnkpG79xeijyg==","shasum":"6d2061d0adf8e8a358a3f3faf833b8b38bacb46b","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-3.0.9.tgz","fileCount":18,"unpackedSize":32810,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeHQ8aCRA9TVsSAnZWagAAvTEQAJwXAD5ChzCRBl0LxiCM\nvVqOkwIIBS5XTaUuRaiCeiRJxrs+vN3DEWN4HjzKkeov8vJmUKsgXWdpiKjH\nywvjHs7A/oawHwjMRuzY0kUU6+3FPGRMr18dFdD4tvDIb/oBwKBm5mC1ReV0\nHIQzyrJlKOADauTl1iiGooBonWvsgOi/vADgVkGnBIJubPIL8nPMK8ZKb0cd\ntmwGtV64wFd3CiO8SJtGshuJvLd+4QWjYX3R3U2rHn7XvUG6DE+drstCxg2Q\n3kvKXjYwwIfSzY/UNd5qBWGM8WXe6sS8sDljK4DXHalmrw+2alZGxLBOkK+Y\nfndVTe4fr0XyuhYsnCAkcFwOGsTVESPVpGGbfJntA3H4cLeik1qySSge1ocB\nsknRXchpeYbtcGF5ydiLNFf6f97CkqfVfPG0DxGnyWVnDnmPcH5p3BF7mJ66\nRE1kxJ8lSKHE9tdukQ5szs/BqCU2WcVgnyLfmvJlSVPEixu42RdPBNwNo+bF\nobMPrrEOU5ab0qSf+VlzifXyohAtRuQz8N8PrlTgybtaRLAY/jnVDEFSYh2s\npJSwfPyMWfEdBzk3onWgAAzXjeYgh/gxL5i6Xl80oC1h/m7RSVNkKXW3F0Gr\n9m8+gh9t7EHR7Jx3ZZPiy6AOEveNo0Z1U2iDTbb+k2LkA9tUBGJyeNYLti0r\nTe8L\r\n=FJlN\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCICS3hWoqmXk3Nc/s4wdVocOF1fvxJ4CGS6QuCyoQWnYdAiEAtATeSPOk54visaWK++WDw6fJD9RyHlH+TwRaQniC/kU="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_3.0.9_1578962713735_0.9747596690966767"},"_hasShrinkwrap":false},"0.0.0-canary.659c743.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.659c743.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.659c743.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.659c743.0","fusion-test-utils":"0.0.0-canary.659c743.0","fusion-tokens":"0.0.0-canary.659c743.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.659c743.0","fusion-tokens":"0.0.0-canary.659c743.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.659c743.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.659c743.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-r8ZPRz9+UyrcQ3B3fIFGhImi3n1kDJMZbh4Q5lEREOSL03EfcLI6l+wDsySNZ7VdvZbgtNqYRVpJljJgydyMNA==","shasum":"a256453f5497a27925cb604bb1930468384d17e7","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.659c743.0.tgz","fileCount":18,"unpackedSize":32929,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeKKblCRA9TVsSAnZWagAAt80P+QAxkKKl6B7I3QbD0GD2\nVnY5Mei9abhEe2ZD1TungolLkukSMvZhliuSZ5zfKAFcz8oVz5nKzTWW8XfX\nPUBZrKdSjnWzLmrgeRgjk7pAgv0ch8KG295d59QHun2Hotq2uCkBx7wbo3Sg\ndS6bUJE4OBmEsCTfFI3cC8NZQYnadWjvfVqIz22WlJGM03HaEVpJ7A3g1xkF\ntw3bjSmMfzQ6faVomoMo7hSdNdu+ulp1+MDel1lMxXZY8vd8qQJxmi+BL6Fq\n4DCEp1ph82w4AdlmmhaKl4rgSOyR0UIqmNz4LTJahUMy8E8SLBDTRnp2Kh1+\nKyVwBL27W2MyyWSv6r6myRQ8kZKDRVj9ja1BuBqcrg7DfbH8RXXicyt0NffY\nLiyYI3XQNO+00rqiXAODMipUhhlhcKZZQ9Z91vllk3t8189AbJDwbIY48TFQ\n8kAkLOH7jrCd2MZXOZGJVNg/Fxruh2ybie7bsE9LpR0fYWtRLisjyxAjXwUN\nCBcmoThOb9b9zR5Qe4zgtJh9dXe2HIkYa3USuse0FY4fnVW4ilGYVmrBOGUK\nMi8+0yeJKK6EoAoAuP3Ao3K9OLZFercJu2NK2M0CkWwGg2VIj8E+fGp9ve67\nzrWhPdBgOoaxTywEVI2BFurjbCJahwsQUQwc6KYUy8FV8RGZm4BT7qKepE63\nEtEt\r\n=/eXe\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIBPBun66dNbkjBMFk9MqOOWuEF2MLQQNzX/LCRNBtOQVAiBOcEokMA+BnbxrKA/jc8RIu2AuL8QZKeMCQqzNCrU6wg=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.659c743.0_1579722469121_0.7127637615661608"},"_hasShrinkwrap":false},"0.0.0-canary.df13289.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.df13289.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.df13289.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.df13289.0","fusion-test-utils":"0.0.0-canary.df13289.0","fusion-tokens":"0.0.0-canary.df13289.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.df13289.0","fusion-tokens":"0.0.0-canary.df13289.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.df13289.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.df13289.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-y8tZvb4rb42aWefnhypeR1740nSYC0wiNXoub+CIGMLvV6ZlvbI4ydmUoOrxG+wE1q0H4yUEFxtt6K+mhGLgCw==","shasum":"9b92c80f32d71065cea32a1e59f77786b882e76b","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.df13289.0.tgz","fileCount":18,"unpackedSize":32929,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeKP1ECRA9TVsSAnZWagAA4s4P+wXJPNEhQzJl1WxUQJs9\n14vW6Gs8O2EM6nHAH43MxBVyadzCWg9Z/yOwoCZtirCb18Nj5ZvcztoOfjNV\nnem2rH52Htpa9ThbscNYG/O6DKzGT7dmC9W9WjYL5SJmY1OmN0LcI4syzFHr\nd5n4wqhARCUtNWcaV0L9uwwRA423tqqmOU++K+51RaiyHbVQy780B4JZ1niz\nofWmVBECqB/a4ut+YI9nyjTh4fl1M+2N2KOI6gOh7VRdDnBopt4TyigTczdv\nhj4S4SrQjeV4OlEEKK50g3xYq99sFtK5QuHFeYjx0cTYgNXop4MQZePDuWb8\nWn/7Xq9Mb8+YUCvwAfSKlM6mZYJHhh3OcPrtIuI/acQTFKgcs0CVXSGS2TII\ngjtxaLnazNl6BzQq4twHtcn2obwzK8lAyDmFRNWei+Ou9LBGJxT4H4RnhX9X\nLTtmDsXsRWKi6hFjGo74y7WOTaEXTzOQcXa5frQ9F599MI9r4N0NjHiWY1i1\nzgaWF44cwLb11U+0YIS9mbl1NC+2Qbi0XmhxVLR7eA0d1zoPBXKb1tQmhdjp\nMeLmbmz0EBxbBGESaiea5Jh0DLhQ4hQ6+3Qm4kRBlAcexUxBXOY6MwMmwS7I\nbxEX2Rlsp6hxFnUJ/01mRs6Ido8cHS8tXWUcVS/4WKIGBbSktCoQ3njPLDwD\negIi\r\n=GVIt\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDs0ZpzugXfkdk+EXfSsb1s1cDqtYxIBDUMuxEWIFiNLwIhAOYXOOTko7QyeyC3VG0OfmHr6KCKUAml8fdN76NL3ldW"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.df13289.0_1579744579945_0.0651886706297169"},"_hasShrinkwrap":false},"0.0.0-canary.79c5c12.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.79c5c12.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.79c5c12.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.79c5c12.0","fusion-test-utils":"0.0.0-canary.79c5c12.0","fusion-tokens":"0.0.0-canary.79c5c12.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.79c5c12.0","fusion-tokens":"0.0.0-canary.79c5c12.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.79c5c12.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.79c5c12.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-swvcDXZ7td6cBDz/lSB8WTvLHO4yQe1iQ443pcPQklAVPINRKU2jeMy83sUVH5OJgIrOWn4J6zzDyvRnj1AhFg==","shasum":"1e2fc9eb425306997fbfee0e6a73ccb6c4538a58","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.79c5c12.0.tgz","fileCount":18,"unpackedSize":32929,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeKfMTCRA9TVsSAnZWagAAqZUP/R2A/KTGcyzjDMisTpf5\nLmsxCkGatBTL5WzmyxI6An19P2uJAgbZfyjcyRK8QsjiTzGEzN9U3QodoBCn\nq/8hsk8Y5/8SMNWFgcshN9IdZLPks2V0X1g/f7aBY4OchDVyGggM8tVgW5+7\nybTFXqxV4xv8RNqEG2OXo+F3/guVT1T+Ep1ycx8jroOHwjumKLJfwnpiyItM\nlFLAKzIOxEf4GQRR3fPr6lZZwKSfsHN/YJHXOPtd3IFmWEXooWbUr5j/Y3xj\n7i0R2kf/3WB8QRG8BvFnYU7zMqygSbzqnbdc+mnxEIewROYSWT0t0czr4AyJ\nMnjxg88xuxdGLSkg0fhJ2l4QCassPs4lRU63ipf+AyhId790/c12vezeSan+\nxGGZ07SwXTCQjLfc7v6NYTeu1yrKuM4EAsVWsBZQcCBkpTh31DDeU83aInhW\nEQjn3hm8hzlPvdfCg2qxgipIjbGXu1y3Ld/RMwZ0zANeL1rQeM2pXq7hiGDg\nsAj2lJ35Xy/8DpD5y4TXIbBF6OLtioXJD/MlbMgb1iuVLGIn7YralGAW5xhA\nC1Iv9TRCo1thxai4xGDjOFbQ3+j8BEfANDlSGL1Yb1ljT6PcFL//AjyWRS25\nqzqGydIv500oBAWyE05WSH9VqgRcZA8X312gkS1LAA4TzVm4ojPLyutT3JHw\nZZ1H\r\n=sQLf\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIHb2wmeg86y3zMwZpFa23TvjeSMKMSCTsRIRwF2RzlLZAiBp3tUuouHI9uqcRsr4PaV/6htMGf7ADaOPOnyuUe9ntA=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.79c5c12.0_1579807507094_0.7622812831469172"},"_hasShrinkwrap":false},"0.0.0-canary.3a8e24a.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.3a8e24a.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.3a8e24a.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.3a8e24a.0","fusion-test-utils":"0.0.0-canary.3a8e24a.0","fusion-tokens":"0.0.0-canary.3a8e24a.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.3a8e24a.0","fusion-tokens":"0.0.0-canary.3a8e24a.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.3a8e24a.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.3a8e24a.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-JPzJKu6YvxrgMu1AX70lx9rq4CJb8CMLc5rKmBsJkOHaRTaL5SC9iSGhdeKCb5iiE3QAR5ru/tL3MsLYl5WqYA==","shasum":"73a15b4d60a8881084df8b6f85c1634113e18421","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.3a8e24a.0.tgz","fileCount":18,"unpackedSize":32929,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeKiNzCRA9TVsSAnZWagAA8gcP/Av5IdC6VfjVttS3yPFS\nS7NKtpwbMuIzDjiVVfoy96rTZwRmPVTYZegVIRRlZlkrfRW9SPNYN7SRzAz3\nXLsFpEpJPVPyrtL9sDoT1U3DNlGaYZQym//t0zkzuzjAXzx9jFgYh7f0jCFT\nMUjXhu/dujF5WNwXMwyYywXz0Ljy9nTxSA+16LpLXvnq2+e9//+7KTieOPct\n3yWa9P0+6QaiP4PACCYlb6fxvQ7VHozA4wQy4DYULSSqtnl0aOf7mSKeO7uK\n4ulUkPzXtAdTL19bppwv+QJhHCcRiwx3eFg0DjuO8/llLUzObeD6kVbgXfr7\nihnj4fhpVI6v4Ukx3K3p1IzZi1enQdCbWjk8ONkJ+/adeoyjs/aJ6r5oHKVL\nYpJcKfaGQe4wqJ6FqjrY5MKxMIfJN4xqkKya52a6B4t/Oa/6vt6pB6XRhsD2\nE7i3hNiPLLzxgkr+bm4yjeE+EtAjF/r9zykkq9UR7hTmVE5c4qaVcanLnISO\nYFwGPV9S3hTYtiPPwzDzyAOSJhYNuJyuhbt9aRTMAwLyVY+GXqhkIuLKAowb\nPGKZPKltYpZJ2sALrjzT+VqVHBoD3RzIX3NzPMP74jCgB35NXYzV2rhO9X7P\nlxyXRQw+e3OX1rzQdELyXf9YUlSTrZ7MEvMMd0ZyuVvJZeqp+q4qvNtjdLH5\n/2jE\r\n=aLnb\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQD2OmP+050PD9D2wFI+jHCFqQZdso+/Zeom9MwbTNkKcgIhAL3g2ubiYMwMrAxKsiP6FyvOk80k0RuNW5vjA3Yr/x6g"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.3a8e24a.0_1579819891593_0.335128768755105"},"_hasShrinkwrap":false},"0.0.0-canary.55e2075.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.55e2075.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.55e2075.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.55e2075.0","fusion-test-utils":"0.0.0-canary.55e2075.0","fusion-tokens":"0.0.0-canary.55e2075.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.55e2075.0","fusion-tokens":"0.0.0-canary.55e2075.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.55e2075.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.55e2075.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-YegX64soUD5stlp4wqimdtC4h3S2G4rVvvAjFUI1tZmLhrgBH4iVNulsDR47yNlctylBOckVQQj0dw+AOQyQjg==","shasum":"4e5c01309bac03b90bee8c4a42b62203deb904db","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.55e2075.0.tgz","fileCount":18,"unpackedSize":32929,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeKj+yCRA9TVsSAnZWagAA+Z4P/3pFajh0oKRlCl5yVMHH\nSeat99TJIXQq8soffF3MrufElt6bpPIFuBKyJ8yx+zD9Aj7S8981d4+4088G\nqXtpMo9Z0GvPQlzQVVu/OnMW/Gf9NKa1B2UB/fpzQBU/RqxDFvavNZJM+Jyr\nunIkF0bteFhMx6UnOn8BdPlneabBIdhIPww25na0sFbUaPYC5WGyWtpkOPMw\nVEpCBlWtUmCZ9O9hqlLMmmRZFaksQUV7z4FAvs4ZPBXpflZIprNVCLm3TCdf\nBbVB1DWUfy0XHzNG9dopln2OJhjdlrz5LXHcVaQvxCvo4GF7CJ68uKragZhN\n6s0yap8Nu8luG9SoZuqJbeEV9YICtoaI/ySp36GI/bk0Z5cCfEuVHRG4H8pW\ncfH+GeBGPR1QPUY9EgUVddCr6fb5SaWC6gY9oYDdfiNxpw9pC023DYKaQf61\nNyB0gve/p2L9Xc4xUE0wgMnRuTz1HnngBKgX6QWpWdEPVsJ6/flK/bhxzjlV\n+TmbuvcnHtxe5qMpZpsZS4PW4LyugdBExlH9nts7Col5VdfG0if/H4tL3QBM\nbJSAdAHO6HBHpjM62pH459Gb4fUqxXET1zCw/Y6cJJBUa8ZFNZ2DXhw1ptMT\nxt/YUKlSw494guHJINXeJzrdiJO04VSsnUQmqdhlI9jvG7nj0Md1TjxuAm62\nBCdc\r\n=Yia7\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQC8hyt2Fh0Mmq6bnpGzj44+IdpHxyBGuBSIfOohEpeJjwIgfbYGeJUhAPeQe6EpS/K1TnvcrDC6B/iVUSxxppPz/N0="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.55e2075.0_1579827122227_0.15268598074414452"},"_hasShrinkwrap":false},"0.0.0-canary.294feb4.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.294feb4.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.294feb4.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.294feb4.0","fusion-test-utils":"0.0.0-canary.294feb4.0","fusion-tokens":"0.0.0-canary.294feb4.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.294feb4.0","fusion-tokens":"0.0.0-canary.294feb4.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.294feb4.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.294feb4.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-6XNuSTBFh8rq8GyBDyNHQis5zdhjET+E4LiBS3LeVYZVe0Gckqx6WKjvlSw9C884cMoq3H7hy19RqrsXnB+f/g==","shasum":"d1a92d3a200503fd9a826a33f5fc52015f2cd67c","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.294feb4.0.tgz","fileCount":18,"unpackedSize":32929,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeK2/zCRA9TVsSAnZWagAAMhAP/jkMkBjX2ssLUsUfzHFz\nVkPKVr5sLE4lMlWdi0dgYAJU8//ZuGHje/6vStkqFLZo5AQqrdwV9GEl27fY\nMB76jiPX5uoCTUw/hbiqfZMS2nEf75jmDvkgIIIT10pGlJEAg82yCr8TVpBa\n+idU4kX0xE66Pg+ZDXOhr3LfyDRbVTz4zB/O+v7IZ6ogGrHO9rb37YGEq+5J\nILjzXC2kSDb4UaRcbY9i3XQ/1ruQKhWzizmlk4UkxzchihA5ehe1G8xf2jtO\nTjUwMfRx7r5g7iVSSVGX+IRnZFOplRRvs2BCoOV5C0864v1vpv7jxj6Z26Hh\nphclTWfrAC8V6D1XEbthhsTMnS7UNv5lVXxFtaTFDgWGwjNrnlR5OFJ1LfjY\nMMTVY7xR1XEw6SIeKzaX/SN7NLwonJ8HomkIlQetXVBCZbngQZe3e8Ejrs3e\npVSqeqQwS959/QIUg+viFrB3sXHVjmnVVplwlZ5z+qc5KMISNZHxHQg9zeNW\ni/Hztd+YuGb1v3/+jw3gKRUJ3IOJFWig2Yk+lXOwWF37VMA6ZrunTA7Ai40A\nfNJ1Oa5aqL33TC3oq0FP6TX6GX+PWRJqOwqOE1BShd2+JPxOl6egxysoNR66\ndmzm2nPCBL3GfA+zoUXPk6ckNhKlkUwAZT+Y29/jjF2TvLTekoGl8MbWUwWS\nUzMN\r\n=wKWx\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCICEZIVvLjlT1ht8aWLJeFParEO4LBzUbAaGaG20GWJtGAiEAgQlE17ZO9cajpDujLUYgyjD7K8ozrYmHYuYRftInZ9M="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.294feb4.0_1579905011167_0.8528550647910171"},"_hasShrinkwrap":false},"0.0.0-canary.5c80f83.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.5c80f83.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.5c80f83.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.5c80f83.0","fusion-test-utils":"0.0.0-canary.5c80f83.0","fusion-tokens":"0.0.0-canary.5c80f83.0","generic-session":"0.1.2","get-port":"^5.0.0","prettier":"^1.18.2","sinon":"^7.1.1","jest":"^24.9.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.5c80f83.0","fusion-tokens":"0.0.0-canary.5c80f83.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.5c80f83.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.5c80f83.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-BOA85dR6f7ps39nL+C7rjIzs0f/aFx3xhqpvukkdlzl8VaGPiQ7izUN0mJt4Gjpxy2qkA/Tk7En7wslOFIME1Q==","shasum":"e8a6a2b679bd89a562f0b1f2e1902430024ba899","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.5c80f83.0.tgz","fileCount":40,"unpackedSize":182083,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeLzLYCRA9TVsSAnZWagAAdKcQAJM6ACTM6QAy7cGuRM9c\nXHpB85NX4Ugh+LygS505nNEMc6HMqPiRUnDKaJ+XnvbY3mY6V5BrDvLOxF9o\nyHS07F9L4fvmDJYBzMmKwXAoFA2uzcLqbWPZm2bT/aU7lB/+PXZSgDF2Rnim\nxz0ZTX88zKisfPDaD5WeBkq1C0vblpcrx0xjCHR5rfmt5AEzf3vViseIG392\np1QsyVnIxHSNc4Ru9R6iPS6foUo1hUzU2Q0a7El1oYbNtQlIISewU4KbyoUJ\n/WBbeyjPU6VIIt75vzSIinAWHgLl2xD7Yjiy3UUGChq4X6bjdOvglyz+s5vt\nyyJfscS/z2e4s5GeQkMpc98yrC6KAc8Y31hN3RCKHDCMFYMd4vbRgbFznmtg\nDXcHR7NvOLyixSQosOfK9M7BOC86NCpFY99ApjWuMp8JbXwXXyXZagXLCR52\nloYopbrPcX7IAu4qd8cNv241S3mn01wVRdPeytxmjY2eOk8zC75Net2lES1y\na5UcqBE2uBLMhM6zerR3TP9NzrDJxSn25JMCQiftXGW2lafjml4lmoYKOkBz\nwbh6tVd5oiGenJkm6lDDtaK5UxXiEniruE+unu/fKyQQ01DZTMClb0koyNls\nr6OzENEm22RqOX0E3aoGXykSjQJDmr0Hwmke4sk08w4Nt0OVxkJHCjQt1oc0\nSZdh\r\n=o8e9\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCmIWgY5lLozHGNLFR8Nq+QPSPJeqsJ6iR25goF210prgIhAIFOqtvsix8NpxVE7dXlIiW7pACxVKCeCZQHcI/Zq+Jp"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.5c80f83.0_1580151511610_0.17054543831102098"},"_hasShrinkwrap":false},"0.0.0-canary.cdb104d.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.cdb104d.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.cdb104d.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.cdb104d.0","fusion-test-utils":"0.0.0-canary.cdb104d.0","fusion-tokens":"0.0.0-canary.cdb104d.0","generic-session":"0.1.2","get-port":"^5.0.0","prettier":"^1.18.2","sinon":"^7.1.1","jest":"^24.9.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.cdb104d.0","fusion-tokens":"0.0.0-canary.cdb104d.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.cdb104d.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.cdb104d.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-EtdEqp0Dq/zr2H5zIH5vCds4Dx+vq+f3ZNQus0dRrkp/Ebdure2YPORaiolc5sUfN3umX2NsEhVIvUYscyTO9g==","shasum":"55ad1eb9e54a698a218acebb6ec5edc024f4048c","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.cdb104d.0.tgz","fileCount":40,"unpackedSize":182083,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeL3/ACRA9TVsSAnZWagAAuXAP/jz9Agxghz5Br7r42xVI\nUn9bJCVsFCvTa7Yfs3pa/XZXATRgitwUQ2epZU1hBcdycb+X+Yow99UgMR5j\ngr7Rc3me9gMTn1TA+QqyYFQ7Z85Dg4kmlMlE3QSHj1IKdtoZNk95slrxb6Wk\nSpTBCtZlDFLxT/yxzGOaGTKrdL4iklUZily/HOZcfLtEtwTlYR6BES3qoJKs\npO9riYHtd3jEDhSPxF0UNziZD2sRiXvenjKQHh6g238xyG2BDErNL4WnhhIz\nhBabh7ohak62ukUj/oTn39SxuGrF7otQyvsYbJkC0J2w1FyfigI2qOzgssLm\nk2pSzn8uHs03rfjEMYR8NTLNKnXcizASiPGVjbk0TntjedxustSUe8Di5jaZ\nAWi6wegGhRoD+s/CKRFEf9WF8C/+9K8CK3EaZdnXI3zv5kr4cVmf9+lWNwwx\nOALpUAQaZQRlO2XjkyJ8dg4LexVSUw4dUJtGCCJajotUyFg8vDwQisNgzdz2\nlrJW1FPnZCAU2mi68yp5F3MoaR+wLWMy26pkk0AqJJgmJbGx2L2SWXC/U26Z\nsEcdP7FFGqcUUxIi/+pa5WbixOQkxUneR4/y+Ouk7H+Ks+9ByPhVZ3TZd/0z\nW/BvPv4iBzy7Fh4ldxq5JJrgC30Kg6jRwd9FFaN782j2GtZetxURRNQBlIBr\nMvK3\r\n=wStW\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIEYW1wa2B5bV43kgvu+vdp47sBDocUB4n2bj+m+/mA/oAiEAw/GnJ+vH0sLX4sh8OZlcFkbFUkzlDbZdJnE7JfdXN1E="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.cdb104d.0_1580171200130_0.43592958525993475"},"_hasShrinkwrap":false},"0.0.0-canary.1db323f.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.1db323f.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.1db323f.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.1db323f.0","fusion-test-utils":"0.0.0-canary.1db323f.0","fusion-tokens":"0.0.0-canary.1db323f.0","generic-session":"0.1.2","get-port":"^5.0.0","prettier":"^1.18.2","sinon":"^7.1.1","jest":"^24.9.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.1db323f.0","fusion-tokens":"0.0.0-canary.1db323f.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.1db323f.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.1db323f.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-QbSXX91uFV+YYinRvTCqOMiKllqjMQdJvEdGlgH9bZcCXazc75lrG/BWL/IBdjYIEf9MGb+qaA6Fozh2xdteMw==","shasum":"4f95be820194c763d2c0ca7177fcece2085232f9","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.1db323f.0.tgz","fileCount":40,"unpackedSize":182083,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeL4QSCRA9TVsSAnZWagAARqkP/RWjpSRp9hZMvuIxdiQJ\nC4muSqV5HLQnggXoKw8i7gYTj6hjegKiiF0Kj3wyORAUr+oqsHUjSdB2IjPW\nT4Efd3/NIzPjSgVNHasmgik4tXYk+BVHGT2WW2U9Nn6zObo+sPPPYvbmxXVQ\nb32YyaV2GiUIMB/P9GKL2zc+z6ukLikxhDW7y8NIeOEQNG5DUF0FotPm9RRW\nDo8thFFK+Eksgo/mPDQDKfnx0r7ivF+Yn6/MCePaiKVcdDAmZ/RYkXElViiO\ns4mLkrc4xQMrbgq5PQQ1/EejOWnCgSxeVh1FTm7A3jwMeN/aYGskDzf6C1CN\nT/PDL/vktP+BNOEaubFBaqMKZLxPoOCPnAU5WAmbG4BKG5WLXzSnuvNWFIvP\nfL0mr4eO4lllNOSNd+1D8kdEIHajqjlVq04HKm9troBbd3WjUm+klos7pNF5\nPacNxHCT24kcad3pNzmPJ+YZhN2iJUWv8occCLAXwgVejnlrhs7ECBMNByBI\nMDrUJosGhSIdIvDjQbL0Om5oVr5Bz0bwTbv/48RhvQWExx5st1v3q4Qo+ptD\nevNKZxIIVDtL1WwSAU2mSpdCTThWLqdyzLxLG5QXdQ4qMuAwl7BMdtG3eCTG\nJR310C/fAm9QuRJ/L61TBAVojsDdbaqDtqVOFKhBXQy//9Q+dqh3IcJkBefQ\nHTjn\r\n=MRxD\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIC382R7L8PqLGyPdpLG7rKeDT0dR3WNzw7q0qU6FB0TeAiA2HElbDTkOUWFGZUAfpdHMM52svRnJ0ePobHoHkyeHUQ=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.1db323f.0_1580172306058_0.07305898828769553"},"_hasShrinkwrap":false},"0.0.0-canary.aaaf2fa.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.aaaf2fa.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.aaaf2fa.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.aaaf2fa.0","fusion-test-utils":"0.0.0-canary.aaaf2fa.0","fusion-tokens":"0.0.0-canary.aaaf2fa.0","generic-session":"0.1.2","get-port":"^5.0.0","prettier":"^1.18.2","sinon":"^7.1.1","jest":"^24.9.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.aaaf2fa.0","fusion-tokens":"0.0.0-canary.aaaf2fa.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.aaaf2fa.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.aaaf2fa.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-plaaPlJwnyinN41LxIvTWlPKMbIne2iIjnh4gASSONhYc0irWK1cYMCRQnhfB3M2U6UbUOYj1tMHm+ZGfG64pw==","shasum":"3b15d4cb2028b1de26e633bad52cc50d46f88e0f","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.aaaf2fa.0.tgz","fileCount":40,"unpackedSize":182083,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeL5ymCRA9TVsSAnZWagAAxLoP/inN9gBxw5jJF7Wzj4Ls\nP38qzzGoEh2aZwqnr9KQ+v9CCd1p+EhZ8diJFLv7Nhxb3WM/i92erxynkWa+\nWDm88SY6NL/CJfIXzmwQZMRO6rSs6YFHQ9hK1zCu3b4V37IiczB0nwjDSSxT\n9qFoIDM5xS69btNCjcvm9iL8/8LFg6ZjsQoi/XCz/QAousnib+RN4uo8Ebys\n/8SZoG85DutsqJlO0x+MFrfA3eh/4CJKfveGMH8lfur1xe+Z+BA/fzr3gZhW\n+HJma7lz9chFmASzGqm367V6qEQtJygVLSS1y72Sap/6NaTty5DpwNAE8m0J\nKVtDlsltmfcAqAr+52BB6em9p0vZ+FHJWREHyrqt9p8sZEqeIA/SckPZw2Sq\n483ldhKhHWtbnLz3A1Menm+zQFAIJr3Ljhzx0GLI4UGjYzP5PLUCEskUbc28\nhI96SOh1FbWIfLyGyueAWm7vXX+Qg+3qZgr412vHbKAWmSmLDOya3VTovMoC\nbibJR9xt17MGU7hg/zvL8Sdd7aPEwf21C/kSQbFWcO+BgbYFYG7bsYuJNmLF\nwj6pTZvYgbWrBlzfR1POLDkjrNzK1zIjetlpuVXgU/VGhuJY1/1hzOCLOQHE\n+84l7XPydDLx+3Oj2huYrFilT4MzpUC4gNjrNrxmr1Y/qFT4804J87+uV5NW\nVNC2\r\n=Kxtu\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCksHvmDzhJosSqz2WycWtRtPpxkAGy5BPdlxaReBo0IwIhANJPfwGgrXOzuGWFOvIBk+FCG6oSLXtLwRSYR3IhEMNO"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.aaaf2fa.0_1580178598178_0.8358648609366754"},"_hasShrinkwrap":false},"0.0.0-canary.fed6152.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.fed6152.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.fed6152.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.fed6152.0","fusion-test-utils":"0.0.0-canary.fed6152.0","fusion-tokens":"0.0.0-canary.fed6152.0","generic-session":"0.1.2","get-port":"^5.0.0","prettier":"^1.18.2","sinon":"^7.1.1","jest":"^24.9.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.fed6152.0","fusion-tokens":"0.0.0-canary.fed6152.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.fed6152.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.fed6152.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-j8kLEbEjUmhnQik7/vD2mIw8v9fWyXf7lPnQ0cZGoFrBF6DfzFKA4rsM0HCsL8/7ExtICm6I3p1lzhQ+YXHemw==","shasum":"b6bf3e0ffa084f404ca6b6558d7814553ad12e18","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.fed6152.0.tgz","fileCount":40,"unpackedSize":182083,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeL+ePCRA9TVsSAnZWagAAX3AQAJxCV2L/tWbNIGtihB05\nNmyBO92dCeguNXVGfKU+9wW+NmGC5sRFru8OUwA1sSalObdK0SICnv57BjPc\nK4YIjfPGTFPRzDL6prifukbYATjj9MWwaDouzshla4Nhi0yKO3Ybzp9/YA9h\nr+DZhnCswR4Z3UQnWBLynfHCKYeTwEKwCf48wIGzA3Zp0HZXRs0wQS/HV1lA\nKc1KyZ9Rze2I0HjJGj4yelTEzW7ic+lrk4yq66H+gku69QpaVEjMOYLg1p6w\nrOW4da7yXN08iGZzvdnP8wfwLsjOJJX4ZEkKVwHJ1xxkGqMdIvdTnon2mgLS\nCt/aSb9KYzkaHQF9hwnCM0zOJNNq3qvWfFV+xP8QwVzP9NuiGC27qmXkkvTp\nnOlwivCCn2KAaD1Y1+xysaWs0k1zwUfA2+9MCC6eRbFOqU0Vc3hmegUu/UKg\nuPoKnz4rqeJ4F1igmAQYPh75fSbYvAQDeHTnKDLiSFj89QLhHSP7QqHX4hi/\nLj/D9eWWivsGP7VW8yyk3KFSxddXOSIZwHjjcJChgXXO/3aC7K+MCg5UlZDG\nhzTN+2cI3cEmx9XMpHwAZUGaiUrK+2T/xmcUwHX+OPdfSSINUu/WzGI8Ccvj\nKqRQ2A96lR8kWt/XZ6f9SNwHQDzeVi+SMiQj01Uu2NnLtQ1j3QrjfL2QgfSG\neJOg\r\n=l4Q/\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIF1KAaEmQeQ554tpLkmj7YzAhPgj1jIFcb4owOJopj90AiEAlXaef0rjaiHrLjTlG/E2AZFz6+k0XIhTIQosTfSOjns="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.fed6152.0_1580197775150_0.21187136111136096"},"_hasShrinkwrap":false},"0.0.0-canary.971253d.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.971253d.0","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.971253d.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.971253d.0","fusion-test-utils":"0.0.0-canary.971253d.0","fusion-tokens":"0.0.0-canary.971253d.0","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.971253d.0","fusion-tokens":"0.0.0-canary.971253d.0"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.971253d.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.971253d.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-LlkZTLG0v6MMViHzjRWANPHPo9z6bzlbkeV84Cmf8PYlrLJnpWixvUxygMxwaeSkmjZ8e8vIAUjHkt/O8HxAgQ==","shasum":"2b8e5c5706857594966e3549dc65084e32578fbb","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.971253d.0.tgz","fileCount":18,"unpackedSize":32929,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeL+uUCRA9TVsSAnZWagAArxYP/2B9eH0FStomlUdbjGlX\n0XyA68YchFI9BdIMUpsTj5md5MrFgvmhH/vRuQbKU3CNupmsZmunkP2jnCqV\nZN/9KqTYzr8i5APNf99Sccu1FjR2GyLQ+jZnRHKSPTHQTTW8ZofvbZCOCeAj\nvYgb8xlq/uXPaErhc27gkdIqD/5iKc2a5tzHIrym9OmobCxUS/qQbv2aUQKU\n1RmmSoKAztmWFTxis2L91yVjZdt2aJJ6JvByik+nHhz57Z53aPK3YxfZRi+i\nJsksB5NnF/lo5gCikKO8c1vTPxatGM8teADk4BrjM11lMy3BvJdU6kdKi1mS\nbFp4PytUPSu29XJveTTK/os8VZSGG3MN+2OaRPp8xmCpl445DhWSOayLrzeR\nRvfXXsxzR983CGR+ehBBLDUzUtCHfypR9JoYU9Fk+JGpIlWx6WKef8gul065\nU2lg86JFckFPSShFAqokFaoELtePX630A4R5c4Zr8ei9osXQWULH52ZmnSzb\nsRDelWvuygXmI69eyn30KQEtiehybH3fzpS++347neeWcE7PerAs04A3G9WB\nxiStnKP4IBZecjSoIV1Cq9E1H4TxCHLgBSO0xW/FjQHlEMdt/f7gmE7Z0FGj\nyZWwPZfP2U1/8IeUDGQSYhir1NH7toF9GrA48obhzZVGTNNaGK7UNi/4ibOg\nTPAb\r\n=VQEU\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCID/aEvq7KC0suGz0i4KIBt1HSkPqTK/C/9eF/6gCEOlfAiEAqmB1AxY+Ri+pqWzqmM/jNKa/YPSx/nQdkBNrpS6rpU0="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.971253d.0_1580198803879_0.5052225834463946"},"_hasShrinkwrap":false},"0.0.0-canary.659c743.1":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.659c743.1","main":"./dist/index.js","module":"./dist/index.es.js","browser":{"./dist/index.js":"./dist/browser.es5.js","./dist/index.es.js":"./dist/browser.es5.es.js"},"es2015":{"./dist/browser.es5.es.js":"./dist/browser.es2015.es.js"},"es2017":{"./dist/browser.es5.es.js":"./dist/browser.es2017.es.js","./dist/browser.es2015.es.js":"./dist/browser.es2017.es.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^3.4.7","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.659c743.1","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.659c743.1","fusion-test-utils":"0.0.0-canary.659c743.1","fusion-tokens":"0.0.0-canary.659c743.1","generic-session":"0.1.2","get-port":"^5.0.0","nyc":"^14.1.0","prettier":"^1.18.2","sinon":"^7.1.1","tape-cup":"^4.7.1","unitest":"^2.1.1"},"peerDependencies":{"fusion-core":"0.0.0-canary.659c743.1","fusion-tokens":"0.0.0-canary.659c743.1"},"scripts":{"clean":"rm -rf dist","lint":"eslint . --ignore-path .gitignore","build-test":"rm -rf dist-tests && cup build-tests","just-test":"unitest --browser=dist-tests/browser.js --node=dist-tests/node.js","test":"npm run build-test && npm run just-test","cover":"npm run build-test && nyc npm run just-test","prepublish":"npm run build","build":"npm run clean && cup build","flow":"flow check"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.659c743.1.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.659c743.1","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-/PrswiOBIYhFXaxzGTJLdGjUkTFKUcOLHOVipCLOxszzkaMwx9IreSH3vRUqvr4D5moNmcDgNogOrKXjJtZgdw==","shasum":"5b49f10d00c3ab21597366c8e135a89aba2c05c0","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.659c743.1.tgz","fileCount":18,"unpackedSize":32929,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeL/bHCRA9TVsSAnZWagAA8tIP/3zTrEELuZionhsqm15X\nLoivZRihmBxjw8sqMtnnL+fSrMbhXiPM1EwOJDL5ywH5zDXnqd5Rzi4eChVq\nvJ5vxvEKYOv7zXH3t71Ay4tVcrLIWxxz8CtLesSuM3vR0lFirJlTaiuUMcQb\na+duKT/QlhMb/OwXqnf8ZNB85H6pdbJmB6h3/SZdE3gFxV+8eCbqLYfJJrpF\nol4AKGERKQ7YfS0JMX3SQYB7MoAppLbT+C4bYjpUXta4kougBboauV2rW3cc\nLm92EdGH3RGtF/VvcPGhHflcnLgeyIBG4IvakU5SXnzlKTqTLGfaAPXbCkMq\nqGYYzED+vGyIUwz7UVN+H6vdVLZObhID3XgLcrpFJ/g1lrECiTakVo2B1a7v\nv1T5r+5EFzfI93Ybl8TsalEtdS/Yhyuy2mP+wEE7HJynfNQgGyshMvYvGXBb\nmsMaN0pgCzg8FIsLSCXi66oEgG+XMYA/04o+Xrilph4HItLXcfLKEGaG3FBx\ne6K1ajLd87J8dm7cuqcEGimrkjTRpaHl054i5OqX4mcLsVswC3/rn0Y9oJA9\nM16sRCEDPoU5t6lFx0Jov98J4Q0MA4LM3EJObaf3cWJYtTIpssPTM0U64xCP\n0bUUQTs5SEdDmUyljvtRX4ndfW+tmtGeeLMJ/fkIZ70BhR6lkl3ilDAPwcLE\nM0Wf\r\n=PwJa\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQD7bdAXEbFuk2viiIIdnDCKgh8iMpcePjpRyuxCrySjFAIhAP33etu4OFshp+5OsGkiVtHV72e342QL+C93nEFnfNrK"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.659c743.1_1580201671331_0.8529567302833894"},"_hasShrinkwrap":false},"0.0.0-canary.dcf8c03.1":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.dcf8c03.1","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.dcf8c03.1","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.dcf8c03.1","fusion-test-utils":"0.0.0-canary.dcf8c03.1","fusion-tokens":"0.0.0-canary.dcf8c03.1","generic-session":"0.1.2","get-port":"^5.0.0","prettier":"^1.18.2","sinon":"^7.1.1","jest":"^24.9.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.dcf8c03.1","fusion-tokens":"0.0.0-canary.dcf8c03.1"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.dcf8c03.1.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.dcf8c03.1","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-PXrMTi6xyHiXNoyUWWg7NNAWtkQ44fM4ZARDFy6rT2LuX38tf5AWpwX9xiXFicGwSXfnUBo6guZNLw7wgopgFg==","shasum":"24210635c593d4beafd15c82df7b9129a289fc73","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.dcf8c03.1.tgz","fileCount":40,"unpackedSize":182083,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeML5CCRA9TVsSAnZWagAAtasP/R3h56q1AFyfCoEa/Z+n\nmxwXmloY4TMKD90gIFqJJtSqDV0KUAssQ2r3qrrYX9K5p3UXveAxl519PTja\nGazrnYzQnYceX1i2Eyd68UhLv659e7xg6BjQzIaVfmPnLhHpYvcQXJA/400W\nULPf5HVtN5DrODTKLekchbZBfGUvDSNFZP4MbaTOwqxdjkuWX66tRIUZvvhF\nIXW0uXILObCtivkEfX00deRLbeIVno4H31AXO9Bwai8zqOHnnXyZwY0+hTkY\nr8iE+Bk9yPnuKF/sEK+ipxUW8VVsQQo92ImEIgWOXiLPTmBWKJcM7tB51qw2\nJrE7jBoGfYFd3urwgEAMkQu6B54hb6kcF/GsVthcpDuflXwatM1br42LVz9T\niX1W+7PzSPIfZbXB2DKSZu5DJAkCh5jPy3csJe6FJpD6ApQcg9yHDf7Gb5NG\nnuBIMjMj7Gjtvki5zndpHgZBXMWc1JbBCsn9AQFT/cQQ2AangwXVAja9wBGr\nIrmSmX5mCYljjk7XBk1V24MvAQfebcA+4rRYCtnqB1HtQK6I+V5Flsqq2O6s\njPyArWd1Fhw0ZCbA5vO9WUXGo3QyrAa1MkgDelQoeI6sH9B/Xy5hCN1BcehE\n4lQS44OQnM6NUIcJtl7Mk6J2LdB8Q4B22Ht6f5yo97jCA6fZTBgGBaGj65wH\nl2R4\r\n=Keu0\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIAm61zhAJ9kRtaFWji+746fvJ4Brj0EYRhelQVeII2ZSAiEAi/A3ujV4CQ9nQc4Q6DjsOsU7v1JefMkLUzrPIvIhcfU="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.dcf8c03.1_1580252737628_0.2132454756568012"},"_hasShrinkwrap":false},"0.0.0-canary.4fc2099.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.4fc2099.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.4fc2099.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.4fc2099.0","fusion-test-utils":"0.0.0-canary.4fc2099.0","fusion-tokens":"0.0.0-canary.4fc2099.0","generic-session":"0.1.2","get-port":"^5.0.0","prettier":"^1.18.2","sinon":"^7.1.1","jest":"^24.9.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.4fc2099.0","fusion-tokens":"0.0.0-canary.4fc2099.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.4fc2099.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.4fc2099.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-o7dvre7jYhizUDp96gzu4nTY/YOCvqZXm/R7D4RxzsIJypbLvTeXKVvKhwzpsNTv4fLyPsTOh/myTa9bfmzEEw==","shasum":"d2e70859e860730351bc3c320826d89004985702","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.4fc2099.0.tgz","fileCount":40,"unpackedSize":182083,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeMSUcCRA9TVsSAnZWagAAv0wP/3/8n5Ap26O0zgv/F8fe\nQ3qcXMQhIhZSqi6zMrk2/VaNushSRw15XiWPLdn/jo5vD63FSKpjHsDe7dWs\no9VKG3chJ/UrUFXstsTy6ErFzseusMGV+ti4Rg4OttbjAURdHRl9V4EfDsWa\nHm1r+bEwzG6sVXMKl36VR4beFQKjuI+PTZQuD6Tn1nIexaP1aJ9iHQhXMrgJ\nDpGcY3yRy/GBOCIbv0JLBSGBaHAXCkcBrhHtoOk/iQu3r6rr10CXf36qv+Y7\noyzhdgAdYQ14iJk58BYg5wQiQOGcsvlxe4/I/cHP4CXm4GWaPUTIREZelvKr\nPvKz9SLaQF3MZiJHOzblt9ICTD52DFVe8Fm+4UAqIvvmclF6p3TEs+/kHQHa\nVmYplw0yG9sl+7rRJRTGMg2Alrb0yswPQ2qH/bd9IWGbIu4PCdkkphix3mpB\nxpYLPmywB5oxqiYchRIAx4sIMQaP8G08lfvkVmMpPmUD0K7R/I1kYPUk9KJR\nUf3iuMJCiicJFACV9uoz3mB5HssOkqj4QKhBO2gi7fE1o/27ivDxTphzA1V4\nPWOaablMtJ4FE5QA2OuFt+SR5etmMUxdOYaRdshG/iSp0IziuZbDcaN7F5nG\nk7OLXUzxRNa/wDDEKtKRFas5PcCGf5Bc/F6cr/EnW8FyQuUpym3SrnBkgVfH\n1v1/\r\n=LyMH\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIE37be13PVGiz7fcGzf0uAzzNfwoqp/W+NFoix3Q7mPcAiEAm9+z79Um4NdUF6ensU8oPwuQBoH/GMKKM8zihAAAVkc="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.4fc2099.0_1580279068201_0.5036955202452842"},"_hasShrinkwrap":false},"0.0.0-canary.2917daa.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.2917daa.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.2917daa.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.2917daa.0","fusion-test-utils":"0.0.0-canary.2917daa.0","fusion-tokens":"0.0.0-canary.2917daa.0","generic-session":"0.1.2","get-port":"^5.0.0","prettier":"^1.18.2","sinon":"^7.1.1","jest":"^24.9.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.2917daa.0","fusion-tokens":"0.0.0-canary.2917daa.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.2917daa.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.2917daa.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-Mf5Kjzmq2lrzqBuu29MGgs3Uer846smIxBpHNo1R5ZSz3kKBARfqV6T5gm5dyOWUpFzl6lhqIc19nUcdkM9okQ==","shasum":"7818c3dd890e76f125d74fd230b5f435bcdc5093","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.2917daa.0.tgz","fileCount":40,"unpackedSize":182083,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeMceqCRA9TVsSAnZWagAAuq8P/3f6d38LAmir1TnmRQcB\ndsJM0GRNIS+S1c6r22K/SRxKZv+cG0/uSkHyM7dDW/EEp+LBL7ceA41Uhsqm\nhjcaP5CXAWLQrYXsI3LDcGi646VpoDe6ybyCVTwL/bQ0GFF2zQ+ncYAMhpaM\ntGbsAv4woGGwjiPE9ikv26XldBcT6kd8vBQKmVYG79uQmmyToGne+tVVczr2\nwHkOazu7npVVW16ZWdL8AdSwQu/mt0ucivmiUEdJngi7uC2lsQbCBbCYXNll\ng9gw7NJtxCtjherwWNQAeP3JnEVA9e/TmSC12wcavc5A04tMPBFwmWK/1Zff\naYpXgIYP+YIIbb77cFdslDKTNTCViMGTEnCYX+xO+j0y5ZQ2PRNtpDTXZ/8l\nSlojcTvlKv034mHla4BCrlsL3J9Njuzjxz/EP0tn1QVDGwKkN6O/dPdz32ey\nk0d86j+C1jboE9x565G8awDS5V5p1Swg/DTO0LiC5CHLgQXMpTBH1OHIVtb/\nmnikt/PwY2fz9aeA0yAUSGSTQK2z6/Bq6egDtAZExXa3J258mW3Jngv1UdkP\nfQPYsjaDUNugSFyGwKYrFiLPD6MUVeTXM37SZ3qM3QZ+Sx94sQmWmN96Zqxr\n4x6PJ45lN8B+pJUTBrLxxZskcjLwDGKt/Gu2QLHi+jVn7ElYi/5SFtX1fnod\n0Q0H\r\n=Nua9\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIEJUF7KGU1YbhkxO61uQTMSu3cDudYa2wQMmFddNJ/bhAiEAnEE1G1FxFtuevgcWWpiDBmgEM/REcumNjuYineE4r5k="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.2917daa.0_1580320676047_0.7464317266264122"},"_hasShrinkwrap":false},"3.1.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"3.1.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.0.1","eslint-config-fusion":"6.1.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"2.1.0","fusion-test-utils":"2.1.0","fusion-tokens":"2.1.0","generic-session":"0.1.2","get-port":"^5.0.0","prettier":"^1.18.2","sinon":"^7.1.1","jest":"^24.9.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"2.1.0","fusion-tokens":"2.1.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-3.1.0.tgz","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@3.1.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-Nb1p3WLmI2LCQt1cHa7dGaZiKcPoK6XxenseEKjZ4o1w8p0VeMxO0YQP5j+d2w5Hb7rh0P4mezsYaUZX+T7lfg==","shasum":"4d334a79a6a4fee7fa974368bb599d29d8794104","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-3.1.0.tgz","fileCount":40,"unpackedSize":181964,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeMeJmCRA9TVsSAnZWagAA7o0P/1+UVWoQX0tFFa8YsLjx\nl0F4pAro3rNlsoJiBgt6RjCtVHd3lNYIEN75mlYCLEkm1Bv4seMwuQpvlaIm\nqwZBxtiZvucgkR2A3Qx3T2pa5TM6MK0VLbwiCVPsU/xE0zffkjw/fgiU7vqg\nA6V6KpolDtfrC/g5Cexi0LjR9HuEKu8q8Nb0us2HnGUN6HFZCnWj1UMtiA4M\nVtQ+2ZsOERDNS+xRvVtQuZCHcjmyOJADDdAuh1OFuGqALiKLk2MbBxNTG5pl\nt1fb6vXVLsiifMcwwrCZhuAdwiKh+3i1v46Qm0+v9bp+PMY4VwvbOHlMhy0S\nhs8148dmYN7vT+P6GgL7RjAkCv0Mf1OZczKrfx1gjxHdn/3YWBhWydLjOW0K\nymTpMnazDVl5u6UsG95FvFvr/LDjL2nQo8aj2w3VJpeFLDTZVPeq4U9t9FCO\ngaC7Hf6yMvsbVd/4Ly+FQO+LBlMmRHIG2WojEYFTwp9ncwxV4zq8Ah2xoN8W\nFQmu+uaNevCdKPxC01KJ4GaCU1p5N11tmj7vaPqOjGQhuCg9pDMX5NbApHzx\nPbH6UUSTQSUmyi7s/BQjIZ+d7xbvTmhHIKhvXQTPx23VS4bHAPC8cOnfdChd\nAO18q7dlMPpInwZ3X1rkuIHmITgXdZ7sOqV3YtppE8gWAacUlFciQJXqe/aX\nsuAH\r\n=z1Tk\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQD6RVTdCocQg1NLUhGyLO4YF78gnH3KihjkruuuYZ0xIAIgZKMeRWIIm8mpNWREcAdsFjFW8/aVQejdjyLg5qpWMNc="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_3.1.0_1580327526409_0.062479784498057356"},"_hasShrinkwrap":false},"0.0.0-canary.97698d3.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.97698d3.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.97698d3.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.97698d3.0","fusion-test-utils":"0.0.0-canary.97698d3.0","fusion-tokens":"0.0.0-canary.97698d3.0","generic-session":"0.1.2","get-port":"^5.0.0","prettier":"^1.18.2","sinon":"^7.1.1","jest":"^24.9.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.97698d3.0","fusion-tokens":"0.0.0-canary.97698d3.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.97698d3.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.97698d3.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-4srMTqpEeJb0CxH6e4iIcLp6f73bhDF8nXBXeAE1sUO0NSy3qistyJ1kju9KAGcXCjjuA82UMPproIu/7XCzSQ==","shasum":"fd565d41952a48b9c0eae1f2015ac44e73638538","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.97698d3.0.tgz","fileCount":40,"unpackedSize":182083,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeMgZGCRA9TVsSAnZWagAAuSMP+gOWpTGJUQ8ZfIdkmgnW\n6Fr7Ipu5T93/Ti1+kDwct0J9vdoeAN1WgIgLJA9+T9TJNUWaielCP/Qcs+JT\n5dtE2FGuwXjsfRsecX9WRNh7sLBLyiKlpUuXbPNp5cnDrUBe8DagoEAYZMA6\nrwJjPui6Hp6ajXdWmSmtm5+a5MDOHqu+WJFap03oK5FuCi85gVX19uPEzGqI\nzHZsAXZMXVitAA/LdS+nTDaRdZ/G1hn/ch2EDDXicy7i4dbFHY10DXnnVOOF\n63eVsZb7+gktQuJQgmXKtWKWIdBu1ZIRKa+aiTZ9n8fm5ZauOWjKc6esqJEJ\n0EjQf59omBXWW8BHp9D2VW0SydIqkjb3RMcAeNByMkH+VH0XSb4TYFwPAQaY\nwFxRAOVMQ6zFUS88LfblXyDGJIhd4/mQ6az5CBE9YO8fOpPBex3KGRuBO2lF\nwZckMikUrHLzr83ak9TP4Mn8n6fcEqPelGeRwPkGOgX/ocX6rDcgBG2Zzdks\nna9QLdDdl7XwXFOF7l+AHmpf8nmzIVruuHmfyCzkqQs09GKXYvQ/W1wOgNiw\n8EC/B8G0/F+M5dOfuj6cXNrelRMcYNYZESyVyEXeeKGhDHzLXai7183keKzX\n0iwXU4Y14eQNQPKbNHlLoZX0FsvcXitE2scd0CSvJNzdVRSt3sScbMDPhFVk\nsLHr\r\n=ZyWc\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIFDzQejeolXoq1h8WEEqm5rdEDzVgdVOYz2nfs8MywvMAiEA36q/LkGOOasG/S2stoRngRDfkvHZHPNsLMYLnuSlVBc="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.97698d3.0_1580336709843_0.8297113392870681"},"_hasShrinkwrap":false},"0.0.0-canary.69bc71d.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.69bc71d.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.69bc71d.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.69bc71d.0","fusion-test-utils":"0.0.0-canary.69bc71d.0","fusion-tokens":"0.0.0-canary.69bc71d.0","generic-session":"0.1.2","get-port":"^5.0.0","prettier":"^1.18.2","sinon":"^7.1.1","jest":"^24.9.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.69bc71d.0","fusion-tokens":"0.0.0-canary.69bc71d.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.69bc71d.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.69bc71d.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-523dhGMAh9fSgQE/kRA2l93wM88IUTu8xCSV4TpFjd0NMJ8XwrmZDQzP2OvCOFZbsSoXczE2V2EViq0oU+HY+g==","shasum":"e541018ba95c0ad4cf63d8a1a399354dfd40b90e","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.69bc71d.0.tgz","fileCount":40,"unpackedSize":182083,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeM5jGCRA9TVsSAnZWagAAaTQP/RLkcxjJwHcu4GRSaCHm\nuVVrpUK823mgwjR2TOdv4Fs+qmTM78TZIwFILZjt+LONcSodyCxIXSvCoYbv\n946UPwsCNJbVvdw2RvWoHZpNgeegRqb4MZQ69cJU7317E/9GCSEj0dZ56Qh3\nlvpkfGaXxeb73W9rlk9BQYTlLeuESPVBdHXYMoeUn7xGBpmjKV3mqSvbtY7r\nH4wLMxYfsosq1cdhtJ8CFlTtVlMA/DcMhNc1WAId1zFl3mFI9a9j/g2VaG0I\n5XfkJG3AP2s80WedI4/tDjsrjtjXXDO+Wrc3bFG36RVcfamp/0hbuIC9nISm\nD3+qgsv4nAAXx9m9n/s3DIn9YjWuu3jrPaEhUXhB6cQJGfBsfDdsPden8VJJ\nA0q0JS8WbxYED0LnYFAwij5LxOfbJo1VPbMnBPele9MZ44Z1N2fqB9GBtx77\n9HD9dUPLI7CWCIOpL0S9UBdddHKUgO+J2eh4zR2Nzf29Qjs3gaVnYgU9CIQZ\n7oU8uIbjJsPYINxHKCy9SeM0jFPJSi049nR6Ov/K7F0tiOUQ3cJYzcgSuDWQ\nlwC2qEDAX30uj3zUR3tNs9jT16RlAhSVp0byadRvGmeEGCOlOJw3X0z6AdGQ\nhGOzDndUT1dOhYA+zxKPj6b9H3NMU4XGfceM2X9Nz81InR5Hu1skJIFjuRIB\n7q0h\r\n=72eZ\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQD8Ot0OBCE8FXNUbnMnRehN1vjbdJ6/ND4cmlVyOIHq5QIhANvfTae80Hquq5WAm2XH7F42wCEroAz2X7trGW4+/tzy"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.69bc71d.0_1580439749866_0.9839378405240058"},"_hasShrinkwrap":false},"0.0.0-canary.fa2f39f.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.fa2f39f.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.fa2f39f.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.fa2f39f.0","fusion-test-utils":"0.0.0-canary.fa2f39f.0","fusion-tokens":"0.0.0-canary.fa2f39f.0","generic-session":"0.1.2","get-port":"^5.0.0","prettier":"^1.18.2","sinon":"^7.1.1","jest":"^24.9.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.fa2f39f.0","fusion-tokens":"0.0.0-canary.fa2f39f.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.fa2f39f.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.fa2f39f.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-5rf4WmbNTiTkMLHh0me7Z2z1bwvYz00pYoJdolqo0kXHJn2TBmHWiVPbFy0K/l+yNyywTaeLYhgFNfrfHaatDw==","shasum":"a64498fc2ab8940635c6e34763038f1ac53cc249","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.fa2f39f.0.tgz","fileCount":40,"unpackedSize":182083,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeNH59CRA9TVsSAnZWagAAQosQAIBmiWUOgp7zu1nw7Alq\n28TyePKg8T7I9AfqfbAEOzdc2hUc6AgI+Vv4HiuDaEddQ6fPfuvNl/swA5Cx\nWvrfZs0vFZzUVEr0NrMiRvOqNPXs8s3HnP6TlJid3zvxC7Jyd0wFwEv+4HTd\nemrBWzVrkNm2dnXxENXrF2gBBLdh817lDq4KuPxzqK4+UAXGoXxlotqfQb6S\nA31eBfVOHOxWkSJkzQEU8sY3nLy2oOnvW60PLKLRBVBo2tjcXeMB7CY3z8RO\nc9zbMjDehLffNQA5MxVsIIywfSJdf0+T/89/QnIfl6K3gYjVoGGUCnZDKzPp\npQ8iJumqsxz0OM6aaGgdsV+n9v7Thv6zN9VyzFC5w35GAk/RQYXTiOfV+eVi\nXHa52yDgFrlSWPii4SOio1kWGK+ogNYVdUpBPWy+ZrKOFhMKlNjfdNH3bUQz\nye4aYEmXkckNHugHXavO+QyNvRefCbA5n31auDBRbgkUDdExbEFfYhwhbluo\nvIVDYqIBks21sWSvyc8l6wv8DrOqOpl4GmSzz4f3m4C2okYURvXAEfMd8+sm\nMCFqW283zTsR/4DAaso6vR1Ox4gXjy0rmG69NxOkwzBD0KJcsEhBLQZLHsAi\nB2CYEj6Sk7cnuaPB8NDAiPyiDbR5mWI7K4egAhIRn0V4pVOpbdFjSaqKjCXy\nxICh\r\n=ZQjR\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCICMJ4fajD9Q2RDGZ0AdSHwtjMtUTFuYi+H0Ga74mElqFAiEAzsuFtWcPJ9dCgPnaMQsAU+UHb11Jgh9p8MKUMSfKq0s="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.fa2f39f.0_1580498557033_0.79307164924956"},"_hasShrinkwrap":false},"0.0.0-canary.1d3504b.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.1d3504b.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.1d3504b.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.1d3504b.0","fusion-test-utils":"0.0.0-canary.1d3504b.0","fusion-tokens":"0.0.0-canary.1d3504b.0","generic-session":"0.1.2","get-port":"^5.0.0","prettier":"^1.18.2","sinon":"^7.1.1","jest":"^24.9.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.1d3504b.0","fusion-tokens":"0.0.0-canary.1d3504b.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.1d3504b.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.1d3504b.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-2JrfG28YF31xeWqY79b03dxcpOkKKjwMwOAjIEdHZRK3g6Fi5gErtQJhvhRtVr6H9sU7nmo9LbnvCiRFX3EGRw==","shasum":"c8034f88fd4ab6d190c370e065242c14a3e4e17d","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.1d3504b.0.tgz","fileCount":40,"unpackedSize":182083,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeNKOHCRA9TVsSAnZWagAApEkQAI4EigG6h8TKXduL0f4J\nCLjMNEWfxb0QzmSNcXriNJEIHgFf/z6KkVpwBheG1vqJWOvxpGf0jSRahVTu\n4IDxIUrxYvImVR/iZqVb0SJ51AUc4gwQBlb1O/0Z5EL44P24iF9u3zqNx7DY\nXhj//0QYBGNHnlTdMMUflvx8cgz5mU3aIxFEdKKW15mg6Ykmo9dKbqd61Stv\n+asoU3OCtPMtXWeRX67Pg/RNAD4l6OsjVX7hgaC3F5W9J5gZcHWZQipoLr8F\nK2QhK8/g4eS1ZQIWwwLLlYCsRrrOoS7OIyyORXiziPyFaAup9nMUzrjtbuze\nJ3brBJ6hEJxN5PoEaZRb5ol6s6WHjlCTCmM+4he2by5Ojs+jzgKwK7zGI/kQ\nsGnSep8YPSYrFfegTCBLgMATVi5YCUVlem+H6Pj/ifZols4W3V11Uvxjz/SB\n2hRLp6DCc/JbREZHAlQ3ydIMVNDKQjqip1ym51w4BiV9a7QKMxXKijPejFRz\ngf44zu/sIEkkRFq2id4832B7kVf+BVdz9yAUEvUaPIBUUSzc2H6G5y+sswXA\nwEZ/2YNiD0XmiU6bL4HDUvkYomPQwlnOqXzm0TdHa8Do90/k304ljIslss3K\n6SyV4t7JyyEDH1AyvNcIiL3NH1z9MejsnQxmPQ6Sp+5RsWMLTh4AsY0kvALP\n2O6F\r\n=+t8c\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCICk6/YQ5uL+nzcdhQl2VD8cMCi1yOtDe9NZN2GyM/ICtAiBn/mDVAGmum/OIdPgdxC5im4GSIcvNsLO6RuAuc2gkGA=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.1d3504b.0_1580508038701_0.30689192128619736"},"_hasShrinkwrap":false},"0.0.0-canary.2effc34.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.2effc34.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.2effc34.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.2effc34.0","fusion-test-utils":"0.0.0-canary.2effc34.0","fusion-tokens":"0.0.0-canary.2effc34.0","generic-session":"0.1.2","get-port":"^5.0.0","prettier":"^1.18.2","sinon":"^7.1.1","jest":"^24.9.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.2effc34.0","fusion-tokens":"0.0.0-canary.2effc34.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.2effc34.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.2effc34.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-sr82YAUj6zFIQLsLLO0PboQteI4eHguBqoSmYV8bjBnxoRhC/JLCVxl75QOMEql8T7rf7tIvGUNf1pBuTAnhuw==","shasum":"da6701d6d6e4587089f00222c069ffbce91e9693","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.2effc34.0.tgz","fileCount":40,"unpackedSize":182083,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeNK3jCRA9TVsSAnZWagAAxWwP/2eg1gqnzkSFstvp8ceh\niW+pCs5wFqVoOCuj+zc2rsBlcsI1RFL5h2UKxB+ZW+sKeQOhuwv88TBnNPAa\nobb6WWtObaTD2jb1w9bPcQHPa07muXLfl0U8/GNJuCFzsMaLVGs2dszEkBeZ\no+C299gqPFW5o7LV6F47gf//0SYf6cDRGeHVFEqLk34HlRQVNp9UoZi/aX4k\n17rKY0tt/v+UKDeSpgvjTXTcoL8kI4+bvjTWzrGohwBohN+j6mphqVaGaSxa\nGGaFYMBZ3ChGXJD73FeUpxX0pg1qYS5hRqSqpH8jOw2GxMtNlAzdU38XKeRy\naBOi4lr7OyKuOzCC2xZz4Be0FiGdT4surEGMFSZNDYI+PfgRuHUYDds0iPIn\nzUuRKJlveJiD/owboJV7J1GN/yNBbEGZJt7VOZLo08Tgf9ZNMzMxvQRKj0Gl\nOwDY9MOuNxa75wg3VMsoJlm23XY7YOd/6o5RCf47h1CpW+sJO/BxoTw4b6lQ\nFc2Uoxb7Dd0LWjD1te3NRm9/Zd2X8JwF+oF7Jhsocc0JhnM6tfw06tSjsPBz\nZvo4qCLkr3jIR/blVYR+HIbknIb+/FOtlMhrZfd50h3T81gEGz1PC96s8G5k\nmFnvgOkoeaAIXZfl0jvUJnN8hcmLr0VsXaSFpqEdMvDaYntAG5M/tVVRI7XJ\ngAGk\r\n=OK6y\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDDb00TRl7+2CsnyPVNYnK4XsBhSjNFpu0Bd+zv5DiM4AIgbFQGhTxthtUey3lbIxTFLIi32Px7uar3q/NvNKmFBNI="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.2effc34.0_1580510690104_0.8120902029391259"},"_hasShrinkwrap":false},"0.0.0-canary.deed5b0.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.deed5b0.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.deed5b0.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.deed5b0.0","fusion-test-utils":"0.0.0-canary.deed5b0.0","fusion-tokens":"0.0.0-canary.deed5b0.0","generic-session":"0.1.2","get-port":"^5.0.0","prettier":"^1.18.2","sinon":"^7.1.1","jest":"^24.9.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.deed5b0.0","fusion-tokens":"0.0.0-canary.deed5b0.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.deed5b0.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.deed5b0.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-p7sFjgs3eAhiHZfiIhaSjyhPG8jUFXTQ6TePM5GtEGr++arrWHYPcFvUBl1OPy9C00cB0nUAcEdmTD3wLvpt3Q==","shasum":"273af6ae8105f7f48af2384688fc758b9d589381","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.deed5b0.0.tgz","fileCount":40,"unpackedSize":182083,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeNOAVCRA9TVsSAnZWagAAmsUP/1dpw6E26E8zS+jan9Av\nj52YYYwbCR28lOv9PmN9VQTRSh9heNFb2mFmxYXfbgnJPZuoLbB4Qx1FuI4g\n4IPbbp0IdFfeNcMdvEBwLNTd2ua/4Dzz5B5h5qBm7p7wVj4wcpvs9guTjq8Y\nfL+o2MWZmg86B+7564kZ3ej0floJ1BPKnzdQTjmKxG39HwFVWlWAMdR74CP+\n2M0gyg5eQCTVHqhZaxQfbK2SzGY0Kq57h//VJZhMAOhukBKpotZ5AgFH7B7C\nImuxbo0SdV+m6Du5VOl559f01jFKCZXJC6DDGj4vL7+TGoOYWnHCV6dtMoqa\nJkJCHJCbMo6oU6AHhXBsD6xDIjlJ3lBQAmaaszk6446r7G6UkLOXQ7WiAFM2\nP4uy7xgDmXFX5WckY7OjnUaYhk1Sx2XLXh61Ycz/77x1Mhyihrmiln6du1Rm\nld9K4cSmAVrulPM4aHo+Q6W35AAg81I5AHYE6EjwyGYa9jBmm5SAzcEsonGa\nboJAmIQW2egCuyW1SNdEICS4WkxRidyBegSh7ZcZ5tS40PcdgHIErPqaRUWs\nw4BPvXBjDRdEzeqh1srVCNTUOSdI0gsnIXWjjLfid1BdOfFHtFtqJs/E/ZjY\nla1PxRpjlAJAUV3QGaQ9LqKeSlsFWNfeEoFj/+WsaKwXwg5r2HZe6RTpaXNt\nrN46\r\n=rqGt\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCg0Cts6MFjIsmgrUfuxAussD3bFsHiWfaLAC5dANPGqAIgEfEWWlEwtw9KgSVG8+wfoKplQky0a5t9LpvmH1lqE3w="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.deed5b0.0_1580523540821_0.8274662259505992"},"_hasShrinkwrap":false},"0.0.0-canary.3088ca8.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.3088ca8.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.3088ca8.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^23.0.4","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.3088ca8.0","fusion-test-utils":"0.0.0-canary.3088ca8.0","fusion-tokens":"0.0.0-canary.3088ca8.0","generic-session":"0.1.2","get-port":"^5.0.0","prettier":"^1.18.2","sinon":"^7.1.1","jest":"^24.9.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.3088ca8.0","fusion-tokens":"0.0.0-canary.3088ca8.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.3088ca8.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.3088ca8.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-e1ywxPAaw36i1L7VGmgX3ZB58gDfUL0qqkYBLR79RYK3+uL1xM/5/eEjP2dxInQo4FfXxgowdUdozpB6btuOZg==","shasum":"ab758b6ee18b3c9173212d5663f86f81e54c4eb2","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.3088ca8.0.tgz","fileCount":40,"unpackedSize":182083,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeOI0CCRA9TVsSAnZWagAAtRcP/3vno7eHEXtysdB7579v\nPXwCSI/IX0QM09634o8wI8XrkR5f9B6gNkFof4RcIZ+Upvi4D355G48QBRwC\nk7maEbS6lK5yL7issZ0RlRiC6k2Hryd2hw1f6eELUE/R+2CEl3mc5UpFm5j7\nFrx3BjWfEpMgTlRWzLijirW30+RKXt4W22RBBL3OyVmb3sV7/2JoTpQe402q\n6H5dQfs0ZiMUqhs7YYmNioVHKM4Ty8kfAEafj5HrfQU0vcBvc1knCIZ9glDo\ntJgOr+bhEjvZwj/e12+YscBd+w+UAwXOsh1V81ARzwK3+7ZFI+4+mZTL/57M\nsDwAU557Uk//l1z6RixkmgrHRq6AHYiLvOpjxwVJX5FhKHYUG8BncgkE22CB\nmWzFtgFwNGgBdcJAyHtlpOn3cFBpl0Yv8eXoMRcp3fwkz8xAuhYaP9UBc5OU\nC145+NhbP6Exwr3l6S4osvPBx7bMYBKVKBEH6JVq2y6SnZC/nwuRfSrrCLSb\nvySg+8aGFhP+rEXbGdke0Hm7ZJvgzXmnSFlx7FLKZYx6ZJbVwT6sxrMN7p3x\nKWe91XtNCJWOn5uzKhYmIG9GEXrin5jWtSpeHctcIYTeV3Mq8r3l8/0khpJL\nc7Azpo0DJneL1RxXAfWm6bTsPf5TGSkIWGY30pf42c/3ytBgFJeHhunBuUnf\nlxNU\r\n=Q6NG\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCfrfeRdCFnUozJRNj6C1GiOuNdcY2eQkO7W+7A12WGpwIhAN0is9fxCBAmuaraMYx8loX817yITpraL1KmoSq/FrZY"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.3088ca8.0_1580764417866_0.04199582119762946"},"_hasShrinkwrap":false},"0.0.0-canary.9a71266.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.9a71266.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.9a71266.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^23.0.4","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.9a71266.0","fusion-test-utils":"0.0.0-canary.9a71266.0","fusion-tokens":"0.0.0-canary.9a71266.0","generic-session":"0.1.2","get-port":"^5.0.0","prettier":"^1.18.2","sinon":"^7.1.1","jest":"^24.9.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.9a71266.0","fusion-tokens":"0.0.0-canary.9a71266.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.9a71266.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.9a71266.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-UgqpFSgwAjehN/Ar/W8UVfZ6/1TYa0RFzA/DNHilNpeLvXK79JEw4EDbK5U4UZY2j0qD1tiKbK7DjW/46faKBA==","shasum":"b90a8de941a585f14806b2ed8604dabc00a6a3af","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.9a71266.0.tgz","fileCount":40,"unpackedSize":182083,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeOI7WCRA9TVsSAnZWagAAE9YP/AyaQrHPtUxhmk41Fbmh\nhwNqsg7jMaSRfFDiuaj3cGG/vnaayzs4EEMTgwhfnrqSCx2p41rXEYMYzFtf\nbH5urxc51pdFYSD12+TiOEyj2vqPBCz2QWMDW1rqP9qVhgJA5KIoxIaQgVFC\njasHRHIghvJTW4l/yXzqilfSIkaDHVksRqFSxdEnoHZZyxasEyghZqn462jQ\nM/YuN53O3zOBP4liE027P50I/S8ec9F+c52GjXUpX7TTuWXqD5oNdxVhq0/K\nDIEuGeQ8UrigWZDU5pbfujAsK1dV6y6RPGcI5ZAo5ZYJUtpE2O3krCGHuSDi\nmBTfDE6ARUHIhjoczuZmoq9DiGJV2NdktFVTY0bfXMScwCBTcgukcaeSYtDq\nuGIEWTNfMpPs102W4P8VF5FhFvCgm4yS5B0eN/lzgYK8Bclcja8WIAcMFwnL\nGNkNotYuoCkoShx2hzxnmmBabKHKrU6uC8amx1RTXuW/MpCPVuiQXbxC96uR\nZWMAb85z9WZ57nLNS8cWE1AI2SXsF7F/uILzd/8uDnv09UBYrMO7Q1+irJNJ\nQ2BXaVdMqVSyJmaayCiGXW1y1tWxYTtrW53elv3l7sym2BUL9ZX5p/bjNfBr\nChiuZdheqlRqa6ZHlXPM0fjCLvCzzAEw1GjwvtRH/aDgG2s1nuFIREpGW7gn\nqtdR\r\n=JM9Y\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCID+poi0UcoESHnN1jSMPxAqugy7ELR7lqrHyvsGo4lpUAiEA5at8mxeop2eFCDtBHpPzs3pbn6awTSqsRx31JvwwHNM="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.9a71266.0_1580764886206_0.955049637402658"},"_hasShrinkwrap":false},"0.0.0-canary.9a71266.1":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.9a71266.1","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.9a71266.1","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^23.0.4","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.9a71266.1","fusion-test-utils":"0.0.0-canary.9a71266.1","fusion-tokens":"0.0.0-canary.9a71266.1","generic-session":"0.1.2","get-port":"^5.0.0","prettier":"^1.18.2","sinon":"^7.1.1","jest":"^24.9.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.9a71266.1","fusion-tokens":"0.0.0-canary.9a71266.1"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.9a71266.1.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.9a71266.1","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-TebOWAfLV2asfyIEzEBClcdR52RZNcVFnCz07YJ6WIsvWaQrZgrJFBJm9fkrzKtgmHcYxhzGr2gDBkvLkgu4mA==","shasum":"ec27c27c86b80a30d9c8d39bf638455ec185c59b","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.9a71266.1.tgz","fileCount":40,"unpackedSize":182083,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeOJPICRA9TVsSAnZWagAAf7cP+QHZMbiEluA7J8XYnIwU\n7xCgiuP3+fhlmdylS0jpSV5qJaxBFaCsvs2/NE0nI7ao6wmrYAa72wcNK8O9\nYftVF0v6XkwawwUKQSepZ99vCG9lAZbHPOuO2bCMJVsKt93sixznJABwY0FQ\nGKR9mI+9UOnj6fc1wVQDTjubawP7O3YgqrHly4+fEXkpQ49UThfvIJMi7DwD\nrzuUdZWNTa78aWnvYKsoax4Uih9OWSRB8z03DyFuJX85Og68vl1iLwxue0cn\nl0JYEDeA3IzltM1e0rvMd8K1AY4zz9WUF5dgMpLhedbDGIls/AMWfeHh5HCx\nR5b1p9HFzwykFozT33DRwrbrAdXrQS0vW4QzRv+AyaRaKOixVFnXkzC4Edd2\nZ9cGxSBzMWxip+SkvKdEqSBE0rsnED+ktk0tssdMpq9ovOP2Zj7kurBNAYlb\nxImds303lUHjthxHhpDAw1NATTQEhnW6wzYLpa2N/M/JKLgM/FpLQDQhlrFY\nkprLfRq1mY4quRKr6lA6+gGAUAgSKGPaTJEJ+E2bFgrGtTdng7rHJALXITrV\npPQS+TbvaEmaHoZSypyd8tB3WEVD+/z5zijOHTvxLyCUQlvouWObKzOxeyPf\nB0Khv7ZV+KLw7dvFG3R/EiokqyHL28KYuj6R8kOQxjuPbvOIjio6tfdEALkb\nrVca\r\n=ZT4+\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIDon21aZKkaYiKDIfllgx5xxbtB0UtSNQrsvUvkN+ypOAiAimdukNADhe1Ja6sxoD+Qi7Z92LmBWEpJ6Oc85c1w/5g=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.9a71266.1_1580766151713_0.8702310014950569"},"_hasShrinkwrap":false},"0.0.0-canary.9a71266.2":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.9a71266.2","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.9a71266.2","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^23.0.4","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.9a71266.2","fusion-test-utils":"0.0.0-canary.9a71266.2","fusion-tokens":"0.0.0-canary.9a71266.2","generic-session":"0.1.2","get-port":"^5.0.0","prettier":"^1.18.2","sinon":"^7.1.1","jest":"^24.9.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.9a71266.2","fusion-tokens":"0.0.0-canary.9a71266.2"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.9a71266.2.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.9a71266.2","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-q2vFxu1Pf2VdA4XAFItXY+efghGcwzBbn4ArQqw5cNHsX892T2JlsHx+I+qDX5JBiltYzErnnZubpOIv+/gMQg==","shasum":"78d3ffe2a681e6ada36c9fe8b3c81cf36320581c","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.9a71266.2.tgz","fileCount":40,"unpackedSize":182083,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeOJmbCRA9TVsSAnZWagAAJiIP+QFdTaqPAomtwxjdfgs/\n00gDZWIbKDJhv0s8fPmhZ2KoBzY25IoRaBTkcpm94D65yoxNShVgCqLRF+s5\nrvwzQohvSHJbzQF3UQKShVUM7Qf6zcQFLnwmLfPJOGCq6nXHGn9lgmaA56ZA\n4T7tyzSPWAVkLe5T+uIdEs17ETPQTnXWr8UId4k41/yxBnLx2JH/tPiaia+t\nuYvs9kj4UjZafLPpBPVCEZrKGJtzUAPhgApuEXzq7PBOa+SRswT2FxYNH93X\nx/w1jAa1sECceWUkmJB3I00F6jECQeZyiONDdBcTatSQgDd9K5xm7bwZFPGC\nN1rhGl58VFOXScQBym0WXJM5FVl37mSTyQLQZ5tDE7/rnbXKrLYGGQeO83aR\nN/SjyxDQMnPh4EhQviWpvn1DRzeAoiZZuDm6lQNTBpALhRj7bkc72+/wTn72\nvS7NTlcSvxjaRCFm7/PJ2m8yMSNp1Zdmu2qSCEFrq1qbl3ONOxu2EkiGXub8\nQyIa/oTMtk0+RtwsM/gGWrvIud0pA8RTAL3DtNuNbLOs26t3lql0iM2EbyMP\nbmgWNYHfIw3I32vepV50NCQvV14mxjJWB4+UCRHTSJkQRgcuQU2rsv67XwJK\nmQeCoqlMEikiC0l4TnON08E1YmwINxukfHzw2DQry7eNhAngsh2jJ35b8isB\ntYLc\r\n=mBJL\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIA0WE53MFP/ZLj5rnX99ch9oMIKEk9pXllpSRRQHv9+PAiAnwmDyFZIYpgcyzQpb7uhX3WcFbNdxaXWL/PjeIYhtrQ=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.9a71266.2_1580767642839_0.8995477903972673"},"_hasShrinkwrap":false},"0.0.0-canary.d07e1e4.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.d07e1e4.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.d07e1e4.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^23.0.4","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.d07e1e4.0","fusion-test-utils":"0.0.0-canary.d07e1e4.0","fusion-tokens":"0.0.0-canary.d07e1e4.0","generic-session":"0.1.2","get-port":"^5.0.0","prettier":"^1.18.2","sinon":"^7.1.1","jest":"^24.9.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.d07e1e4.0","fusion-tokens":"0.0.0-canary.d07e1e4.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.d07e1e4.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.d07e1e4.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-M8IavNNt99sSthDxzYttgHxLZC+9kgbAgsfVAJb6nWSOlTqCqq59toR49UlGZ+lNha+NJjAZ699LeV0RMlqE7w==","shasum":"09292e104602434b1a1edf68db61024202677fb8","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.d07e1e4.0.tgz","fileCount":40,"unpackedSize":182083,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeObxmCRA9TVsSAnZWagAAQQAP/idydJaqHVD8JPxDg99B\nDSxKOSM/mpHh4kv5x0NijmAlk+lDLRWNDTsv5XSK5+94OHW8xfz4PrfDIKJg\n83jR1sOY5MxBshnPba7F7a8ZGen/JPEcsSaMnTJXrtPE7H+ZnhhBUGTUv0qG\njqPF3hkdhHNSgwQBenmV4/AArjEvEedJc5+0gU/23LGUpgDj6VwZs83sZSeF\nD24JenDzRDHRwER3LCK/9+cW9xcC26F4o8GMdCmpgSRpWCTVn/KSbZQTZfmv\nlWr6Z6J+XSN0EA8GmLCLqgC/QPT8krAHyWY7Z64a2dlfc0TdKZuZRNVB6gNO\n2aTBnPRNgm8wAZCV6WFSNeberPjd0MXrRxBO4NNgSroNA/L5wxjrYBnVjIib\nVjouq2AytZ1uCKyZH356FsPMv8duYkyP91beS3hTbI2FL9aE7uh474o2E/WL\n/QPRjOef+UsuieqR6Wr6vTy3UzUuwKgWuSSjnF1qTGx9iJU2eljXM2V8OKSW\ngDR9Bsxms957gIzELCUrgLIstBAKQ7hU8seZVabtBVXL6qM1SiRadVYSOWGP\n0fZUODMOL3IdzYoW8WOOdTcjMsmWq7XI8Vd8TXr2gz4Dfss+H/FHwPTK+rVh\noO7251kIVLAyJTPF6KMKzdXVBXLJwMurCtpCqft0EzMYSGC9HUYtE2Jb8O96\nY5p1\r\n=slOG\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIFVQvnmHAoo57/zOx2q1mMx88ms1y7amUYKp0ZRb5MyBAiEA3InAcn2AE/mVZonXbSuFssWcctISFNDjocme7WH+Y/w="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.d07e1e4.0_1580842086266_0.8946277166653447"},"_hasShrinkwrap":false},"0.0.0-canary.05b1cf5.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.05b1cf5.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.05b1cf5.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^23.0.4","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.05b1cf5.0","fusion-test-utils":"0.0.0-canary.05b1cf5.0","fusion-tokens":"0.0.0-canary.05b1cf5.0","generic-session":"0.1.2","get-port":"^5.0.0","prettier":"^1.18.2","sinon":"^7.1.1","jest":"^24.9.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.05b1cf5.0","fusion-tokens":"0.0.0-canary.05b1cf5.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.05b1cf5.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.05b1cf5.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-9HalLFCAhwizWI7i7JLrioFrN0XuSfxE0xjyzHBGw4DbZeoV7Sut7HlHMOPubO8hIt9OXQconl3QxY/Uu3RDtQ==","shasum":"925c56cb9206e8af222f19781c86e1efe86db70e","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.05b1cf5.0.tgz","fileCount":40,"unpackedSize":182083,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeOb6OCRA9TVsSAnZWagAAm3cP/2DMF8ayHWP+REduWEgd\nn3lQWpC9ZyNgQKtxF3OrcRG1tG7OYFJmKpDPdk80n0OFnFDH+ea9qFCOUThN\nVIst/wf4DMX0do3r8pFSDgu/fZpSzBHQjL49C3YfRJ6fp9CuZ2SgeLVMpAwt\nxeHdYXRd+iFpUb4rJ6elMx6qQpmFK5BwFyvFJUqROQUAJFHxMXGlxpqo2q0E\n0lSqS2esu+MWLtfVo2iWTJ/aXc/4q8Wx8cV5YHa4xbqALgGYoAcS1qAiO8jx\niTuVyMxBnbBJP3XTi0Spx6oZlicB6L3uc3pmPNQa/CQKQfs8eg3+mkanyz8h\nBtYImBHM74ky/tpb2Ll1sTJde+gEnJoiDZrzfwatGOJs2PsQyOvysr3y4tlN\no1y4XMeSoEHMmk98x7TUUqT9tKWaIkW873uCJPGEd9ehsf5dTEj4sMQkf1Gy\n4Rgxq5mxc09odQ1+NKQjWGVL19kovcbE2B4XZm26gn+3ZptX6+HcYowMWRKL\nOys4ZRsUfsnqyx/KrZrFx3Vp/oOvmmBBE2saHAI5IByO0SCbdVOLXuiAXjbr\nXpivj0npVx+cNXt/Yzhtdsz+QM7LlJvWkbFgoG1jAce+kBwHcbuXt4uYnH3r\nKKPbtBmHyn2PqurdxjfSPZ9RB1Ug8tz+qW2suDXiu34zVAYY0P22YhijcbJx\naXVe\r\n=kPeh\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCICsMUQPp0kOpEMaL0RZbR3q24CZIkpYYN1CRTaxx+E0GAiEAz3Uc5YG3xL1dVQIpZf7Ax897npcviimTw2FyymHB1NY="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.05b1cf5.0_1580842638028_0.6872772388884882"},"_hasShrinkwrap":false},"0.0.0-canary.986cea9.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.986cea9.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.986cea9.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^23.0.4","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.986cea9.0","fusion-test-utils":"0.0.0-canary.986cea9.0","fusion-tokens":"0.0.0-canary.986cea9.0","generic-session":"0.1.2","get-port":"^5.0.0","prettier":"^1.18.2","sinon":"^7.1.1","jest":"^24.9.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.986cea9.0","fusion-tokens":"0.0.0-canary.986cea9.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.986cea9.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.986cea9.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-IE4ORn+cI16+21ffxR4HjOTlVrgchEmhyQysYPLa5z1Wy92ljCJ84VwSigVzVTaKl17ieFeQd/RGGi0gFqY/rg==","shasum":"6e4f5c1328de1af122bf08398a75f9dd1743fd47","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.986cea9.0.tgz","fileCount":40,"unpackedSize":182083,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeOeSYCRA9TVsSAnZWagAA6jQP/35JMKBI1fYoxMdezg8J\nGIiI7eHDk2Qm3j3ShWx0fzrVsgIEfLJQccFuJ7bT5ERLJV14VhHvkUPzjbhZ\n18IYAtnRDxR2z59iSh2Ncq8RsSfOFgk7gfpJ1CKQ6bjLwmq1e2AqAOWgZ0wH\nvPqU2Kmoc7LDF5djR+Ny3l5VcBWe9LLNLIGR6v0L7iUyUrvvvS5siVs+2JL3\n/gQ04fyCdgjlip+uPzVUDwQWKlhm3tr9JkL9cVOE9K2UbqVIMHgPCbYG9vZW\nMu6NvD7V9L546dQm2ZscEJ5xgPCzKCq1brqao+FszfVDm8PTgcAdItnM9Jji\nZPW6/MJSB1JW7rXFEWauprR9vbH15aKK6/bD7eCEmziZnyEmqdU3R4m6auds\nan8wpDUpODCyDKvJt7ajzmelO/rpvAl5rYxZW3oPKs8DZPxWmuaLmoaD83F7\n1kT3fC7MnyCW3Rvwp64gkiA9LQhmczcIbT++0AaLtD4eN8jVTh1NQa0kDf6b\nV5odUQ+hmZVckcNAsGGN7GbomkUK9nQlvmtSszQ6vEMDee5srE7Si8lcVBCu\nYYEStsXlvHthQ9rV/8MNanFT71pYUyd48XtIByPMEGskqc3Msdr7b94xVDEX\nFbOMMyg1AKFV2PSIvW2QdzigIFQ8VFpPeXeVRc7yH7DN7w/LXhAE6uj7le+F\n5GPh\r\n=O3s4\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIHOCTiuHxnzAhdarDJ9SkzQUoSLokKdxXBM7nNb86naOAiEAk4OlEYZGFA1k1KNF+5P7tktBRpOrOIAoTXYOKDz7E7k="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.986cea9.0_1580852376218_0.6079026631768005"},"_hasShrinkwrap":false},"0.0.0-canary.b8a6237.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.b8a6237.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.b8a6237.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^23.0.4","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.b8a6237.0","fusion-test-utils":"0.0.0-canary.b8a6237.0","fusion-tokens":"0.0.0-canary.b8a6237.0","generic-session":"0.1.2","get-port":"^5.0.0","prettier":"^1.18.2","sinon":"^7.1.1","jest":"^24.9.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.b8a6237.0","fusion-tokens":"0.0.0-canary.b8a6237.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.b8a6237.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.b8a6237.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-ye/MQ2BF6eYhJAJNc0E+Hxz83vm+hd7G6BAej4BDcg5HKKLwa5pFmoOdycmy1Q2qgkM89ObqVp7OB1O2ycbFKQ==","shasum":"1022b0eab5d81063d6b9bbc9c708e0d49522d1a4","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.b8a6237.0.tgz","fileCount":40,"unpackedSize":182083,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeOwmgCRA9TVsSAnZWagAAnWwP/2CvUtCOFgFWCSvBAZWv\nzfLTYhku/DOw5RdLLeFy8bJN3Wi8JLXA7MVf1azEKRcSlDRWXFNH0MaYETxv\nsk3FO+2nZsunRNFS4RphjMwUQhXRkRi3atXik/UikWuUQ0N+v3qEE8G7vn4e\nwVCdnhPLSh7kRfTS4R9qyVRP5Ld5s1xGeVMDKLoMithbYssBxtkojtmfq85s\n9gNpWpThuofdbQGKDhfMsYd4yxeWpUqpj+eI/KPnP//3mDrfGpiK/8ByQQ/H\n2Of8QzUH3oz2K6AZRZMbrmE4GxWf31VpKLhe9mInnRgPrtl64y3lP8H0N/2d\nYY2f+R1lSewdHEujWGWtksrVwoBHSwMpvibydyt5K4NEs9SZRCvWbaadfZGp\nG9JSKYv11ozoAS4ss9uRuRoy4Siv9BwDVyWFW0yVr8TCjdk2NLjXjHraeO2Y\nPcwbQhe2CNv70unJElpwQhxZzKrpez1CWDFRhhBgi0x/bmQKW1MkNPauGzD6\nAbcj7wtWIxCxc+Jyj3Njkg9rbZTGIBxuRHRgKkjoUBQXcnZnDWBSWD6OjdtB\n200pfR8RSdxrfjRsOh4YEbWJu190EINAeY6SRuW0wg0ls/Pg/zl/VgkYJTSE\nMyRaSWP7ur4Tz+INYgM4NOQ/9MnfEa8Lfsd5dl1syVQK88/WNzyD+xRetMcD\nW2Da\r\n=G60E\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDFFq5mK3U8tfrHJV9KpLzndACsBK936eL3u6pHe3JpwgIhAMLjHTnNPvYezsYIWFDMyxdMkAykZvoyMfNrAkh5cNow"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.b8a6237.0_1580927391929_0.8505162085054059"},"_hasShrinkwrap":false},"0.0.0-canary.2c705b4.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.2c705b4.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.2c705b4.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^23.0.4","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.2c705b4.0","fusion-test-utils":"0.0.0-canary.2c705b4.0","fusion-tokens":"0.0.0-canary.2c705b4.0","generic-session":"0.1.2","get-port":"^5.0.0","prettier":"^1.18.2","sinon":"^7.1.1","jest":"^24.9.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.2c705b4.0","fusion-tokens":"0.0.0-canary.2c705b4.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.2c705b4.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.2c705b4.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-AVeMRiv5PMCXEX7an43tMaEzBJ5aYOqUBxTZdn1KYQvau39zGeCwJHAcg4U6NQDEUA4sUj+u1CSFOlxZY5b82g==","shasum":"762d34f29c0b5d501ff8df802dfe4ed4f1aa12bc","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.2c705b4.0.tgz","fileCount":40,"unpackedSize":182083,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeOyy4CRA9TVsSAnZWagAAKbsP/2AzNXTr4H3cqRloNa7J\nK3PfZgUpjqk69ARYJA9+wkSOY9b6P5sskuZpldHQ6EsLnsLhZDemiypnw+c2\n6uyhcSExbN0idQ7bXJj3S3TcKSUlARDeVsXpJWwZeyTA44T07lLjumN2mXrp\nNV3Ws3AUIk+EpdTMLdeAdtOzfspKYPBSGgiujcrqG9zmoLVoWt4oxQ/KW3S1\nopNfI5Vx+p+pvCTwPXmPeqZlQA3nAkhlv9SujQoo8HOWcO1lx6EB4j6g9gaw\nyTusyGrahS4/Exotmh3jaC9bkqwBPYN6bwsTqg260T6rUreLRdK2F+AK9pDg\nMOU63BK7NU6IrYNsKgd+j6O/sNXHpLSNOAoc1YT0UqFahEsxsJxQ+ics25Mf\nRQpjnNP4oBz/XHLft+7+i42iqLdoYWHp1FJNSOxazasgMQ0HYGxN4PAHMWOz\nbZw8ZJ4HEwJP9A6AjkMxo+Sg03KsYz5QG2216PDM1Azu5Hkl5o6AELb0p2JJ\npinsXLj77Mj1duzrmnRw8PpMFRWAHJW+ajodmKGMXQjIuLAh2ZweBCrU4fRF\nGDpbPG+w793185b1sYwdKXEBOUWm9APgnWfYhqxhYrIww+x+XrMGthDK7Loe\nPF9n9RW3hcj8oNDQplWZCYHB5kcoVgJTzQ1oveVNEAINqNJ+RnMYL3cb2T9B\nvk8N\r\n=2TMC\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCIDQ4imnMSnNHmsQGnTT7gMltsA05QZmaxaYq9P+m/aAIhAMCXgRKp9mnht9LX+3GJe0bmE0t2aslfV9mdsbABKpW2"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.2c705b4.0_1580936376368_0.27923618836852704"},"_hasShrinkwrap":false},"0.0.0-canary.4b659af.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.4b659af.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.4b659af.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^23.0.4","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.4b659af.0","fusion-test-utils":"0.0.0-canary.4b659af.0","fusion-tokens":"0.0.0-canary.4b659af.0","generic-session":"0.1.2","get-port":"^5.0.0","prettier":"^1.18.2","sinon":"^7.1.1","jest":"^24.9.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.4b659af.0","fusion-tokens":"0.0.0-canary.4b659af.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.4b659af.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.4b659af.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-sq5FxInVy9ogwm7zNFVF4haEPK7EPaSEqAeR8q+zeiBKcKhwhDWgBnhBGcIoUPYfbkb0Dsn+ItDnKJdg5iC7fA==","shasum":"e8b42b64cfdf6482d8060b54214bf40e49427155","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.4b659af.0.tgz","fileCount":40,"unpackedSize":182083,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeOzDJCRA9TVsSAnZWagAAeQAP/i9KlV6YYb8qahl4Pb3o\n94UKTpanxrCu8ltIuDFVZsxSNxqZ0A7vzg64eFG2JjrdCt3aLgx40D/zSfJW\nPRadEd8wtNx6J/AxYvFbpcVmf2NIhG5xIoYIUybodQR9RjczytM8DXo7DuUF\ntKNabxYWIpv83/mpWimy1p5NwvPeMyxVXm9pBWGWYuno6882LF6HBPx1Cu+l\nu/5cXL7AuLNXJUVRlaIDh5PV+q/U2WqlZEFg8p4SaS7UnUrjnoo7kFDYJz5v\ncF/5CqsCVD5XjFbtfMeFvR8Wnqx0SfwXkWN53qGEFrUKg6to152W3Fo81FSm\nMrxF9DlIRRYQ2YthK2SpWgUWDupourQq2pWqvSjplg3aTq+7V5NPSwkBGTqX\n9BbN/kaJiN5tbX2onlDEkVEDGueCnlnOykKPocmBe9zqBB5lS8N/U5aRyJ3C\nmQ8BCbPWjtnztkMFVNRmN77mu4qE7Zz2Y7P6tnlRAq5OUs/myFg0ggu9VXfe\nDDDIHtPSzmIr6A1/qH/fX/C93+kzeeorNl1QlS9Nf2Z+ug8vBa7aXbKMWlSo\nIVYE4Km0zzZdmbFa8ctLo7ROXHfpDbiZwBXffkrihzc/mt7QaGBoMsvoT6OX\nbp1VumibJa+i66XQrbWMQ5ENtQv6g7JocQ/puO3kjOCrVluIcCkHCokmirvm\nIJj4\r\n=0Czu\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIEh3R2QLUdAf/YlyiiKkVrxAdSc6nQT5A4nwncTuu9mgAiEA6dUENkPjw58zUDmA7PvcBTRaNIGJbRAUhN534PCmPGk="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.4b659af.0_1580937416578_0.8176455754893475"},"_hasShrinkwrap":false},"0.0.0-canary.96e8674.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.96e8674.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.96e8674.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^23.0.4","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.96e8674.0","fusion-test-utils":"0.0.0-canary.96e8674.0","fusion-tokens":"0.0.0-canary.96e8674.0","generic-session":"0.1.2","get-port":"^5.0.0","prettier":"^1.18.2","sinon":"^7.1.1","jest":"^24.9.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.96e8674.0","fusion-tokens":"0.0.0-canary.96e8674.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.96e8674.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.96e8674.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-ahfYcuMFDnEtLWK1YD+o5XF4MMd+a/oTeSAOWGLvgTUgZJFQ1bkMZCaczNIAb8yidupNtdVM5HJ2qj7goUSL5Q==","shasum":"9164cb95d5339967c34c750d755eb3a2f8b9d6a9","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.96e8674.0.tgz","fileCount":40,"unpackedSize":182083,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeOzMeCRA9TVsSAnZWagAA87oQAIILVQfvpZDbxbJd7WQM\nk/zhnJxTscVvdrs1l/oSzz58IcdARSF5UcYNNs7pB29rQ+HEZ0nXUU6tS5t3\nsOylA3BUOZw2gwhdt+BnmvKAReJualPXfqfz040FY6ugEbQxhTw399r+h3NG\nl+CQLJYR9vcq+nu56Ym+7SOXK4rIriNfMWMEhfzUr3/SgCYw9n+6eWFugrCR\n8KkIQsX80wy6ZUTWCzQ+QsMiquhHlnuI3faD4f7EzejHE+G/z5gMdMAj+aAz\n5Ryl0XkXK52fMEemoHcTB+F91v6l8urRVhSNcRQxivVLoVXBdhSaVlyimXbG\nIMx6A4Qcvsluz7+puoJtGuwhP9CbTULekhWFceZKvjfNrdQgosrjRK31N9Ti\nZvet9rzuqdZYCA02jSuBtqE1qMckKcgsK0T4R3Ffk5exuDNK5mu+sSdO6xm3\nHTG3mcn30xf0fCzPMTcCHYEGihGdz8M4kKbvT/+VgkLFuN2fZiCRXrF44b2F\nJFahHg39m7ybuZL5o98ekfDFaSzMCxYyQQnc6BUijnMMTRqHCYjUtDDCd3Ty\nwek8C0jTt48IA/gNq3OH5pFJTwJfW9LrD5NBwubkjik66dYfpQeegbtSBKPf\nA/Wy5unxPifVKNsG44tbbj00zmnZ0lFsUanOL8MsCULOEu4DWT88sLt62A1r\nXAdp\r\n=zY2B\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCICGYu8tlZfn0RfYB8813Ewg9k8GRfSHgQJTHMED53HWRAiAc5LS7UK2cQFFZNbgU/EqF8WsqGTs56dGEx/+oD0oWHg=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.96e8674.0_1580938013732_0.33303246043925205"},"_hasShrinkwrap":false},"0.0.0-canary.96e8674.1":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.96e8674.1","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.96e8674.1","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^23.0.4","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.96e8674.1","fusion-test-utils":"0.0.0-canary.96e8674.1","fusion-tokens":"0.0.0-canary.96e8674.1","generic-session":"0.1.2","get-port":"^5.0.0","prettier":"^1.18.2","sinon":"^7.1.1","jest":"^24.9.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.96e8674.1","fusion-tokens":"0.0.0-canary.96e8674.1"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.96e8674.1.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.96e8674.1","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-6dGEeDeg6PBO/sMOwypIuON6kJvr1aFoP18TX3engwZlyk6tBKELuVoCq9TREfOQE7pNSMpzAnyn2E0tOWe01Q==","shasum":"f2dcc864ca9bc918a07c1f9b4122c78eeb6c0d00","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.96e8674.1.tgz","fileCount":40,"unpackedSize":182083,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeOzVzCRA9TVsSAnZWagAAEnMP/3M/HJhCWSx5PBjYoK/r\ntWOFXy2LND97XVm6XEpwX7XMgR6dWV1c5jRB0NaVGWTCekFvYUeldf6JtBKY\nB9Jx3n+vPiOwomg3CKrccceQS6VK7BDA2QARCR1A8uTKuAH/6UAwmS6PLo/L\n7phtMhEPP5q422DJ5N6Q7dsEXEdxYR+dEoUCAel0CbjP8GW/BJg+1KQoeh0a\n/NVF5QBwqOiDC23m23iq0K12evK71oQNxqkM7oaYpcwRtd5n8KGZCN9xKCA5\nHpNbesvVQnKg4SkuBMWaOSKtrY7Oytbq5AOW9NpqSQyW7ua9/hpL8BCs8vUe\nbSU3yqE0xe2d9cNCCHS1WpptOuxUDumfWoLTOCfazfWtAqPyuYfIjE8SOSD9\nP8h9CARa6bx7j2aa4lWHqeC97Rauy5K1ox4CYoxuLHfirjsVccW9Cj6HVEI7\nJsJpMSvRnl2et+cno6pCDGbF0GXSrRmgp6+EcdD4KmulDhguSAa8iBubc/tB\nTvb0xSMJJK4U6k1xyC7LNIdVB3ud3vUpNCz13+2/sz9zMp6ZrTwXuy7Lggjv\nso3sV/YpVC903BNZo8wSxtmalGOEpNJ2f35L9JH3wViHZcQ8ehg1rx6M3TXW\nTqLLGANu/zgVgIpyKfy6sO4aLF3qb/GCWxZhJGQCpZiuTcqn2pOEu6fivss7\nIeza\r\n=Wi5G\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCj7m70bdRNKd3Mf3Kug8iyujXNcOv1Yg0QUKx4kzhs2QIhAJqaI+jKInugWQgPXhmT09gNS+pOd9ctV4zhDX37XZvG"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.96e8674.1_1580938610812_0.6334737055453923"},"_hasShrinkwrap":false},"0.0.0-canary.96e8674.2":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.96e8674.2","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.96e8674.2","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^23.0.4","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.96e8674.2","fusion-test-utils":"0.0.0-canary.96e8674.2","fusion-tokens":"0.0.0-canary.96e8674.2","generic-session":"0.1.2","get-port":"^5.0.0","prettier":"^1.18.2","sinon":"^7.1.1","jest":"^24.9.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.96e8674.2","fusion-tokens":"0.0.0-canary.96e8674.2"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.96e8674.2.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.96e8674.2","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-R0KWP6gy26Io4sR42b55+Ufl42d4uFIjYZNzblRU8fU/KJFXiQaikEHE3eHkjAPtiiPqtYX/DmXgq8biLjyMXw==","shasum":"ccb4b81c5e0f19c6d400fb1ab84c4bf76a395964","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.96e8674.2.tgz","fileCount":40,"unpackedSize":182083,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeOzgXCRA9TVsSAnZWagAAR3cP+gPVajLDtm3vclJdgRYE\neNQURIXaai+xpr1FRfd4c+REmfKV/b83XYJjakJtJaL3FfZmgBqAHakM3SVC\n9PR3pqBQamN1/80yZ621C3rA7jNeGux6mOjxdiA8deRc9/0SLfpJlfhMJMme\nHAlfC6L0QuSTgl3bQBqAal5HXFlGduHsMGrP7BcZXhHrIKER0ggW1Y8fedgh\nUnx93D/tfIJu3ev4Qv/OxbtFRw3VItIYOvsC3rqw3X2+0Gv6619DL2nbFNOZ\nQzeW707zDrPn7Jn21mOZI1HEepITP3hct4Zp+nqG+fd86L8dq/ZIor3KE9gF\n2PWpUvg9GpNlEPued+rh56UpNLFlqcOP3vKWQybGxCjsDuqt+84Yq3oZfatx\n3QFPlWBNGGMflT2gMWbR6WoK0hsq8eXMjazbHvhQGtSaZ+Ew7AoVnkt3lqZK\n9/fo++j6NAE+sX4qsRSeYzXxNwxyKJiSZC1O++l+DRR266g9RE290+3HFB1X\nWNOC4q2YZTg1Eik/ReuNl6HBLvvmBz9y+HLkWuLQ5ZijptPfafRzjDCXaoCk\nsqOqP/WIh0rfWpWGFUwHmNG6wgp7yqyTFP7NHzw0jGOmsxF99KJdm8lRKz0+\n4/G/ela/ANMftcUm9FmlOoQBeFA1HL2w3zsnx1CmMqDp7E+QfBtE59shK/tw\nXSl6\r\n=vtym\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDnczqLJ3ot8G3ev1tiKhxh66VvsGxIxWPhWuL52AvoSgIgPkrfc3ja+/38mmH2vVXbDaEQBRZpZ+NmvjQSCKZEaEs="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.96e8674.2_1580939287251_0.4582933789668482"},"_hasShrinkwrap":false},"0.0.0-canary.b640602.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.b640602.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.b640602.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^23.0.4","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.b640602.0","fusion-test-utils":"0.0.0-canary.b640602.0","fusion-tokens":"0.0.0-canary.b640602.0","generic-session":"0.1.2","get-port":"^5.0.0","prettier":"^1.18.2","sinon":"^7.1.1","jest":"^24.9.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.b640602.0","fusion-tokens":"0.0.0-canary.b640602.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.b640602.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.b640602.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-gzVIom2LPxq1TYisA48kNIWh7YhPZ7nCphPh2RX+8/Q1TMXF5Aht1DkF2FfL9sNzCOzeQRlf4a9XTP80LbsT0w==","shasum":"90c2c988254b11e7484895ffc59343fce82686f7","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.b640602.0.tgz","fileCount":40,"unpackedSize":182083,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeO04SCRA9TVsSAnZWagAA0CcP/2dMg9xv2zdsJn4t5QLk\nNPw5X5BC6dhsx/XEo+v4Beju+M4TSlA81D+tmTA7PDoI9FwDTyO6pj+vLmaH\n+hQo7ZzZitMNnfn860rrNFxIQYOIDIM2fQSJ0P70XJHxbwXCdn6pRcP7cMF6\nad+gmc2noDgcakSP0IRI7tImzK8e7kMxkCiJH7013AgmF34U0QB5t+q6tutl\nFP6ZbFDsQIZy+mLo2JwUe6WOT4HcjeJbBP9ru1wKB3zVh6PU0S4kmKDt80IS\nJr6q3T5RtSF6zqztWm+HwC9Wrso8533txW/p4yoivBM/F/Ct06QLX4Cs5ptP\nglK9lArXUFZXhGW7OKyX8rvYmgk6ix1nPTSeR+qdn8CSUMkGmOVMmlLp8umk\n1E7tNa2/BhpdfWWOADoHkZIl/Icoasx6gXgR0tcI0BON6FWLEYLi1tws9f8L\nuIv/sf29Yd5ozfjIxuSQ1dNh5MWhbFGAXWAgWpXy2DA6i5edeMrp0R1Kyjpd\nvOAnvc+2ueRbCO6ClEgPwwjg+3pzqix/yPWE7bykfAYyrB+AQCA52iGSCBul\nF8gMUZKoNoTHD94gEae+kobyiQjMJ7C1qgmZ1UNrFGTm3FlWULN+DxfpaytV\nXAUFmntMKMcguIiAXBOWYzIDgh2AXmUJ3GOLe1EDRYpmg7Rx2FYB81xgOXC1\nP0Vs\r\n=tfnZ\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIEpgPkmfxwNCpeR19Dxq9/5tGNvNy0/c7w5MRyCtD4sVAiEAnQsC4COUH+RBG1gQeB23x150Kp0d2XA8jyQyAcd+iTI="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.b640602.0_1580944914445_0.010345721051045809"},"_hasShrinkwrap":false},"0.0.0-canary.b640602.1":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.b640602.1","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.b640602.1","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^23.0.4","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.b640602.1","fusion-test-utils":"0.0.0-canary.b640602.1","fusion-tokens":"0.0.0-canary.b640602.1","generic-session":"0.1.2","get-port":"^5.0.0","prettier":"^1.18.2","sinon":"^7.1.1","jest":"^24.9.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.b640602.1","fusion-tokens":"0.0.0-canary.b640602.1"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.b640602.1.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.b640602.1","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-BhLoRMhWoxI3ouKGle08PsJl82AicRM9FSrqDZl2I2hyeojga3YQpzywFg9J9Q6CluLm52wQOiA40Zgu+ff8bw==","shasum":"fe5b757ea1786180590f7c6e46f8b26a6a08f987","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.b640602.1.tgz","fileCount":40,"unpackedSize":182083,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeO1EKCRA9TVsSAnZWagAAoWQQAJfOGB6IAn9PPJ5LmyBo\nvfXh0Hk1dswZt1yET+yRzjPP+eYdA20SByK53o4+Tbp5K0BXVYhz9YE938Ot\ni0VxyjBmbOVo4AKp5rIV4pZ0AxkztD1anHhXAlL3u1LSZfc79IY5imLO5HlP\nyHrom0KS+Yj99a+pZ+NzXgziclZ9+16GAPCcr+TpfRuW6hPMwLOgrosjZHt9\nRQHYW894pUpO8qzGZISPwpqcojyMVpiK/4RnUwiTp9+NHT217pgSGYSkbhHM\nqWOyDTPjzn5NgtyCWpyT81T5/8hLUdccCtyDamRc0zYUMtcr6U9J/T+wpiUT\nuy+iE2UgukZDGv+lrhLMoOY9ff401LnBcCSwrE98GZ7QC+kjdyRieF29bFoO\nnzn1Uky6yqYE6yBVgDm/otL9VzZbAjHth03rIw+I13A90odUFjAGdaZPEdve\nrZLaLIioLhRnWSy5UVbT5Ot4ASyJs9LoXL0+xeYEw7Toqs6FCF7EY3dDW7fd\n/AYKnuf2b+lEuYmDClpYITXX3FLIfkGKlXdL3ND+xN0rv6lWZUFxUqVdt3tF\nv3FGze8K29dgvN9RIYBq80g3o4A0oqrkXPPq/zQzW8qTwcpxgIjLduB689AO\nEzsc9JWnjziSRFPxD9WM8orVWJxKak7WjWykO2VQrRbPmJxLrjf+wnSOL11V\n1G7G\r\n=w6Kq\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDoDCAkYaRTe+23GhvWDOM5NWjx13iL0i9kzjY9+4tODwIhAM9mtN0WrnyEed05F0K8+7oKqBXjzqZxAuVK6E5kEokr"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.b640602.1_1580945672818_0.035885408790766515"},"_hasShrinkwrap":false},"0.0.0-canary.2ef1293.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.2ef1293.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.2ef1293.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^23.0.4","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.2ef1293.0","fusion-test-utils":"0.0.0-canary.2ef1293.0","fusion-tokens":"0.0.0-canary.2ef1293.0","generic-session":"0.1.2","get-port":"^5.0.0","prettier":"^1.18.2","sinon":"^7.1.1","jest":"^24.9.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.2ef1293.0","fusion-tokens":"0.0.0-canary.2ef1293.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.2ef1293.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.2ef1293.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-JP0PINLPG933HpVXW9SVfpXunTATRstS51dGNToJkQcp29cGgGweq4Q3Y/YxGRy9X0h0w/ibdALd1xPNd7IuaA==","shasum":"54f8185cebb1516fd23f6b378c56c4a8981e6779","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.2ef1293.0.tgz","fileCount":40,"unpackedSize":182083,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeO1WtCRA9TVsSAnZWagAAxpUP/2fWH+biQMxrZnH0gs2l\nV1PK4gizRt/xto7FWcoQVD+7VCEnsovLBtrQgRyot2+/dHf55x6deURdzj2x\nBFD0ERN+3HSICFONIPy8riKkRaI+6Jfj3COL2oLtXTx3GXqUWyb6vocNBcfw\ngSlQHw6cmegh1uQesRJAns83yqkZFHX6QQTWUsq6qmz0d7sINYiCSCGPjJiE\naPld5H8BK7nwytfPZ/wIw23JUwdoDaLPDZmNQA3S5Og2zCtMhPG0BqdEPEHK\niZwSIrzJ95ruDtkYysj8bCtNAY+QfavoMoWlKP6H6AXQ2DwlQlkywe7fHy+K\nnTonjx4Kb/6d7MyeoiyGoTNbFxEVStsoV7Rdx7Px+sQz7e4L7JSG6RlXiTXw\neypyDbel1/SvFAXxBSnpcTUHlCmyW0GTyMIKY6/oRKXSZ8HWrgjYo3aElYBq\nKKfRI4u5hSA66b3BFqELG3jViVRGjFmTFuvGGjfRgzqg3I7I4WiPo5wKZswO\nci7qTY5ID2GNtjp3koDhQj/+cM3kHt2217tiYky/qVwG7W089IzPk29/cZ91\nsHR03Zg+JKyo8A5ZxwtjGsND9aoEZiJ2bZQfpapLaoKR29NaI0JAEGLT/34Q\n+/ywbi97bBbNnbG0Ahb2kPwvjL0sbd/8e/usGLVbR6sIU3opV4/5/4gZ/SPX\nMelB\r\n=ujcY\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIA0dR+GCy2jy2f5hgr7WilNQozNeITT7E5Qb43Ce+7OXAiByl7p8kZjAgNoACUiEadoftgHzADmKAlqEP25Dqwo7BQ=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.2ef1293.0_1580946861435_0.35727934663108485"},"_hasShrinkwrap":false},"0.0.0-canary.2ef1293.1":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.2ef1293.1","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.2ef1293.1","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^23.0.4","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.2ef1293.1","fusion-test-utils":"0.0.0-canary.2ef1293.1","fusion-tokens":"0.0.0-canary.2ef1293.1","generic-session":"0.1.2","get-port":"^5.0.0","prettier":"^1.18.2","sinon":"^7.1.1","jest":"^24.9.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.2ef1293.1","fusion-tokens":"0.0.0-canary.2ef1293.1"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.2ef1293.1.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.2ef1293.1","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-DenPRVZJLmXHKyhHMj8OyGhwHX6nlRsSowmbHu11j92rkBI0iPNZPt9PEtn3PBgkCu7cfJ/mAZNrC+mtq0PHAA==","shasum":"e65397664b6a053d487d4bc67ef360f8391e4a62","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.2ef1293.1.tgz","fileCount":40,"unpackedSize":182083,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeO2jACRA9TVsSAnZWagAA+2IP/3gpi3xHU8WRGGlWnW05\n74EmN17upbgpYQuFwIt7VYwNUQ0MnuHy8R9VwcaDJhwAvONkCIO9dHxkMaHg\ncDtLLm7QSF51iBSY5nDAzfdQTXwuG7/JkeHK772tJWlR2CowbPsN/ufwxgQN\nBMaEwf6ZHYrFxid6WdFVu0+28tJO9rSdal+8LsEkg60PESozKfOQ3zDpXxWd\ncuj5ecyGd4lz4qhsqez0LOg71h8K4LIsV0kiYZODzr4HZHVVNILNhL0DU45k\nhhBox6XKE1GnC4+yTx2LDUTycjukmMhTrMYVFAzyopZ3iVIXm8HCqo1Jng5F\nr8nsrMwJJ93Y6bGJIFUa3bhmkfHPFY94vKnVx/QG9G4+Z3OBXgcvnIX3YLT0\nCHV9Uevru8gGUmchu1s76o3B2nDJoWd98/XXIW6UD3SxM1Jj9TNjmjXl2132\n5CSehcD8SMoF4eePmkhtHgeBqCUWvMWBKlasBoiN/5mtSalNqVGlLbbxJi5Q\nPTNccogVaziBOlfPfu0uH8Nkxbpi51c55Kdxhtb4VzlWbTVpqsdUplVqfBZl\nA8r2xYfL08v040pJl5NlJ+QU5dXIv9OFraLeyHJleRfYVKnHIA+afep7zPsG\n3XO8xILPUSELmd/++qhZzz4CVgF3RuvqHD2s8xF2jFdIkd98E1MMdl1WeQDT\nHBf2\r\n=gGbA\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIHzNKeMkHtB/GaXwT/mh4BLZGhFrQkqWT7Gsd+UBOyCPAiAGoiXr6pLo8vzPNZthaDrY36dJbNpffjHljp+V4Gxb1Q=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.2ef1293.1_1580951744466_0.6314702746238736"},"_hasShrinkwrap":false},"0.0.0-canary.2467727.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.2467727.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.2467727.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^23.0.4","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.2467727.0","fusion-test-utils":"0.0.0-canary.2467727.0","fusion-tokens":"0.0.0-canary.2467727.0","generic-session":"0.1.2","get-port":"^5.0.0","prettier":"^1.18.2","sinon":"^7.1.1","jest":"^24.9.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.2467727.0","fusion-tokens":"0.0.0-canary.2467727.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.2467727.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.2467727.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-NQa5TmRE9aCLMc1TLIyyy+mVIPIxGw2lKCHGYj/7LS/4JIBR93S6elIgMtv5UB70FQ1CnE7RDNVuVDtRCYtcpQ==","shasum":"f39aa6f58cda549a94c2f65490c88c1639881f9e","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.2467727.0.tgz","fileCount":40,"unpackedSize":182083,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJePGV2CRA9TVsSAnZWagAAt0cP/3Nk6vVygesHujaYUA3U\nokXxnON2zjczGBTziIoN0MPeO/6kmv2EVROZQESOPcbFHNlnNym0jqa4cLnJ\njy0MZy5T3Fns7p87DD3iQfEYm37OVrkc6ddOJ5ptM6n4b3Ji0GEjgWyOVDJZ\nt+ZfjyVXrSb8U8cpa0VHkhXZRpa53qoqSexHdXIHAaKNL1mJC8U2rf+sTr/L\nq1IrhSTlE3O7GxGw2KRgVZdtPfDVWC8ZYigJv3/PkjzcWMBkDdJof8lvcskd\nRWjPDkdcsuOmmXHdov3KbKXgDBx10I63de0fgtnoUfqkrkkkaaCOltDKkwrs\nOhvbQgeFB0bc+uXOAP5AnVV1SA1UrJk3QcsxpzcxBHfaIOrHf6hBDKEXHsYJ\nfpYAJTrGXyhGNqnXuKqrQpOi64t8x2TWuKiahuRxxGcrKh5ivPFzzS2lJCph\nSbHYf38MTALSTxfKkMQW3pPvQfbxVY66iiHE80xpV6XFEvhPF0tGi7+G+Yxn\nQ6OGV6L1w4kFVee2afCVSnqz+2MK88cMaeAGoa6QJGOFJ+qOYhPAWTfApiRX\nOXKCE2jIHgq7GWum3XxCxNJan9yAkXtjtRdGZY/UG86tm18B+JalM5wDyM1Q\nNddHeD1mvYQoN5FG97aEg6facBvZ7/hxuj7QLc1oyH7eZZUrJwAmg8Gi8Iy/\nl3jB\r\n=ANMf\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQD0HpXjFt+0fR8jCk7V7J+mkoja6pqFOgl7qh5mlS4gFAIhAJysK3HEOgZcJott5lfhl81ZFFhLBwpIpBwYBYV/h3iH"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.2467727.0_1581016437581_0.6180210353887758"},"_hasShrinkwrap":false},"0.0.0-canary.ccad833.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.ccad833.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.ccad833.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^23.0.4","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.ccad833.0","fusion-test-utils":"0.0.0-canary.ccad833.0","fusion-tokens":"0.0.0-canary.ccad833.0","generic-session":"0.1.2","get-port":"^5.0.0","prettier":"^1.18.2","sinon":"^7.1.1","jest":"^24.9.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.ccad833.0","fusion-tokens":"0.0.0-canary.ccad833.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.ccad833.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.ccad833.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-DeDe0X/41ZqdC9fvueaTm7ipwjK+tZG2xduecbVe3bHtGsu9HuSzjFtu6m2SXRd2oFDSCZGPb4PAvfCNitScuA==","shasum":"6685036c8b981473f10005e17a73d71161cc15fe","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.ccad833.0.tgz","fileCount":40,"unpackedSize":182083,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJePG6ZCRA9TVsSAnZWagAAEdwP/1BP1vICHfQSbC7F2dnD\nYZylsYCymW9vh9VIaQjjtGTKO8zw3j9hZ5ugwD8niBOzlOoAo29EWiREBGe1\nASbmIO6xW1PmYBCEl1T6NM6BkTTSh1lpvILpu9vjK/7jIppareA6QxIbOl0k\nkx5yRtm8A3s1WRIOrwv81HXZEBNfAPlfgSMLX7CJk3hs+aFb6E/eJOqIs+UR\nPgo/ZkXH92nKKADOdpfpcBJx2m5Tp9y7VlrkPJg38scEZl/iXbP0pEmhHk+S\ngsIahPK9Vrz9Ium2kUR3nN7Kpw79A9HdAuFlidqh+MPmswQz+5j2WUSBm9Wo\n8f/xzZ4H4r9EF65hTKopoLAwfjimLPWqlEjgBzMadD2Bs8QyFjtrgWOiQ6+/\nPQLC7kRMetBWbUHlbM/h9s54OI2bD3UJHeWBqLO+KUe+wtbMofM/HxUNOLhQ\nyLbdKnXVNZx+k3Nbm2h0wnoGDGANbhXMGjF9ZzR+MN0VdDxm6qDfgGMM5F/p\nQuEz+F0Yzq+lkyOxe3wE+woA1yuxWG1wyVL55nwgZt2hW7IWvXFcMEXCWQ6b\n8qZdoGWsdBGVZn2um8INDkoiOvFGjZEhaAMqBG8Pmso8Ulc7g6Z8uMii3X8o\nMmxZBziocLOke3Bb7nuAJEHWrjU7AaLk3a/VQgOE/F2WMAfk9bKTP9Lmp3BH\n483d\r\n=Ipqa\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIFZCPom0LMxJO1T0G3YR4F8RtRdtwH0yyj4BA52HtQ/PAiEA8mJ5NpicYwNXmU+prf0KHXwe7SgyudImJa8k+hkej1U="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.ccad833.0_1581018776809_0.4819282741942692"},"_hasShrinkwrap":false},"0.0.0-canary.e70cabc.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.e70cabc.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.e70cabc.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^23.0.4","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.e70cabc.0","fusion-test-utils":"0.0.0-canary.e70cabc.0","fusion-tokens":"0.0.0-canary.e70cabc.0","generic-session":"0.1.2","get-port":"^5.0.0","prettier":"^1.18.2","sinon":"^7.1.1","jest":"^24.9.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.e70cabc.0","fusion-tokens":"0.0.0-canary.e70cabc.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.e70cabc.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.e70cabc.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-3toih7HuKa5B7Px3Cd9uRN0AtYhmCYMxgCSWie+l3R+hd/oy9HL/u4M8NqqnKl+B6eWAUnJwI/5mLLQ6lqjgYQ==","shasum":"a13baa0bfaeb605600fbfb9e3c18cd44a2b22646","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.e70cabc.0.tgz","fileCount":40,"unpackedSize":182083,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJePeYpCRA9TVsSAnZWagAABOcQAIyDFOnomjvmPBe9R6s9\npVXecdRYAoUtrikYYJca5LRh5i6mXq5awbhKiom7f3EXhS79eOWVpvQ4eQ6H\noKFeGIQrKU82pP4ol7OUqBeS8vUT6N70R4SWyI1MyUzfxfegB6q8MJOtUDB5\nCk9gmYqr9QPY1G6ujNmA67fkPQkZ22l+CIiwhx7qR+SJYOCodGOCwOQGNaRF\nwJg62HMVIvNw5oxswL1L43giEex1X3Gjn4B5Z1MuRF12OwWu1cJn0N/kvdrQ\nMOym3i5ySHNbfOPK8qbM0ywkKgsxk7NuzpTPQRPIxGQwcqeypJyNAcvIfVQ7\n+/waYOo9Llw2e2PQ6nVTY22OcJ0RqWcj4O0eZ6sd6WlYriIeCF+AR0BUvfO7\n/DsQ/bXdQfJFL9BP2UONzno/SnyZfWzHhaCY9jIHDKFV4QTws/BqQBmK3+z1\nmFoa54rCiwjcBPjSN81jT0RDd1j9clXY2LZ3vYJLgWgZMpDyZi0Mn3JI7Rsc\ndHF8dGqZgD4VNbB45XhXZ9VFGZRZzLWoR4wiqd1Pz2oMrzMSWpN0coyNj5Is\nuLPiSIf8THeI2BeO/MiJ5uc42kZZmzvIpbF30JcsF9QCn2LGBxW06hKCstXK\n1unpkJSYMN/qkvljUTO9eXkh2sUh25BK1SzAEARs76hdGzDVyH60w2drpWRD\nXcwi\r\n=uPjH\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCICAODoWLblNhuNWZAuC/e3HixI03mO1wlREzaBwyY+J5AiEA0v3cnP1n+SndIZ1MeAGr22DfRQ1TyNK32j/0no8nIDk="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.e70cabc.0_1581114921204_0.8095302943507416"},"_hasShrinkwrap":false},"0.0.0-canary.ed74fa2.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.ed74fa2.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.ed74fa2.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^23.0.4","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.ed74fa2.0","fusion-test-utils":"0.0.0-canary.ed74fa2.0","fusion-tokens":"0.0.0-canary.ed74fa2.0","generic-session":"0.1.2","get-port":"^5.0.0","prettier":"^1.18.2","sinon":"^7.1.1","jest":"^24.9.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.ed74fa2.0","fusion-tokens":"0.0.0-canary.ed74fa2.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.ed74fa2.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.ed74fa2.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-0f0hRhm05kg2dummePrqYzjmXYmcM6ufRaZRKEws8gjx1srNJCLTAoG0cq106GhSpGBJ34r6xeFIyb64n37MYQ==","shasum":"7b40f09f105bb512063d6534e814a949f0b4a0b9","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.ed74fa2.0.tgz","fileCount":40,"unpackedSize":182083,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJePfyGCRA9TVsSAnZWagAAM1sP/2gjB3JCQSwl61l2gsNz\nZNn9KT82w8WoGA6dqJfEwTROd+eVI+7sO5O2GtWqlPgoMTOWMOC49WFvYslK\nQvnbQk37r/WyBnyw61lXeGRvTZbLS4hZh/soz0HETilSKSafci4oNPqEjnir\nhmfJftYTAXfg+/I2w7c/T6UUkeKudHhv7D9tcpwxSorVOnU/dj4GtgwwPoGg\n/29KvBQ20uQ8/DETZlShGGf0+wNuwTdEQJIbT7X4YDiDIp53jl7bik1kQtsK\nTMQg5ZmWZ79sZSOzgTiAfVykS228wnITDsP6W+6OfVX46gZP62Aq7kwiAppM\nJ5flq2cPoPB7vm4RAn124jR+1VOdHCM8Qp5qv8zMWxNiAUBMps3x4meCxKM4\ngEOiN/xTlTAp+bg8sTIovnU3GJgKF5mJcsYkOXBIE84TRFEzv/tT+mRnz75J\nIegmQ4atoN6FNJd1xCu2zaCwkAN1X3S3sProJLtnbbXJSsFTTzbRMMvgyHfX\nuq5trE7wu3KL2lPd4d/96h5sG9g/hcgFOl858Nkez0mHIKyJoy/8F6xZQ1XW\nS51UHwizBJh8f7akluLQcy6uWDresPlfHoexZNtc7t12vhdQ3SxanNB6XphA\n/K4/YTa15MjYkARYaf0ijpwsVcEKFvr6COqk4sXbjFssf9oYYLePXGbJk5zR\np+5O\r\n=dy9r\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIDl60U8BZAW/Vgn+nlQr5g2B+ByW68PCm7MokRTgyuwCAiAUtjzwzUENF9iaFQ4ElPdXtUm595it+iGnIRg5j0l8wg=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.ed74fa2.0_1581120645658_0.6435308333609588"},"_hasShrinkwrap":false},"0.0.0-canary.b127562.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.b127562.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"0.0.0-canary.b127562.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.b127562.0","fusion-test-utils":"0.0.0-canary.b127562.0","fusion-tokens":"0.0.0-canary.b127562.0","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.b127562.0","fusion-tokens":"0.0.0-canary.b127562.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.b127562.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.b127562.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-sY2Qod/+AYb+sr4sdQCW/RYSHdBmB+p+rXbusKeGJL9N9iPP4qOEaCZAx86iCXVLHZWz+W7lhNDJ/1GjJwNDOw==","shasum":"e3431ab8c7f148b144f26efef0b17309ad7073aa","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.b127562.0.tgz","fileCount":40,"unpackedSize":182082,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeQgE9CRA9TVsSAnZWagAAZt8P+wac2h6msnhhoatPnqN1\niKBXZ1GBigcI6wmeaeIdHziTZTgSDvoNzNQBgPSLzjBtZBrEMUvaqEXg0Bfu\nOot+bLC5a/dXx5EmWnzN8rHp03CLZQPhc2rJmWGMOxARPwtByp4Hpuhx1kk3\nyXgdxp2p+Ah0EuuuDDx4RIZNHJI41dObIBRKUkqmFG2f1au3rsB4eLeZETY8\nOpzMRMGI9WDpLJvwGvOwy6uAnxQ94/KUag2wXVFe4CZM7PsbUL51ETeivJ0y\nJlZI8dWPTfsZqEzbl13G5YusNlAshZbLPR1RXAwGdRNVkHgBq2tpas7KgBvm\nCVSFZMqskqOwjx7zeK36z/8ebg5mAavAltTu96aPe6+V03caFLOCx07KB1cj\nHSmUnTS3W3RDWcfWln5MO963DvrRiYY8KPCGGPDr4uuiwqd0DNFhaMumniJx\npqckikqVX8g4uHHpKn62e7SGYydzWLzvnN1kdU3sqhjRYr/tWbpde/ny3pWf\nyUfcbUG9k4Lll00sgfBxoh65DPRckMtkvCaptkCfMuVo75TinBiUR035Kevz\n2v9HSAOj2p1z16kNfKNF56M4BZASm11U6mk91ky8CM8NqiEoaghf+ElqBdPH\nwtEmhvijUMluzRY6w4SXf09/wpZlf3BcvUC0PzJOFL6BQNB1evr/NbbDmDBQ\nUYYa\r\n=U01r\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQC2iOw2br3WymtUNlIsBJKtC42gSRNA3Ant6qb1mHpUuAIhAL9tHNAAhaX/nxijZgSGw2yrEcqFLREC82JipV6N2/7+"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.b127562.0_1581383997202_0.9079506061782148"},"_hasShrinkwrap":false},"0.0.0-canary.fee0408.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.fee0408.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"0.0.0-canary.fee0408.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.fee0408.0","fusion-test-utils":"0.0.0-canary.fee0408.0","fusion-tokens":"0.0.0-canary.fee0408.0","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.fee0408.0","fusion-tokens":"0.0.0-canary.fee0408.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.fee0408.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.fee0408.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-kv86XwEXlBGpso7/3Zdjbg5DLsBSkVQ2IIttctgeI8n2Z7xPX/heW8UiMklqDXws/CoSpsbswDI/rVu9gYhb1g==","shasum":"bab27b41bb3cfa029b17ab50cdf44d70068f8523","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.fee0408.0.tgz","fileCount":40,"unpackedSize":182082,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeQxORCRA9TVsSAnZWagAAkdcP+wWN54gLtTvV6Fp+txij\nLtUadDieeCji2ciSGtOr9sN6PFCNFIGwY0UWQN8fNhIpUCLPswe50gQIe/5S\njfwuwbgZ+nlz0n3xditmKs08AQoTLjCHodDVnYTYI2KZgH+Vdoiz5esjec+e\nK2fHUWA2aYBYP7fk6Sh/T+JoTHe+n6G8WMCNOCMpwMyu/procdfe6xz3fygr\nH9uqZs1iol97lzAWdakVqw60PbyRsTt3LtyUw1ut5uT94w9yToeCWewM7EaO\nLVJzXwWpdGHCSLvVsNKuQ9mQ0WsJzNlrg3AYtlUpQH5Z96P9v4g12wCH8gFX\nBke54mGBrT/1S8+B6g3tnp97PZ40WiOClfX7OCVhUQxWTsiAf49RcGCQO6Rt\nk3PPoxa6ACc69JvfWsaamPFMIWHpzgpp05JHhoMlVyUEyVI2Y/Pk9NlvsD/6\nIEmfTvBfPBU/OXdZ0/+rmrUMrrgBun+88dF2aDjK7vMjdXjDY+Pv1e5o3Yef\nq4WyJjcF0cOHoSNhuKHT93PP1Kf4SR5eyp+6eg9E2YgQHGl6ItCoOy1Kv//6\nkM6CZAPEyee4ZZkdBnu5yxfO8zwpQM6Zdox2QjGJU/V5JWiNFkg4rjOsZhLm\n4CYWXoydi7u4p9T3M4wXr1AqAupr/l7c4eGhwEaW+UwoO1sstWNtJ7WOCAy8\nUaFA\r\n=a8kq\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQD7AiP3WG3SflzTSWrakjFHBA11a656/F7BM36lS4safAIgCy8WukqqIy+ieYKYHsFfe7OJoanTRIETMJAOc1pD2fU="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.fee0408.0_1581454224728_0.4287761018956775"},"_hasShrinkwrap":false},"0.0.0-canary.9dededf.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.9dededf.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"0.0.0-canary.9dededf.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.9dededf.0","fusion-test-utils":"0.0.0-canary.9dededf.0","fusion-tokens":"0.0.0-canary.9dededf.0","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.9dededf.0","fusion-tokens":"0.0.0-canary.9dededf.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.9dededf.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.9dededf.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-dinmJV/Wk9xdl6NWBOtFQR1gfrU+WntKTMP4y9hsLp71u01l8mZ0AGrOu0LoIaBsKLEgLB6q9QlC8kvoiqhp6w==","shasum":"df56ddc87b4b3b9d161f19ba3aa8dc9723715f6e","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.9dededf.0.tgz","fileCount":40,"unpackedSize":182082,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeQyEbCRA9TVsSAnZWagAAoLgP/0NQQ+C0LkNJ7bWQpFvq\nXJH66Qdx31FDgsyJ27syGg5h4PU7DMb21vrfQKba2w6MLslP54EQe+obtole\nTQ20AzfktKsMC+3F0M1RDyWvwDtwcHjD4uOB7J1bIzbStmblTPxZtkfjNOVN\nKR8M4hcRmSVkqlDQEZ5PzEqzgfKbN0YLQeJVisPIxvzt8V572i8iqAT59heL\ncPijl3+Aj8UYDdjm+5o7JUGX5I/u3xviMco49s0ggUC8WPYvO3LM5A2G0aFV\nfDYHl0zjiGEtVG+ZfyeK+I2e4jTJVcuAA+h39CUQoygueuy/1dWstGYto4qq\nX1fhnVMoWYG4awnL88THi7kjMWhgEBgtriIaKlurSJKkJOEMfZKUwFePZgLz\n5CQtqxGIA4SEijZTEUBgi/sLXjHvVqLCn7mZx6cbVxfUStQOyd/HBwMR7UNQ\nKjo1F3XuU66wMj56wdtod91zw7EsSvlFCO/Crp5XnukxixFyXJfSy3C0yv2U\nwE0FfXZ4JJE8n80uEgOycCQyOFzwyeRtDg+tFycM6rv6gKwmCwYUDMP5xfrU\nOmfuIUmFqnLtFf7Ia8eIauWMoX0zUut1N5Gr+zsE2yrMdT9tScxSQE1+Pf9Q\nPJ8xXiMWsEi/X8+9wR8BNa1R6kuNoNNZovqOMj1X+Hk/8cTMAMUNH4H5h6kh\nx4+P\r\n=ZExj\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIDUtKddspJ9UVUcjIqdH4re3spPi07N1HX8tSuEzi5adAiBKDJDSPFnxQJqcH5pbqO5GelQbHEal0qfiUEG/P16Efg=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.9dededf.0_1581457691029_0.9708229374645914"},"_hasShrinkwrap":false},"0.0.0-canary.9dededf.1":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.9dededf.1","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"0.0.0-canary.9dededf.1","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.9dededf.1","fusion-test-utils":"0.0.0-canary.9dededf.1","fusion-tokens":"0.0.0-canary.9dededf.1","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.9dededf.1","fusion-tokens":"0.0.0-canary.9dededf.1"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.9dededf.1.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.9dededf.1","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-woi/DDAaCEpoLS92VeFFCVO5lZRs4MWWpszv40XGJOcrmaTwiMIsq8g4HK9uURAVU7EnWBf4T1DvJXrSUWwx/Q==","shasum":"acd4ef07e39e0e45adeb83843123dfc8aa59c305","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.9dededf.1.tgz","fileCount":40,"unpackedSize":182082,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeQyIsCRA9TVsSAnZWagAAhjgP/1bDyFnmecxr7mt0wSkQ\nHTApI4j2Ju9q+Ll4hQeh+F9QRFVL63X+kWYE6tMtZbDhTJFcvZm2ktEmAqb3\n/bVeRcj0HRdBMXpI7n55H5EvlBQWQDnukenQwHg5cniStIT7FB0RQBc1ZJNg\nfKmsrnFwnTkMukf7Y6U0uhIdB54fDBWZDbycv190UKLeU7FBbmMWzzQ5gLcI\nZKzWeMOYAhLys1O7c9N6dCR1BsUNH7HTDlOs5/43ZzPUmv6K+gxZCsChr5y4\nuqnLLJLlfBwVVnCu08z9fp9bGKkXbLku6Z81oQtaelAVtqZu6RqHB+1ycLCY\nhUlRADn0KaSBf2o7zwhjlGttQo0DMHb/60txHFeQf66dUtrlAczxXwKmtKCs\nIR92mXPDp4fFnbyKt8BTXa1oIRB6JMWuWeDK/gtmsJ92HqzLkAVJ+nYA9EQX\nzstul7+Y6ZGCJzG+NY9zM3w/KT0ILf8aNNeJ8Q1s0gSyM2EHiwQ2z2Nhan0G\nSnzpas0ES7L8jppWtVZPa9ne+HIU2hUdl0ovtxPI3jKcuxkxw4rjdZYgOvr8\nWJNnnXYRlemlveKTSSOlo6UnIoTUGC0MaiBG5ICw708QtLMQhKxhZD6IUIDu\nNUqGKqr/5KT6giv93wpSe2KGhnFijbGvSMxD7DSFyI/788XvG9W9iIRC2H79\nbYNC\r\n=4v7f\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCHWafs+168qBeuKAPuwMw98X7Jbqp9g6+G/g74k1iwtgIgMsYc8oZg0U/FprNnmMLn/PyHjWXu5hIW6HQ8S4RdZpc="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.9dededf.1_1581457963946_0.147069347956871"},"_hasShrinkwrap":false},"0.0.0-canary.9dededf.2":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.9dededf.2","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"0.0.0-canary.9dededf.2","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.9dededf.2","fusion-test-utils":"0.0.0-canary.9dededf.2","fusion-tokens":"0.0.0-canary.9dededf.2","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.9dededf.2","fusion-tokens":"0.0.0-canary.9dededf.2"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.9dededf.2.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.9dededf.2","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-LI55p+JM/hGAvCji0EVA1Fzqu9lgT7nI7pjBbp8q3aa3lpYgAsecl6sV8n4Hq/76b0WxBGzNTT6zxSAoXoxANw==","shasum":"f88278c3529aa8f684c5657857160a8793fdb77c","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.9dededf.2.tgz","fileCount":40,"unpackedSize":182082,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeQyPdCRA9TVsSAnZWagAA/HoP/0MM1G34bwAA9nyxaAvk\nvIH+4nPHrqcsI01e9vKliyMEKHqzUp+hPOnxt+5nyfJIxDKYbzs2wWgWdq2F\neCpFA07x2BIzu/Dy+F/UYipEo50qDYilZa5Kbq8eIWAm0uv9nl+ZzCZPhJhL\n2Rfj1Q83AkSP1Chw5erLql1l6afKhAfY2+AoKGCZFLn8SYHyX9mx0qMnsIAi\nAwZGeYyhSUKN7mbzZmygjpMDHCBnAmJgFdkAN6FsCD/MBNjBFQx1ke1ZhHxT\nLz7mHLv+uc7TOZYiGaJ+i0zWF4sle1d0IrbWlP14fADSbJohpTZ1JO4oGjm+\n0jFWw/E4K0FYnp10Iczz6XmIPIBvumVMSYp9KV7/iDxguNJQckcayQIkffIX\n2hTotv1LX2C+sStcM1RFWYwv5hN2nwo8hyMsIJWkxpkRkJAj7PyjNp2Hcv1k\npYB6B1RSLS8AgvVBvnFUWMgHyWyUKyvRowCdLxrmNotICyCKbYa0Ou11VHyt\nh5FuYRI4sQNLdl/puMw1quX6nLcFkNMVJaTc7b8VH8Ay0QhOFRDPRjAU9nu2\nG8TwUyG8zka1mvXjL3YzmcS6im4fORSfbAmc14eOBnjiUOnCkNYmbF3Lm9q1\ntxBwEkLUXUHTyQQKc80PKCQGZycBE9Kmcp057H0aecE1zqslW7NX67Xvs3rp\nW5QL\r\n=POfr\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIA7Shx6RpLHj4zL7sq+U1x9d7xr2yYhhBnbg/wva1GgVAiEAs841LBrolZv8P13sYe5kjwOD+NpLDp3nzgBVKAZUUYw="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.9dededf.2_1581458397445_0.16271574070621941"},"_hasShrinkwrap":false},"0.0.0-canary.9dededf.3":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.9dededf.3","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"0.0.0-canary.9dededf.3","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.9dededf.3","fusion-test-utils":"0.0.0-canary.9dededf.3","fusion-tokens":"0.0.0-canary.9dededf.3","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.9dededf.3","fusion-tokens":"0.0.0-canary.9dededf.3"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.9dededf.3.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.9dededf.3","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-BlHuXu2cb9Fh8BYsC0wLMlV7g4+uT7sJ8EF/ilvNws7WtBW6BGv4jGLbXWlCT5F7rI88PYkLkUF+BbbYCgGGLw==","shasum":"53668e6f70964a28e767272432ec328cf2890d78","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.9dededf.3.tgz","fileCount":40,"unpackedSize":182082,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeQyR2CRA9TVsSAnZWagAAOx4P/3uAKTleXwMIITbrBGYw\n7EksqSgL1rwRE9D805o7Y4S7GlNsP97CXRWkRiL+8l79Jbhau5DIqIL31BUW\nZC8C9BwJxBcjTsuS9gOcsUKOPphw5hm2lNH+CbDcgB8WGCtYrm6CbLm6aYiG\nSTN8vYfcGB4LQmohmGtM1okCOPmdbiuoShhQcSg+BbyN4JRCGeFN0Y5BT7GQ\npPAQnNeYyZkzrR8sYIajuw5TO2i08VhFYR92NARw9hYcCkm0bkF2vt1GmsWQ\nlvQrlIn4QJHDm6lxPHoKiB+TFU9qjmMarO5/Oe/mBJ9odW9vhnuvERlEpo3x\nHshZtVrM/9Phm9VDK3tgcscHpyITnrVmVwVuZ22AWZz4tTMZdBMeK5efwMb8\nWg/lXUpimQ8nF2M9NseDtOLLnmSylDt36cbtcjWFRjh6ZpwKnvebVsphwo3V\nK1hqGDbF88TggPa8SRACNEeRybxQrE9vk50WEMHd11/oLoAxUnPsDxNXb/fe\npnbZTqkNHFiLYzbd3K3Cv93aHbRwzHdRa2eO5Pra/a42BOUpXehZbQFhVYwF\nB/QIVpOB8RqMhgjVaF3KuKVcciB0sOWpa3Ou2pELtaOBwqDBDrqMkwfuNkrn\nyDdW6ad3NaoaSkZVe6MLXNSotGrJtOGntWKQw5uL8izwS6S4t/bYL9wGqiyD\nUUJB\r\n=VbZG\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIFui7FoaF7o00eGWzYkFP1/7q0dbYd76yukk0YiX+TO/AiAREuOJ7BxKWpl89B4VcDsMI4vLr672D+RCpmwMdtHQUw=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.9dededf.3_1581458549525_0.7923492167216888"},"_hasShrinkwrap":false},"0.0.0-canary.a0a3534.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.a0a3534.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"0.0.0-canary.a0a3534.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.a0a3534.0","fusion-test-utils":"0.0.0-canary.a0a3534.0","fusion-tokens":"0.0.0-canary.a0a3534.0","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.a0a3534.0","fusion-tokens":"0.0.0-canary.a0a3534.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.a0a3534.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.a0a3534.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-VgtckKc3W7a4HDUMO2oVUJ5kYNSqUCpYFASTCyLX/MLcISABZN1B2bx3dK8+8FpHLFryEbjRfQC6F7qqMHP29Q==","shasum":"8ef6fe78f9a57a3a785ea3bacbc7604ec567706c","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.a0a3534.0.tgz","fileCount":40,"unpackedSize":182465,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeRJdCCRA9TVsSAnZWagAA54gP/1Khsxq5L8r6kue1uJ/j\nhzgixDHsn2gU6HKcJlPv7pKL2IJcbIvo4ga++j8traeLhWmNjsUI2vqfJgqu\nHFsEllBvw8rijwWWx1ux1oU8zqdDBY8moN3uk17gF/Kh6UF2F5Le6oLkjWza\nM3LXp/5dc3c3pCYKMmJCnY0TWjI4iT0PN4WT+at0VXULFviPiQ4buQcu6Fuo\nXTnHeSzXtQeCCptn+de2f1Qlox19GPtJV1CPQg/dkbfwzi7vLO1+/3X/U4fH\nGoWX6yrSLJpzFYCtAQDs1Ep62til30MmXwJ+HQKEAdMfN2u61YVeNir2mPqV\n4ikqGwIGLbrFgNpjI83eyRb5B9uJsWwCOjtZkGq76d8Hm/q/lsI732/GqpmN\neerYrytFpKlLu+GkNzHcZKMlYdpkelvIQ6ObMhBLGWnoElr388a7X7NvmBTf\n7mrUMcwntwLChkdnjbdk7eTkAQTwf9kO4xvmAJG8s9fhQ/SZBWFeRXwPpxQL\nAbfhtvIN14aO57jtryanh3B3BdEPb5K0Q7R/yjzFp5xD/EcQ+PrU+5yfOPxe\nj7E2FSeWkyOf8ZZp196AYLflwj/ygQryQQTw6kQQzlQwAiz3crxjH6q8bzY8\naJFBbS//N8yR00VpcoUyqcXepICf/frYVYGLd3+MVrKy3uVCh2II9Q7dgKqR\nNIL7\r\n=CwIT\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIEMWg1dOv+sTHOl7ZORqfeTYm01E4AMA7idESZM7DXBDAiAOmBW6TJdkno32bnAHnkvcz+pSZZKwhlrZRkxFYKYCKQ=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.a0a3534.0_1581553473582_0.14240046439981557"},"_hasShrinkwrap":false},"0.0.0-canary.513dcf4.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.513dcf4.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"0.0.0-canary.513dcf4.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.513dcf4.0","fusion-test-utils":"0.0.0-canary.513dcf4.0","fusion-tokens":"0.0.0-canary.513dcf4.0","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.513dcf4.0","fusion-tokens":"0.0.0-canary.513dcf4.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.513dcf4.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.513dcf4.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-X4OAwIDDaba3IpH9jvNxbt31NEP0J6702VyC+DZFvpTZwW5r73rTerKAqgahannREM79aH4gRKEH+lcg16Ak3w==","shasum":"d2523179536e83ddb7b46008fe726d06fa322d46","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.513dcf4.0.tgz","fileCount":40,"unpackedSize":182465,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeRJy0CRA9TVsSAnZWagAA63gP/0QsXiXPNYLwE2fNPJb9\nreTAZvW2Iphfv5A5s1RZ1qixteaw2dJlyaq0BkWf2dzwoKZhLeuE/2ro7Xit\nmXPaKRm/nZH8XIjHjpdVToALzxWUZi10zR9lnn/hzKAbA+kNY1YyWHSTrBmI\nBcRjzkix4P5pEeYUEXr0QiBX1VBvCnzw3SCujcEJYt7J2vC2YXNG/rlVQ/C+\nEyH9mCpjLtm+vfnsa1k4YD8UD6wVqt8DMQWYnrZkR+S8vxo12jV7IyLHSsla\njiHxbttUUAtc+w/7qWUbQzke4VxyF4ws6nO4ZBCHebiqH43tdRBHuZ2CBUfR\nZBbcJIoSE4haRJ/jYMOeTHyN9lZ2pE9kMpzzidpDvvv4NAHpujfR1EQV3HRN\n9fUfaPCSIYsn3QWCzP5BhjPshh1d58P4EO/z+UGZGEa0ebtnX5Tm8SSCcD0e\nMDu2rYEBDiSSKprrH68luJRy4LSesfv6csX1HJ6sI8A3yA1ADOBjY1nq5EzT\ntBjPJuKCp/ECDY1TREawXKkf7UMf2LiACx9sehCW9OY6OhMaduMnwBPfIzGl\nZY988A1FxWd4wRoJYFyLC6Xcs6lCj/7MkiWtSt3ywXfFDpNNqrpl9fxEiXE5\nqIWm4s1gtOoGtSOHwcHK3xh/jdl4IdrR/D9xbM+Ez0NF2aYXnAtpEqEhacNt\nYMlu\r\n=r24a\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCcgVcWBXRqXlnnhksCcpgB7rcBevULTfDO33NLjODxtgIhALvkRHqXlkvAbr51ZbapVufASTUtCD4RGNpJ4RyfMIhk"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.513dcf4.0_1581554868403_0.7469420312279986"},"_hasShrinkwrap":false},"0.0.0-canary.b276aaf.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.b276aaf.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"0.0.0-canary.b276aaf.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.b276aaf.0","fusion-test-utils":"0.0.0-canary.b276aaf.0","fusion-tokens":"0.0.0-canary.b276aaf.0","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.b276aaf.0","fusion-tokens":"0.0.0-canary.b276aaf.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.b276aaf.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.b276aaf.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-pV8L/4DzlLobuUwOY8dLthsGWha66phHpj7hr5SCSiFtqZdgUkp5x/mpzSfwz97zQbWmQLtX3ZR95VFASnuX4A==","shasum":"ea1c92e263f2cd0cb8b89abd2fb2d1003b04278b","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.b276aaf.0.tgz","fileCount":40,"unpackedSize":182465,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeRZx+CRA9TVsSAnZWagAA6N0P/1vXhXhtp+yy8wKg88wx\nvOF643/NRfcBKlNocHYa4yw6/ilC4EPTtZkIcIZXbjDy9DuTqNhyHWoZrwIy\nTB02QpjItyDLH9Pvc3FBVQRKPpIuTQ21emXsIMBzQjqpbd3tIYurKJ2NHoID\nNguNc/ncbRuLusFa2X3PXor3u/fQRkjDl+QPKUKGi/O9E+ak/3OiPPy+121s\nGbbQWuZulxCn4Nn3oFBpjjw621H9nVjq8M6lf7w60KqaVMBnbvM7QkMu+DFP\nzf8+MFgGYG/qQ82EBLxZIq/35tOwb4xr6+mDxi0QABBFRwMPvRtxMsALDhih\nDYnojl4PCM7iMOeujab0pcMeQwjooYp0x/gQ3yI0lTi/Y9YScQHxiWGCiPP+\njX1e3ryJFoVOxVuCs8z4GFDruS7YPqmly8JZO5SSJkutvmhNQAV9BmnzeXq9\n2rXVIRqp9+C1M9qNMHw62qdJ/8adT5PNhGOZnKrwlbdXrTRQk02jNCJ9SQ0U\noJAa+Hn1NnLuqpMvNV+cu32xy0OYPNi2bZuT3w8GweOxtpCGpxHQh+Be8QUH\nGg2N94OwYxxhSeGNWE2Nudl1nQrkZhXWjtJJt4RFBOTEg1R7b2TPZEiefAl9\nSWndNKYqhjadKSY06nvK/GGFkvutFXdj/60MibyVNm8I8QbN4BiOgLqf5E9+\nIseE\r\n=Fqv6\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIDf7RqZJ5748ZrU2p/TaizgXwRI4RAvxM5+fXxPHzb3EAiAJfHqm3Y9sl6WcHyTJGo/+V++MD+htio7RPTLOBhBNXQ=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.b276aaf.0_1581620350265_0.8285213005608749"},"_hasShrinkwrap":false},"0.0.0-canary.a8e624c.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.a8e624c.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"0.0.0-canary.a8e624c.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.a8e624c.0","fusion-test-utils":"0.0.0-canary.a8e624c.0","fusion-tokens":"0.0.0-canary.a8e624c.0","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.a8e624c.0","fusion-tokens":"0.0.0-canary.a8e624c.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.a8e624c.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.a8e624c.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-/tgp0jHvUAnbkoLNr/Ue8AR+ZfmRgjvEyC00lQk+8Ade5fOdeOrDrfvEa/nf7wtkX2ra2gJJq9tkpuMJ6N/Q0w==","shasum":"187dbe8043a8fabdd181d5b8914b0dab87521ecb","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.a8e624c.0.tgz","fileCount":40,"unpackedSize":182465,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeReY/CRA9TVsSAnZWagAAJ7MP/3JRs0vFgJkpceytYRdD\nidaDBpdlO7Hr7SQFo1pCWQmP87IZkvZlARzRC0YK26NJJkmj825/XcVkV547\n6F3Uv2rTOmT3oxSWaVxBwi+DENVE+DBiT9p8f6uAsM64K8QrEjFE8StZ5yrq\nN6IRYP7rnm5JXW2fe370y+ecCR5le2furTzad6n1q8reKY03BtHAdHWy3ooi\n1fIMJG7K2zfg2prITpkxjRahyoGeh9icHWcoWkRUjiT+wB6ZfXjkv1I2bdhy\n5zWROCO67GN2PUCqbqqA4c0l+8op7v+wwi48usyGAQPAKsJPeQB9msvUO430\nOQa3NVe2yGBLn8qwle9I+YKSdVh/OM/xPKaFb7Mgyou2BWCdniuAE7O6a65O\nqdN580HY0gnOOuMA+DZJuvb9BBUlTqwth8LMcISKnotFGGQDtTuFfnKHlgj9\nLzCTu86ylfhUj+AKAgfVOCducUU7JwE9Ycxi37FD2iPRMH7+mncFPewdlhgn\nzK1lhHG8OqtpC2G/7jFcwZawsRYT4YmOF2z/EYILtQRGAHj6s//ExDIH1Yl3\n6aE2y7RsNxcHcL27tcm5vE/ZBN3BOI+JPeq5rUs00h5PkpDYu6achDPaBFcI\nXTYVWTtIWVXFzyg3XKMZ8OCj3/8UFKrdaKLncNKgiHbA9f53ZZVYT04m4fPy\nMfAW\r\n=c1iQ\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQD0VBdftju2tmFH8tQgqt0h+gni6lSRaVL5uSPUqn6o5wIhAM6rxY8KYuaCav3Mg1uqqWp5kMWORkLq2qUGZB2ZoG6F"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.a8e624c.0_1581639230750_0.07876892499502741"},"_hasShrinkwrap":false},"0.0.0-canary.2661049.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.2661049.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"0.0.0-canary.2661049.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.2661049.0","fusion-test-utils":"0.0.0-canary.2661049.0","fusion-tokens":"0.0.0-canary.2661049.0","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.2661049.0","fusion-tokens":"0.0.0-canary.2661049.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.2661049.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.2661049.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-236fhBVOJhff/GP02uNWJ+ARosGBTEbLccgVA8SJeXv4Um4Jn2wO9Tlt+foJXQmdyysiosumu3OCxTAxC1CzjQ==","shasum":"07a9e3de3c72a199b2c653a3a5ede40dcf290465","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.2661049.0.tgz","fileCount":40,"unpackedSize":182465,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeRfp0CRA9TVsSAnZWagAAZZAP+wXQSswDRl/eTUFui4Qu\nRd51TTHF8U42SVwOeNCyt5GE8fSR9dV5bpgpItvF9shsSh6cuobr9Vapzxjz\n2ucKsNFqC3ozsZVjI9ELb8lgELe26uO8me6O4LZBVFy/oiVULeltempYRXgY\nrpdE6CfTw9+GrkV47p2b2qMzT+/pZlsFyzvHKLWOCMJpgATXNIf2eFMvJqSM\nwNU25++/j/cvRyZTWl/vtOpA49qtN0RVVRwnd8eMI8W1GMeJGNHuDjRNZAQK\n3HC6slkwUvFZUZwkwUWGJnyfInqiFYtknUz3oDWX35m/CZq0jXnFGqTtHaE9\nR70aBnC8jae8pFT8gzN+IAuc2nYjcPL2nMccCHX44DvWv9Ae6tUc1GIYm/0h\nTBDDtVTJ0XULPBm358MChn0vHurVHLN6e+BnenUEYnJrtyJbM+B9xrP/dxhP\nG1KctfrfHWAre9ZLShEx/bAegQks09orAlV0EX9tsbB6rG7/SqGp8DHOh9db\nuZ4RgQXmrcGBIpvzXab0vvPXVHF+i9Op7RRDsKe0Guigfr5CVkj13S6/mVNV\n1XAw10AylqL3eGN8sxwNYiItAwgUD89AWmFDYirC7y6JHPEbK5dq4yrdTjCA\nrYkRiu3LaynGfIQX+cjFvv6rz3zMV4IOnjYfZPsQnK1S7BbpIVVgL6iadvVv\nZV66\r\n=0bUh\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIBRYt2Ze8vy4FbkdIW27jthgQmyBjtEcmayib/gvziD5AiEAxDNn9tN+2I9DQwMhH+WtQLNVnYhARDkaYTj4n4T0N/I="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.2661049.0_1581644403994_0.8020514850452978"},"_hasShrinkwrap":false},"0.0.0-canary.2661049.1":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.2661049.1","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"0.0.0-canary.2661049.1","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.2661049.1","fusion-test-utils":"0.0.0-canary.2661049.1","fusion-tokens":"0.0.0-canary.2661049.1","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.2661049.1","fusion-tokens":"0.0.0-canary.2661049.1"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.2661049.1.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.2661049.1","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-p5aFK3KfZ6iuI4kgFlTDWd8d/jRMS1JVxLvmhW3Y7Mi/An/EXto5vqGpNpaFTTyFOkRnmucGF2WQsOaJD9Bw4Q==","shasum":"1486d0ff9df915d57058c431cbcd9e45fcf56ff8","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.2661049.1.tgz","fileCount":40,"unpackedSize":182465,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeRfycCRA9TVsSAnZWagAAjdYP/i4n0oqVbk/NqOGzEGhX\nojnMMxv1GO0H48yCl6+Y6jsiOTlDRuMII1YhPxBdEmSWRN0TSxNjhuYnXUQO\nURMuS1IERI/LQmaLuy+G+0G1h7kNvTFN9RFA+majdhtyCGMWkbjkboEdw1Wi\nsQLjflIHJgXYfOl96sSlNqNNzLeJMwJU/3PxruD+ogL7PZHCn2mzeRBo2bwt\n/WrifN1kuwJDtuzevEfEvsVPCsXjZHePJ4ngacqTZCPXJCTZFdJ6SgFJMd2x\nITCj84FgjTYxtsevQ93zBpHhhYY0oxUnxJUj3qZlb5Tq2eSLVjA04h6F1TsG\nl3SIBt+iCkOJ/Ev/14uaePWZT9VuTKOQnknZooWfRt3hf1zx01q8MgzTJ5gA\nOw8nP47U5iReC4Bwb1vrWTCvJuBv2HqhiI+66hCjC6aWqlAOyZQAVuNDxPsx\n2mI+IwaOwS+DzvfW1FtBKyapaWIblKKBYx8yVkX/h2Zmdgh7flFT3HaQNJ1g\nF7YfODcESZgmbkjYf1c8u9aWXZqEcPrfy9kpm2+7OhDZXX3m9gbfwCoW1WoP\nIwU4yF43DWa8wjFf1Q5GP1tXHKV3VBEG2tBbs66zmQidIW7r+SRXaAOSl6v5\nav9/inrLDf7s2oEUuVJimXYmoqSPeWT/4Bb+43W8QxxJxZjfjPjpGjSjzDPL\n531P\r\n=758k\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIBANqzcW4jTwPZsloDKalcaJu3UmWM7eAZbHYVifCrtlAiEAshlV8TPPGNbkmfDMITKbvQ38BypII9WYuN/84+HUdZE="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.2661049.1_1581644956064_0.8269711497002132"},"_hasShrinkwrap":false},"0.0.0-canary.7eb4e1e.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.7eb4e1e.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"0.0.0-canary.7eb4e1e.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.7eb4e1e.0","fusion-test-utils":"0.0.0-canary.7eb4e1e.0","fusion-tokens":"0.0.0-canary.7eb4e1e.0","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.7eb4e1e.0","fusion-tokens":"0.0.0-canary.7eb4e1e.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.7eb4e1e.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.7eb4e1e.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-KhNFVfSFx+16YF2iT0YtegQWgoXzLL5K+y/XBGPBFEWrJZuwmDcFKTE2gzM8ALAX3PLx83F9EuDYWc0hkv3tzQ==","shasum":"02742b158ae052ad576baff92701d6aea11ec7d2","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.7eb4e1e.0.tgz","fileCount":40,"unpackedSize":182465,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeRwBRCRA9TVsSAnZWagAALG4P/2FAnRcdEtC/PWoxoAl3\nmyty4N8NRg20qFbdRyhgsvSD1ktPHX2kbmCTAdBVZ+/AXL4/Uwl0FvTcq/vg\ndVMJBoC2jgITc5aWNOlY1NNltw8XXPWBGGGDuibmle5sA60sqbrUCiomXhbQ\nNy9hJC7mhZh36Q9XDZCGosl+o2Tv1FZ1puK0LwDJzrX0+rCUht2/leujfq/i\nO39eWyPiaj8g3XcU0WPzncSK7QnfwugZ8chUr8kgmtbCjSZFpaqAnLbT9oDv\nBTgY8jKSZeDV1VHOI3e0x0cuMaG7MoXsRyWIlXqUonRmygdtDul/cwJFrEkc\nEDVO1oVLSoxfkhVvbabY9LpUSKu4noL7ee207s15IFHixqC4xI+7AwVRHYzy\nuwElIEFkdgF27jz/9i7Zr7BwRCAWgfvSm6dWNokrw7EhUKV9nUCp5kgB/TIl\n4fVjcxBJNJaZPeP23iDdPaBy5H/rGG9IqQaNLxM5zgx35sElNysWLOkMXQYB\nWFZMqd9InNGO38pW1dcoKoGh+AtFtTo9hwAtXO9KZlQI6IdjoFAe4ekC4YBo\nfVRq8iEI3tQoXCkqL4oJTjv4f5fO2S6e0dCCuJjIU7knKcpiWRurTbuMEIPe\niFsT4cVLSaH5NAj20eJWT5gFT95EkApeIZ1ws+zY9gsst+fbvtQ//SgDKwI7\njgQI\r\n=JWqu\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIGY9oSN48F9DJ8fiZhj5mqHsfGOWDxFX9R1Eg8h3s4ZyAiEA/bYyYkQep/9fMGAfjegRe4jlikNJbw7cTs1LUN9cwH8="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.7eb4e1e.0_1581711441083_0.2983365349410352"},"_hasShrinkwrap":false},"0.0.0-canary.5e59509.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.5e59509.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"0.0.0-canary.5e59509.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.5e59509.0","fusion-test-utils":"0.0.0-canary.5e59509.0","fusion-tokens":"0.0.0-canary.5e59509.0","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.5e59509.0","fusion-tokens":"0.0.0-canary.5e59509.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.5e59509.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.5e59509.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-ZSi6DHowP8SejYDkZhxXXvgHZX1KwMhKVO1MCbqdLTjRTLJ0kSXoe7zVLIHsQiqXhMt4tF6gHrQBDK6kprfaFw==","shasum":"6d842afe301b7a5cf919413e5d0b05bc4e820400","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.5e59509.0.tgz","fileCount":40,"unpackedSize":182465,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeTH3eCRA9TVsSAnZWagAAL+YP+QCftDiQaUYmsOMzc3dA\n50P4KdCYYDxOconPd4J5VzgBi4/utSQcdI3OW3u7Z0cxmuLpHrt3Q/lAe2Eu\nD1EqxtCr+WLk1Ene861oVBu+49UYcIgsrkduhRyZ37UG94MJ9mSWTcSNZhRW\nfJ+25sKqVLDlhiMKDdDelK7XUe/z9xTrl3qcZoDkCaWS4ATLpeB2uYCRkMsX\nFu8muWgNpbPgeCs/euyFEY8JwWlEx7Gz685C/ACor7+5WdKVqzkXERdVqhBk\nbH5YcNQlZTgZCScdKpUvIE62disON0QwQB+Q12no/U29PxN1TcskdabQF1k8\nmI0y7Ht/vmP2tJENJs7ewneteyvKAlH/mhMBcO6SkYm8jeUIbM+VH1kSNkbU\nrBXQPm+GdItZKMv2y72hO3uWgrxsizE7Mp/ZJtip07ZsCf0OaSyMvYZ84tdR\n3n1wcg/5jd/RWzTdtAxHOA0hiOnSOzit7SytTktiPAoGhE3byMEzq5kKkxoM\nuInNoY9ZMNAPB1EGKUj8gnll+6wGoWSEa6zsjAa6kKpTZonFIR2gwsq9Qjrp\n6XiJQmhcrrqyacJz86AHd/w6RpYeEJ+xv1W7U+QM2u9mOMKdGwLXV17wFyqk\nrx8BhCS3gue3eViidUBcWkThQwkQcHfGvEurKJvXubY75t7zqMiwxqbjGtAA\nkXTL\r\n=2DEK\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCHh6QPUm7MoDQlE0U4sUo/ItXrJ82dPVEcdt1nKjY1IgIhAJJI4qm1TliPxapOGELVS50Zl6Wag1Ax8WQ6czEI0Jj1"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.5e59509.0_1582071262293_0.1865044588853424"},"_hasShrinkwrap":false},"0.0.0-canary.062c690.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.062c690.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"0.0.0-canary.062c690.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.062c690.0","fusion-test-utils":"0.0.0-canary.062c690.0","fusion-tokens":"0.0.0-canary.062c690.0","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.062c690.0","fusion-tokens":"0.0.0-canary.062c690.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.062c690.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.062c690.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-ukz6a4fBTth5FbqfKCNBRmu+FljqPhZy1cINF4CeyqrMga4pkcErcaN4MI1DwgQkVWmXGpFp1BoXRpDFTxfFDA==","shasum":"9389c5c943e0ef9843d016a4f2a8dd0d888d33c1","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.062c690.0.tgz","fileCount":40,"unpackedSize":182465,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeTJMXCRA9TVsSAnZWagAARLAQAJmZFiJcjxxLYqtTAxKW\nTw1K5UZS2WE7HHQVlc+bbMIfJY2Etq8hbXN9gF93SIXYuO0FEzGrGsoqrdYI\nMR9368FnHRWoj7LqhCcjJ1VS5EspsZXy+Bhwz3wrc52NRlG+3LJGT1L2QA9B\noZApmAHL9fTJc77b3BYSUqLWHHaVJNJc3b/RF2pVF6JYMQ8qGNJDTFqQaGfK\nEBEZf5bt1VvVqQMMzbXDE1PB4aORzOXlNT9hxGDt5oQafeyLCmNMbuMLD+Zc\n7qfDRiHOhFer5AsZQ2t6oMee1FGDhT4Z+Ss4Qj8ACAR4rBqjjAbUUCcRamgu\nQD1qblOrqORoFqCujO74R0qyoF5QwgI8CpRZqFnQRES4rm8MrevTSLf0rV47\nLiKOK+Iq2jghM2ekh3MDKmKAaTNJxCIls09hjLF8iTnTB1NnTtijSb87/50J\ndVKfVf7wLlCRWSSzLlpAgnxsqGwIr17Dmle17zGDSL1F5OtSIbohN/paSWLs\nTmoVYL2ks4xMlQYYLPom67uoU7zIutk/AULNous6/y/Itma3Ey5W8VEeU856\nU6i5WtqMNVqlgmzPJ7PGdFWiwwF4NWTveDGIFYLNsT1medJsQVMlNUCKoLkT\nctMzC1cznQomexmguK2Dobm33bm25Isxhg8q9C9QUYpuKr14/Oa4nmW+YO9T\n0dKc\r\n=rRzU\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIC81EbkR0DRp8bNEVUcNIq0haNcBH/35p3In3WTMal3cAiEA8NjTwAIvGz0fgYIh+L7sWxljZwCtTqi1OdmG4RNmQSA="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.062c690.0_1582076694835_0.5886779580387778"},"_hasShrinkwrap":false},"0.0.0-canary.c9627c1.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.c9627c1.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"0.0.0-canary.c9627c1.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.c9627c1.0","fusion-test-utils":"0.0.0-canary.c9627c1.0","fusion-tokens":"0.0.0-canary.c9627c1.0","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.c9627c1.0","fusion-tokens":"0.0.0-canary.c9627c1.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.c9627c1.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.c9627c1.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-1EcRduCBVOj/OpzMlcuwi+84/HNUADc3pA9udBaLQkf8LRqleU8mNLxFdKIHmP1gTOSPDxnWYRI5it5ZVTGKHA==","shasum":"eceae119cd59906231c1362450ec1453b2425984","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.c9627c1.0.tgz","fileCount":40,"unpackedSize":182465,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeTJrOCRA9TVsSAnZWagAAGPcP/2M40ipgU0bkwEGGpkE3\npnQ4NPgcRjpmbEY5r03I8q23wZXyKu45Hjax1cQ65F21nm/J0r9mbAADqS0G\n00Cxydi7rPkgrQvibUFRapGqTQnHjshQOGJv7qeMr/2vdTYB3T2tXWcs4seA\nz3XdDP8iAgO7x4bUcwVguv5T7ONU5gV4hkxMIcQrL7NYrXhJMCQs0Lj1MOIR\nAxeEP61ONR6pt0SbzkFa+SNZacVvtG32HzFjtVKluPcV3bn43rc454X6/Jdc\n8a/9oDNhoIdgwPrOIpK/OLj2JZcYXxZ4ePix1azheNinL0oJmVXd+RhL9CCE\nhhJgT4tENIzgUlwgPQrMfmUBn0YeDVC6sSyI1eotQcvmeCXebxSY/7hQe29L\nhrf/OwSrFOkCfP6y+xYThX4Q6x4+W8yXYkEAB+G6lCYy2QtIRcfi9M/hiDVj\n70QhtGAAi1amzNSqyuEPhdqqvdsejMod1lRI5YwdwHN119kSDYIF8g/5gN0k\n/dHgirmuHi0oRJVtGKWAwRL1s60ycoQpgPmv8G2iSXc7CiDLHMVu7RmAA9hX\nTWrbZ7oVcjnG1I6CYOyaXp2kU99iS9ky3ULBu5Cr+yB23FlHlc3IvINXIzMb\n2EYUvLA5cVlI+vKkahW5C8k4AnMGLCBlDAl5jr54Bo7ueq8faN8fDoRsNfMw\nFp9W\r\n=s0zl\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIA875NnLna1nT5dPBu/CQYdipsnLazUMDZC6aITbDxC2AiBAjJfkzLGOAfC3pNDkWSsjKCz9deM9rOXtH0cgniNSFw=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.c9627c1.0_1582078669947_0.617319448080625"},"_hasShrinkwrap":false},"0.0.0-canary.48ddc5e.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.48ddc5e.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.0.0","babel-eslint":"^10.0.1","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.0.1","eslint-config-fusion":"0.0.0-canary.48ddc5e.0","eslint-plugin-cup":"^2.0.1","eslint-plugin-flowtype":"^3.11.1","eslint-plugin-import":"^2.18.0","eslint-plugin-jest":"^22.7.2","eslint-plugin-prettier":"^3.0.1","eslint-plugin-react":"^7.14.2","eslint-plugin-react-hooks":"^1.6.1","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.48ddc5e.0","fusion-test-utils":"0.0.0-canary.48ddc5e.0","fusion-tokens":"0.0.0-canary.48ddc5e.0","generic-session":"0.1.2","get-port":"^5.0.0","prettier":"^1.18.2","sinon":"^7.1.1","jest":"^24.9.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.48ddc5e.0","fusion-tokens":"0.0.0-canary.48ddc5e.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.48ddc5e.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.48ddc5e.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-p6j6wGr7D0taEAWZbEN4MN3xJAKWZJSfGRxiv91DKCioTTG4qK/ASOW+xdIY7ijUO3EBOw61fj//MAYjaHNBeA==","shasum":"d22c1739ffc995577cd57f77e5f3c2b2e8136c19","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.48ddc5e.0.tgz","fileCount":40,"unpackedSize":182083,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeTcXKCRA9TVsSAnZWagAAkygP/ROYCsW2Tu9tc/FsltFF\nyVBtxMv+NLl2Z3v5LWtCQUuuOOjTOUbRLm7+JR4LXixASAMGrgObeMJjTxz/\nWWmRjXSP5xGAjUX1EHQWq7jn3LNvYbwasQhS+zgTj4e1H8g+Frw9ZOeAzNEk\nje2n65hceT+n6BuDo8isjKSLFmVbvsjUiKspeMgeZGCAgMBdJhKibxB/6/R7\ntWfYqEV2mG7OfJQg+aM4IsZuNsL4bJ7ykCne1ldGguqKQ9UVxsp2odc4sCXr\npdNqw8ZVJCkJsEQaEaw07S2uXL67/6EzHlXct1cqKNUTv1FPhWWVpzekj6T7\nX66KSwL9AZ3AaYXuRmsoG5jgbCGppwEKYBXuDx9kLXfJ+i2tV9Zq5tp4pE4V\nzTwGrAYHMmUGSSWjHWhLmO6G0q+Z7V75HQ5/aVPw0tAz9tEEFFwZAYfolU00\nw5/RJNRQ6qL4dmpwflEuI3h/RqB4A6Wg8D1UHmnok3EG1vhl/YSTymkPY922\neOYaBYJaWiwuUmOq2Zp67OHs0FucfR4Y6E9jwlaaOSaFYOi+d+ruBv9LywBp\nlmxEznKKcT6WRQxHieywpzpQcA0CB5PE1bCXNT0B9xyY96ek+08Z/bbCColr\nFl+itvGalDMgDp+F3wp0blIhKZrIfPVt4xh5Zbq89Ja4hKvEfvcJSdlDSfP4\nnJ7s\r\n=puLN\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCkQNryfxm7MdD2/tkFNK8VigxUqUPKGQT+JdBD8gIgYQIhALJtVEHinKU6+gUks8AYOR7YpuKfl8w2cc5dgcldCcy5"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.48ddc5e.0_1582155210255_0.7126950398290715"},"_hasShrinkwrap":false},"0.0.0-canary.119a885.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.119a885.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"0.0.0-canary.119a885.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.119a885.0","fusion-test-utils":"0.0.0-canary.119a885.0","fusion-tokens":"0.0.0-canary.119a885.0","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.119a885.0","fusion-tokens":"0.0.0-canary.119a885.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.119a885.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.119a885.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-VAcFK5gAAAE2Edpf4GOlfspI/c5B8hJykhIqOSQ/jsIuKezpgGVQcpgNQHPWg45PhZ/oop8JGJnDUMOliK4jag==","shasum":"ac9eb7f8d0b42c327577f2d956eb7e64766ed131","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.119a885.0.tgz","fileCount":25,"unpackedSize":61660,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeTtguCRA9TVsSAnZWagAAvKIP/1djksw3yd5HGG3ftSY9\n0o6Sb6aq9weLV4p7oJeTIpErRP5rrgqQH9yC2TTV0FCl4LQAt/4+6E9hd1YW\n7SxxXkJOm35LOmIYGoTDzjqj+NxAJzUZhLV1qIDTtSY6D5A4f7vMic98EbZo\nT2JiA1csHfBVuBbUJ0zki6AmISiF+wpDcp/DiGsi8HEdVKNv6oqTdp0jHR/J\nWD9UJ9Y3ixY+Vr86eyn0A6rFS9OJKOqjdTDaYVPs7iHefulUAqxD4CD+4IAV\nRHRdCQDML+0mS8UStJYNiUmkE6AKhxy5e2m6TdCuu6XcYk08J/+190dpz9/H\nWKsZO3vlsIV5EeG9MqQfpZaVW4d1eC5iXV6oM1/+7OKl21B+GpFlK9q6kd42\nuJTGLRYANWHXUb535+jf0UWaYWHZ+f7Gp5F5tkH/CAES2UPcl1uyN2ehY2uh\nCz60YeGsnq7EcoIZ+b/zg8IJVpBlLNmIRKMOQ/Tb4wjL0LpxSAj8wWykXlhk\nz0zUtVwRHgKV+oWKjl2ct7LsjKfAywXpHbGUSGFz+Ov0kfXyPvYXBY+MjQH4\nbhu+Iw0AT7TbiK6diULoH3AZfrkTx9K4k9mQwRGkO6Fx9j1fvuBU57SYG5J6\nJyyy9C9vQH4Mi92vQZ+dGPc83cz16Aujx2F42d8PfKzOFZO7aBZdapw7UbX3\nrd+d\r\n=Ha/S\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIHAhQpO2JB9JRjgLe7lwXETkgIinFA46vOAAbOSseI/EAiAio06ywz2rA9BEggVQ0GIqMcLac79gRq4QLI89Uf1moQ=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.119a885.0_1582225454107_0.36440018201650926"},"_hasShrinkwrap":false},"0.0.0-canary.9908539.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.9908539.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"0.0.0-canary.9908539.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.9908539.0","fusion-test-utils":"0.0.0-canary.9908539.0","fusion-tokens":"0.0.0-canary.9908539.0","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.9908539.0","fusion-tokens":"0.0.0-canary.9908539.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.9908539.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.9908539.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-L3GBJFVL1cGi1gr22UcE4f4Bqc7T/u2i7yswQ0g+3ryfGH82AVQE5LPUxMYhG59uudsD0AV1tI4YxlLIOMtxGg==","shasum":"3ca117afc53150a33590aebd1cd6f676a780b06b","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.9908539.0.tgz","fileCount":25,"unpackedSize":61660,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeTw9vCRA9TVsSAnZWagAAzOAP/RyUyfxSt205rff5MDLc\n6cK4i2OK8i4Ibc6w8twFgHdHDfk1Bm/XFo51AnMhMbu7LD3oNLFa0POXi0OV\nKk0+w7TGM1+O7R6ignaQLzjx3YtEWTr1g0FD0tu03fH+X+STLpcvToedBL7r\n/WfpX1J5pQEqnKPXP0lSIEXDE2iH2Umy6xXAUCrzoPWy+R9wAYN3PRw38t1a\ntPVk+0PSpmAbvZ4kqww6fDHQxVtWLP2e1THbFWNAJPF62RoROqQC4aqpNXNJ\nsNTFcP00kRJTfFcroAn0gNl3KNarzxHSlpJ2h2PXEKSsSVVHLueiEq29SuFN\nmtR8Jg0Ga2Zn20tD1YwzK3+9hOtk1xVKN5t86DHuHgwZMviYQRN4cIwpAC6f\npYAegnZ/p+0rzgEuMKfdZ1k9nuzDvdjp8mI4CMTsFgCi+U5ODNkwJSElx+/3\nqwT+gZZkUidvGC0U7SUgpdof6OuWRSb7eFqt8fQSx8qw47Xtv2hhRV/Bdxy0\nBe3j/aeJAqOcIk95VSPfM+/vXkM8k5scAgatRxtom5kt1QYsFhvpqib6xFwR\nZvM/I3U/3PT0Mop6DALI2m79AywPEJam+U/Gb1Qz5E7NFotSAlaj9tY8yYkb\nVCCiZF4DT0L1IMR+hEh6Os5wPRqYsVYh9Xs8vVuoygl+KRfNkzVknUyzzvLz\naBm1\r\n=zjr0\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIFFrNkh8VS9eiQt0ynunJP+1+UWTFbAIg636hCU/+Z98AiASJiVuQxqm+m0H70x6Uni/o6iixpeXME5hLtfXp3hkhQ=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.9908539.0_1582239599498_0.9284842304858267"},"_hasShrinkwrap":false},"0.0.0-canary.5386f4d.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.5386f4d.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"0.0.0-canary.5386f4d.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.5386f4d.0","fusion-test-utils":"0.0.0-canary.5386f4d.0","fusion-tokens":"0.0.0-canary.5386f4d.0","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.5386f4d.0","fusion-tokens":"0.0.0-canary.5386f4d.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.5386f4d.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.5386f4d.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-laUv2DaVbagRrriH1+qvz5Yg1l8KcZK6ngneeLODH+jAjb5jyNocJdiT4eHFtRQRnUTjZSbRM2jX9UkQ8vn5eg==","shasum":"c736ae68f54e7929a123f8636ca33be859af57e1","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.5386f4d.0.tgz","fileCount":25,"unpackedSize":61660,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeU/lOCRA9TVsSAnZWagAAgVgP/2o7XMd09GK6CC8RyJHO\n9wN8QFymeQR1qqiYM9tndx2fdpdsQqH1A0K/cnVe8C2a57XXWuOs5+N/ebnh\nRsreaM+C0jrfw7SiHfHbCSfllbNOedeZnCDROMrlRJMkUgbQtxyxD1iWaS9m\nfYvU0nEjNvlKNegSrkxONLa4gOvH6gvbeqko/vTP8HuryX0BwaXNT+LUHn9d\nFxgEkqCeqJgHS7/QDVGSD4HUrXeOt35g3mac5AvWb1sAsvi7AYvlLvIDIaW6\newHWgiIzXgKuzE2IKL5NIfEaHmNJYXgARHJIOFztAvisJS7We4mTKp6sF7dT\nP91Xopi7X/Y7NB7WbjrflSmzl1hfDkW+LLYt7HclGYOluh+N8quSq/OLDe3j\nhFLS5o+k65UjgENkc+mYow3BDPxYwSmdSTX+N6JvlGMwx/uLv+3nWNuk55HH\nsFAGeGXhVi65ZJJem29zQTEefLhoxG9gP2ol0STk1msRpzky4ZretRP9eJ9c\n205Gw6OYGbZUmOjoHQVhva5PTAXIu3V7OFVv9faWcg8jgxv+YUYLIYQO1o6X\ntqk4nvrr/seI4qhW+qnGil2bQ38BKp8KIf8ZQs8DC7E017eb4CVn1swXqv7Q\n4iV8lton3vCdsD7KZuMHpG7Q0y83vdFedrODkxuLUywZMkne9VakyvKufElx\nAaiK\r\n=aKvP\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDlpcyfGk/udpeazNBuFpwt7jZI32ALZecFmCfomCDVhgIgAp64XQ/WlyyVrPHBwu54/VtdKM8mh11pwFP9Nhf6uqI="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.5386f4d.0_1582561614431_0.3035431203267518"},"_hasShrinkwrap":false},"3.1.1":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"3.1.1","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"2.2.0","fusion-test-utils":"2.1.1","fusion-tokens":"2.1.1","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"2.2.0","fusion-tokens":"2.1.1"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-3.1.1.tgz","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@3.1.1","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-KeHbDK3hL+eijj3rkEingO+LTJrYuz+BJ5JKTeYix5Jk86F6tfBr5JduCwfzI9lpgEK+VfogzAOLxtlWJ0sOcA==","shasum":"d3960238e3a697fe7acbacf855ce336ad72a4aa4","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-3.1.1.tgz","fileCount":25,"unpackedSize":61541,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeVXBECRA9TVsSAnZWagAAo0cQAJGCUfkOepC4PVMUcJ1F\n8QoLJJ3tCv5+BXjZLJ1SiO5XwWfQB/CxNXoXLKpe58H7M632eYmIKTwecXV+\n9usnm+D3EkmidwqQKxUu/gk124B5RdPN0UTumj2Dh8AWj8uIT1AbjsubFzSX\nsSOKjELOkW/JfflSVYht8/6dTiH7GDF65UK1GsNYG/gX4Iyt3WlKu9x661z9\nsAmAaZ4/blDAKJaT4rSwW7sJih5rHlRJohUkq2IK0FUBHw98u5Y1zi9fhI5R\n/LoXnSnVvV4bvmhDSWqNX98SKi45FyEnJ/m0IXMe5++3DXyrfI9q4KNKS8Re\njYn5l62eIlzKJEWP944BvfoDHyrqMyT+uchr58XtVdETNlchVoxHNXdORskJ\nRXKMxl+/du96zdV5QyMXXvHlI/hapUNv5D7yZ7vYvlr/KixSqVDMgcIPg8j5\ndShpFNO1M3EZID+0bKKCHcDQEVwyrMyFY4eRvrwTfMU8Pzx46ndwtZGIPMuW\nIyuLUmE9imd3Idqm1qOX63U5nEVdv0w4LGpwQ+w10R3C+trhVwMafGtY38sr\nuvHUY9ckJIMe74t7KnYNhUBVMwHVbRcJSdANumP+RWKQJXtctyO8H3Gc7ZD6\n4JS+tjvifVQ2MKcExbhDv7tbg13ujqEsDZyy+e1+k/DE8Nzw4Q40xElGwz9H\n7Xa5\r\n=EPZs\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCICD/lFoUmN2fOYXjDtJh0zbEa9TUw12blMGLfI2NfE9IAiBPGiwJhwyPV4szu9z9c0cJp77hHygfRlIU9OE03ZDjcw=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_3.1.1_1582657603895_0.6979507206210382"},"_hasShrinkwrap":false},"0.0.0-canary.74cf916.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.74cf916.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.74cf916.0","fusion-test-utils":"0.0.0-canary.74cf916.0","fusion-tokens":"0.0.0-canary.74cf916.0","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.74cf916.0","fusion-tokens":"0.0.0-canary.74cf916.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.74cf916.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.74cf916.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-VGg3zIryvLvTdY/76Hn+z9vL2dxBlfrvoTz+jBYY5qxw1UzYv7G+1LDA80tZe8jwREII3NeBNCEtJBKH4eIJcQ==","shasum":"7049b3d0a13537cea692320a2d3ad98474935f9f","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.74cf916.0.tgz","fileCount":25,"unpackedSize":61643,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJej4bDCRA9TVsSAnZWagAAcBUP/iZKg1liw139SW3cOKCu\n/jcOpODxeFEFMyO786g/Z5UibsMJbbNFi92n26OM28JmmDhPijiMfWd3qkfr\nGt7yoEKWW2jP+3l3oRTAzcC9qZt7XguVa4eaFnWUS9QBBaA3wcDXLz3iO53i\nB7yCD/q7rk26X4CI7ZgEE33Tb8Fvasc2VurTSZSgcBRoVQ3ye5jE/+vb8xQL\nG/HoyHiY1ohL23bZwp/MmUIxBoXcNcgzdF4hEqS3MPCOELya4/s7psPaT/qs\npvzU4WCV4lFSWKSEmd2RAH11BcXJ1eY9Td1Nnwq2goA20YQV7Gacr/s2rDRM\n/l6tEuGWL+8PYuVUBvfhCO8c2eI30DePvLtDvXoYixEjl94Ov8DALhobv8ch\nCYdPYrdDRghxBGJazkpWWyfAk46dCybOJK+j9MfQ37qE+sA6YvLU5plO32eD\nISoEHMcfzcVAnb5E0daZ8j0CJ0MjtdYDyBeAJJLKnqGeDtkAAEBu8UL4vRdj\nn0VNLAQNixNbwvpDLT5tcEpBNV5RwfTi/GWi6pMdYObnOz9TNfew3HRb1a93\nXnAa0CRROxfeIyK1CjtqGdF6jRSNSylvujFkwu2tWqtob/JKdvhhYJ6ohSTh\n4lD07xKJpIWvq7UjKd1XqJnLQD+fxM3bK/34MGf60z9K7lFLcmLlXzMFFPUT\nL/eQ\r\n=E6Bt\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCICQOb1qXim6c/pcShIPdokfF5Zxkxjo3ed1k74LRCDz5AiEArEtdlLOhasmiPSrBmpXoAwCk/TMW17k1scSnnP5pgO0="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.74cf916.0_1586464450496_0.8873724646552066"},"_hasShrinkwrap":false},"0.0.0-canary.5a76e33.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.5a76e33.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.5a76e33.0","fusion-test-utils":"0.0.0-canary.5a76e33.0","fusion-tokens":"0.0.0-canary.5a76e33.0","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.5a76e33.0","fusion-tokens":"0.0.0-canary.5a76e33.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.5a76e33.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.5a76e33.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-EshFYb75Ua/4T/QG9e8g5Y9ddiERtoHyAC1xE+R2vwXMsPTXAvlahYnAsuCm7QhmvtGUhPE18/heY2AP0lz4ZA==","shasum":"0001565c59c66d932a02c226f3752b1454fc1910","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.5a76e33.0.tgz","fileCount":25,"unpackedSize":61643,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJelRAFCRA9TVsSAnZWagAAEHoP/2WALzKhArbQo8QMyWWS\ny5E8JqjWG/6rkBZz2jViT5Kasy+R0U51nrDBmwz0Jdl1JUkLOxsYePR2zGzb\nKrtSPVChU2qHZt2p8nJA4PbM8AI8iAyCMKMVkz//U9FHxHWyBpar22L2GjLM\nqd6LGjudz3J5eXIwh0BI0LEUDo1Kf/LzAVmo1/7SQuiiWA1w5UKsTVrYU0E1\nmc/hLYqGXIPADiDqYciQiqsndZ15bVJVNyqN+oVd+sWEQjkBcCpdMon6D8mF\njuASSfOirhwjYKW2LGhR8oKaavyYbjHTRVm30+TwO4SP7Lili8mdZuFLLyrm\nklznXzo+tJ2xXz5X7XEZuZCWfvMQ2+rAYvtYBru8yYq6eTAXNTzmH+prjsHm\n21eavifxAmvm1ql31FVvvXGMusZhPLhL124DkTHW6BwrNDiFJbWlkGrrDezS\nJSBToPSpc6M5wUDVnz7Uo0CQX3Y1xDXukPJRVHNuUKTjiBBJo8gWMU7FXQJF\n7UJkcx/mmcXynS/TjjzY36gLieR6WuzjV2+tCZl5axCeZE8Q1pA0eMLTwFPc\nTvrpnKlD2Z5uHN36FvEKFT5H/Jw/KLq0XTVmsJqYIfmrEMfEYulsVT+sm/7Q\nt/XJTRnmohVKbESRsUMzBRd1a3hPzXQjko8YtfN5WD2vHotEoLB6R34bew8Y\nhhbs\r\n=KwRN\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIFK7hHDUq3TtX335mQ1hifMu80s/kk4RAe7wI4hXwB9WAiBR7JKO9FUbHDz+/Xr+N/fkGc46vK/KvkCHojkqXfJPDw=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.5a76e33.0_1586827268618_0.8528397398835375"},"_hasShrinkwrap":false},"0.0.0-canary.8de64d7.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.8de64d7.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.8de64d7.0","fusion-test-utils":"0.0.0-canary.8de64d7.0","fusion-tokens":"0.0.0-canary.8de64d7.0","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.8de64d7.0","fusion-tokens":"0.0.0-canary.8de64d7.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.8de64d7.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.8de64d7.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-a+L5PhrdfaACv5+5OMCej7FDLJTmpJDZLydrwBziWTCZHMR43PZS3vMUx5YGl1u6Tmrki6tI5x1QZsOju2u7og==","shasum":"12f6a45abaac471f136c3c32628438d0fb7fbdd7","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.8de64d7.0.tgz","fileCount":25,"unpackedSize":61643,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJelhTXCRA9TVsSAnZWagAAlZ8P/j3xvw8Bl0JtDAchGJxJ\nCbgCIVG86dFgq7Vmw6GuJTyal6XGxtw6GLBFqq4gJW7styFtuOnknH/GKHmm\ngEjqBTzqrwWxwPa5q4+aH5ISD4Vx5Y6C8aQSPfkiS0HTXVxX9vctrTrqLfJA\nGYQj9rlfHgKj/qQiLJMkIEr4CHyak2ZoIAAwbtoyxQ9J8CQh+P7xoKOPsMYm\nmFAxeH9fdoBMvsofoZ5sNE00yzSKw/reWqLErZqGgeYHSVvBrHL3WHPNq/6C\nxlJhKI9qKzuCHpFjuCUB2Q2fv1lwBqiysVoB4PgaiY/vlNSqqRMCR4IYIpTK\nDIyjO+ls74tEFM1SVesgzDvTSFBzSltvU9bSUz4XzaSLF9abBV2mdYgiUHW/\n2TiRKBCf0CITWl8kKlGpj3MwZwkwyPAYgzuStdIrKqApNCzWc0wE8tDSQ2by\nkPpSgK05OaCog2qT3Idd+ZOCwrSA3aVG7JhEiKdk1eqYHrPbyNCctCnhpk76\ngdvPlzwpNygUT4DGCKrt7ieljsomWB5HBS8R3YF8JH6O0TTuLcwt3IblWUaj\nezMSY8rFcylNNm1yJhS8yDalvOkmvAWcjcow2btL2s/jr9hlT0j/mAJWyypH\nFjutgRfWToz3SUr7pEGW12OxX5xQByo62owRLx/OcmRHXQn0ugnfGwv9uZ4i\ngO5n\r\n=ZKTK\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDY10BEg3CZ/HBHxXd3fmYN302sju/bVTYAt2pTu8vl1QIhAOkIPITEcQY9fuyUtumDElmzh0nJSkFsCg58uY9+yzNg"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.8de64d7.0_1586894039157_0.12313516137741032"},"_hasShrinkwrap":false},"0.0.0-canary.d9ad58b.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.d9ad58b.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.d9ad58b.0","fusion-test-utils":"0.0.0-canary.d9ad58b.0","fusion-tokens":"0.0.0-canary.d9ad58b.0","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.d9ad58b.0","fusion-tokens":"0.0.0-canary.d9ad58b.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.d9ad58b.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.d9ad58b.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-FnMdlO8XNXpdkorC/ccc3vrp86WNK+1pI38oX9J/wpyFYsRcBz3cWoVuRCf+4XAMoX3LyKEBlOz1p8jNLI6rlQ==","shasum":"b7d89876bfc548edc86ebca7ccdcd3ebff369fc1","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.d9ad58b.0.tgz","fileCount":25,"unpackedSize":61643,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJelqunCRA9TVsSAnZWagAA5ngP/jtNuIXNEfxUhcv0GMmk\nRxLUcNjeKd5rP8EzdF55afGuIc9Cm75nC+vEPc84b/3fCt/g8OZ6jAMenEjA\nBkL8ANjJrt2Qyw1C07wEPx44Y3RSX/la9Txw+yi6J0NMHwK3DmbUN76BQosD\nqRKZd0FE2U7y9V0uOSx/dTUALVLudZdZgQ+uK987EMm6SmlRrSjLoZJQbPOX\nEmh64E9pQqbA4XqUlvSOMUVsO+96a8gUbuIqRSh2H/rYCcmHZTl27mUiyw9E\nGajZRbRl37+y5LjUJk48YbQ69LwhPLxC2uAYqAJQD702qG7fEXWRAqtwxBQI\n9uZ9zQqufqM8jwb9HrIFPq/+Q6weasgQW3e5hjWDxnRQLgvva55lpafAqRy9\nl4iQGr0jGN8APidLZlrRa8fJIwA598nYWa4I0iDIeOTLILot9PLFkMIthkpM\n/Nv5hLgFkEjDlD/o+22ODhdHrLUUvVmLSNxmOsK8dYeJc90mLEW0U42kXgbp\nANSgi8wWqp4IXM8/BPzXT0XsN9xY/9gM6htH/wPXFdCzTC48Kacj4awcChdJ\nNNIi6RCLNv+2+aqBbnuPUfryRR7E1vGJw1oNr32Xk/g2kn3gOg7c0CO94KCo\nQtqhhImJn3XdRwYWoYC6OGh5YCmQR1phCsAH8cDDXe+N6qyCYFlPCvaP85Ch\nb4wY\r\n=ZY9C\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCo66eAS3RLZ+gD/X871j39koWe37sgR8xO4BJuWXbnKAIhALkvj7DioQihfvQdD71N4Kzf8GehJJfR8pdFwJJdmsJC"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.d9ad58b.0_1586932647420_0.1573721387383391"},"_hasShrinkwrap":false},"0.0.0-canary.9049f58.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.9049f58.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.9049f58.0","fusion-test-utils":"0.0.0-canary.9049f58.0","fusion-tokens":"0.0.0-canary.9049f58.0","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.9049f58.0","fusion-tokens":"0.0.0-canary.9049f58.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.9049f58.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.9049f58.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-O/tqcZMJnY8TVlG+dqYKCRMfH9ceZ8Yr/J+fvETiB7bwBi9wpLL1859bgfXN/pRX0s8eDGGhH1qPsVouwrNFjA==","shasum":"0bd2348e268e7ed7e81a8e98995d0d8db6dbefc4","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.9049f58.0.tgz","fileCount":25,"unpackedSize":61643,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJel9zTCRA9TVsSAnZWagAAfeoP/iMZPY8sMQBNcXP1lnug\nqaQMcRBEKqZf0XrI+r/VxGs7T+NgfGColxJMVvQIbLfTdV1cOjL6xaKyI/Gd\n7lQnG+qwKt3+VK0aF3t131UUAkhH+QndtYiEHSJtKJ3/oE/CHzpMw7AvMHrZ\nf3u6g7iqyquXI9NYaQmuISUrcmJ5NkEahOhUfFmsAfsK+RcOpRbJn4xsM7M+\nLUmty+pE9S2OA1J4GtKzo03/Gdhg+esWJJZk12kpo/K6bdoIMTXENUqMM4+X\nLnY8JSf9s0JXrXVsp3OZNuUkETP3N4Mns4g37+PVDTuCIw0Pnp/cAknX7GMf\nvhY8l88LhR30tv+i7KPX2sgKB1jhyobqn2o5AppiIVgUghr+Et1T1QKXB3Xu\nPWPyhu3JDRZev/NqpFkuE4u6LeP5zVAWKO3m0qdNazVQQfkMHLHjkacekOsr\nVIJu6XWDp+AONgmyy+UsNCmLgA13mhgRe4xSYAmj1N2upARI5ETgGIq+/mWA\nStP47lFpU5mPrBRjL8xpsxquNOPJQpge7lwKR0umhTIZExWPcivehtZIjBtO\nwekDXvNweeivrYlTSe686cvuuGDGFjMcJgqcaPDETEFJayhPwvP8RRCCijtF\nPu52fJ7bRWARj8eDQExEPNr+WpT9Ejnk8YTcbLbOfW+ZNugfueFlgTXbzgRh\n8zrC\r\n=1ltw\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDDL/rcv4L9lIdUWCm0clkLspDUREdxUhLbJJeTHacQEwIhALlsS2Wf3KQa/F29LZSiXp2pROdkaAcwIqWGQuTYzBN5"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.9049f58.0_1587010771476_0.6114205044431014"},"_hasShrinkwrap":false},"0.0.0-canary.1f389e4.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.1f389e4.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.1f389e4.0","fusion-test-utils":"0.0.0-canary.1f389e4.0","fusion-tokens":"0.0.0-canary.1f389e4.0","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.1f389e4.0","fusion-tokens":"0.0.0-canary.1f389e4.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.1f389e4.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.1f389e4.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-JDsuQDIU2zgIpumpKYGp7F9k9FFigJ83X+9I+2239aqxQOKovHDHE1RPoSB0c395Nx04DE2eO70yzBQZvjACIA==","shasum":"8628ef4b31fa2c61439ef8a24aa8dfb2f30af93a","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.1f389e4.0.tgz","fileCount":25,"unpackedSize":61643,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJemJinCRA9TVsSAnZWagAAgDUP/AgMXqyPrgiG2gm/jDzi\nADRk7V3FtKKHtreLxG96dfpL3doEw1h6DpGVLqoPSFH8l9izxWhAKwffBRBb\n8lJZ61wpJGeGGWBsKDKB2Lm12On+5EZq6GwftA4yA2beqKFSSvy1ho2qKcyP\n0zCbqEZ8Z5hXVdyzuWD53e8IXvN2fQOujwe/SBX04rdnsUwrEB/LrcruVK4t\nOGEFA06vlH+uRwtmJIjNcDDTqnJQLQzrHNgl6Hn+YPkRwqNKd6qMbc6xzAFA\na8F5IQV0eEeLtG/is//7n0uAOXx23doUe9yl1lLF0wxh1JxpCswz4T8m337n\nGQqtw66jp+sM2TanE5vZGaKnl50XiMKyr6VO6ggd/W0DbUrRtQ8+Quf9a5Av\nBdMsh5iE/mfORf0AT/vLKEpBohmEMHyOIqactkChAuZ8GuUkPf37GRMCFIxX\n4jWTHEYKbtbsA5PNaWxFysGWshN1XzUBhAleqYNaO7UWr+foEKrrB6wzuvMw\nxNG9iYLHzWDOvIAzpNpUOSN4LPkcdP+Bvf3HboyvseFb+dAiLzNqm1T2Bzbz\nAjrTqK2pbRRFiorYAMQcOl8gHcaPYoqHTzFaaYm/LkOiGMXiABRVyf0AY7i4\nPgz3vGAW9gpqZKI1z3eiAxa3tq/9ISpTPHq8vhafERoa7DKwPHfsQxB369Jw\nVWhq\r\n=vqWx\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQD4/r1yEFVuCS1lfLh/IRdZu/bB2BYLd4e/7BtTlrqYNAIhALg6tcNZMg92rAoJwuDaYXFLXRag40sYeW0NFs5mj8j5"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.1f389e4.0_1587058854996_0.3188080919709686"},"_hasShrinkwrap":false},"0.0.0-canary.952803d.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.952803d.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.952803d.0","fusion-test-utils":"0.0.0-canary.952803d.0","fusion-tokens":"0.0.0-canary.952803d.0","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.952803d.0","fusion-tokens":"0.0.0-canary.952803d.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.952803d.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.952803d.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-2BQHMi9zCFKkZ0EfehhElAWVylOSlEzVD5L8ax/lkckJ6jKLc65B8YbCA7VFapHgZjNG8TVpFNexRO6HFhvwnA==","shasum":"52ed309d862c9000959f7adf20f786abbd835b3d","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.952803d.0.tgz","fileCount":25,"unpackedSize":61643,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJemK1wCRA9TVsSAnZWagAAFU4P/32ee7tQZ+Os9E5TOLIB\nBwMqYHrMVpeEV9BFwAp97gkKECR9tvnBpn4JXdMCwHUxg+JRk9r/kGQ5cC9b\nUEy7DtZLNfiUntamK/aYOteKhMwoktPQ59mGuVZLzX6xuluKmqSFbXo+Jkqw\nwXZ0T0PRcNgPe1HnbqECPiSheiRyQ6IN6Ak+n+6t8l+kf6hv2fMfP2tDfZCO\ngbsghrun/nYk2G8QBCyymSI/4LYF4bWPzAqtslBcvNzLArgwIs8+kuM1xjry\nHPTMDHYudTxsG9+oaMf5aXttsS5Id8GF7HaDY8/GGgZRcB9AzluDKFwaStZK\nGfNo36GFvIyq0Yz4IAgkAT725WT4oUanwGqfsGNcsgvLGCkmH+9vbPMvP8Wx\nFdGzIVCxm6uBjhREqKjG1hh3EI+fRsUwsLAcc0uModm5yeGDxb7YYJz4H4/f\nferkXY4LunH+ICpHcWK+k25ydnHCuFigL+V3w7/pugjCiNGrQaKGcGK1WiC0\ngLpaleJPmEyy9xl+OF8DiFQjFmGhL0IKALaSMBFhtZMuhSNX4sW9RQF6apka\n7HJXe0WcSt8KzCiYrzKP/WdqO3gClH76ulmn4ugpm9tFfS1l7pcbWBodkhJz\nyXNwyQ2/s8CmFshOMrpUtpoD07dNWpuvwoxdWsWGEGUaO4Og5QLpK6Uo5cno\n2N4t\r\n=lZLl\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCcuZWFJHqX04d/tG3fZOURcR88fxpcFd0as1tAGCxR1wIhAI4jtlhx3GnXSYDw62BorDd//DGj3TdVPyVkZMyUDCzd"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.952803d.0_1587064176375_0.24568373231740348"},"_hasShrinkwrap":false},"0.0.0-canary.0813b9b.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.0813b9b.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.0813b9b.0","fusion-test-utils":"0.0.0-canary.0813b9b.0","fusion-tokens":"0.0.0-canary.0813b9b.0","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.0813b9b.0","fusion-tokens":"0.0.0-canary.0813b9b.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.0813b9b.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.0813b9b.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-hDc4y0Ku9yh4FeoYu+DCRjK7XIPz+2G0eubRfXDu3RTdOm1l5R5kYuPqKfCqFkutIZf17Axh6+OJsjmPScjq1Q==","shasum":"bbef6066163a9818542b2500e2e3a167b6d3b13d","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.0813b9b.0.tgz","fileCount":25,"unpackedSize":61643,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJemkYsCRA9TVsSAnZWagAADVcQAJ/BMTg0AsyPAOOuOfPG\nkx2r14wtwj/EUlWVRFum92WGBiy+IHQ/Uzo0Xhy5lpu/JFwmGur6qMASBjIV\nny0+hwnOZdXaNqSiSP1MugaPMtRDL0D29+VCRM+oW+q7CLklAlxOR+H1K8PY\n9nL153nmDuWBQjLpGAax8iRVUeW+YZWfvViZh4T1/R6E5Cth4598CwRoHN7N\nmmUfWEL/eklvet55auShe6xyoK47kiFEha+WFuyu8ov+0SIxLxGm6GtrR6Cm\nHCek+oirRbO+Y4vxH7WfquSq05o9a2iH6hKh2tjN3O0Y21Ho8+cvfIS/7F9x\n3nhzKK8Va+QfvxICQy4sGyS+fi52iMy64mgpt5Y/ccdvpoomULMLFAIO2Okc\nVF9UvYJpjz1eMAT+nt8LfXuQe3FTLidR/VXaJEO7IpJ1xzt3Glqpmdgu4qui\nzHruWX1kN0d/y2tYXJ6Q8oD79axkDI5bRnJl7a6+XxDZ0XumfpzlJGkzVhQU\nOcwbw3rT7TG5136mVy60i7GNDkeH/KkKJ5NNE+ytXleTRPhgv9F4eV6omGFG\nO3q4mwiDtkU+y2mbuP6hAp4Jub7YYWA3KaXDSUjQqrEMezaesaZmL/MvFcvz\n8K7zbxkhJF1ZSjqaxfHhSTi0WjbdjCimOBrZC816AdSpGKkWMSXq+g41AICZ\n4f9Y\r\n=gAYB\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDBJW3R+30RNU2mNXERzbKgkdWCj718aQBAAhUDMs3n/wIgBLSoz3iD7KLSPwzeMsGOpZu5379fncPtSTow6fjlPLg="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.0813b9b.0_1587168812245_0.21176599383565753"},"_hasShrinkwrap":false},"0.0.0-canary.0cd5338.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.0cd5338.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.0cd5338.0","fusion-test-utils":"0.0.0-canary.0cd5338.0","fusion-tokens":"0.0.0-canary.0cd5338.0","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.0cd5338.0","fusion-tokens":"0.0.0-canary.0cd5338.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.0cd5338.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.0cd5338.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-jSHM0vBxM9bdEQ31pi/BH34WyL73s2n6fc+IPrGTGD0vw+jjhmYYvk3slls/rMhPef3VbuThP0sCz5gMeALRpQ==","shasum":"0351b5f139210ba6381c116ee6cc860515ee6e19","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.0cd5338.0.tgz","fileCount":25,"unpackedSize":61643,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJenhkaCRA9TVsSAnZWagAA69AP/0UMbLNaMu5Ui174Sbyv\nqvNqkNUsfwICbr//dK8H6PCkieTP4ZPCODhuWFTDYeKIxkgFI3+LZTpBWe7K\ncI138/Rin0p50DIduU1jJF2eL9AXVHWJRWxuZN9GbblmKjd3IhzBQHao5g11\nnFPDIpg29l34WVblOhH/4wv2LKznL5X2nEEiiLmnzKmbU6UzNUFmXrd2XOEM\nd/DPVtVAVQucykOcjD9UqhdzNrvwy5UkJ6G1FgB4Pac6M0rEGYRlu1Gg2Ax2\ngeFtlpMj1lQHgTxJO95U6pW3wTEVDXPn1NbqkoqOPtkp+DzaY6dvaw84E83+\nNfE+6XuHcSCnG9Cyjek/A0b+57TFcpFinilThs1KhXlfvZZK7o2Qp7epPK+k\n37VIy0MPdtDm7zwTgNc43L/5uj9v+bixaU6Kb/qhyXgCMZnapKD7AueYXwbW\n6QbznUQbzRFYcHeAHs8CeiuoN7Q9UrMWVXi9RX1IGbxE3/WPWcEnNtRxFby6\n3KPC8Yfu28OmLaFGAnDS5dGrM67Lu/CAjwanY38PpLOLqq22SO2oyjtU2YDF\nk4q6f3W0ogxgiTPNRmEIvIRXOrPeBQ7wReNNgCIvzDEEeUIDWcW7Q2b15au5\nZr/L+n9rXKVqI0Vdvxz0H3sE0wJWVeal5gzAjo5wFStz3vgPhsNn2HOuAek1\nXZF8\r\n=IDIQ\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCCZuQLV2Z6e6D0EZuRzvOQBpALN8IZTdb81CkzzPNV2gIhAJHTNizXK0/PYQYZI/CfNspfxP3Agd2I5n+pbKUauJwk"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.0cd5338.0_1587419418336_0.6489773911660663"},"_hasShrinkwrap":false},"0.0.0-canary.e8742f5.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.e8742f5.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.e8742f5.0","fusion-test-utils":"0.0.0-canary.e8742f5.0","fusion-tokens":"0.0.0-canary.e8742f5.0","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.e8742f5.0","fusion-tokens":"0.0.0-canary.e8742f5.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.e8742f5.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.e8742f5.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-4Gq0MTQJVBDtr+NHTNpJEc1mTilvZ5zBlC3OXn5aMhQPEAsH8tO4/2ANiN+sq6uPdQXlpJsWPvXBZrRx6vP5SQ==","shasum":"7f8e94ffae8a906b19e7bffc4344d3e1b550ed70","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.e8742f5.0.tgz","fileCount":25,"unpackedSize":61643,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJenif+CRA9TVsSAnZWagAAaaMP/1371VMPsotOulAYXzDm\nasU8SB80vtEqt4adWiFQDOGDmCH/sqxFS0wBQ6WZDHsRknU0IlDPLZDaVBfO\n4301ZxiRu9uyxeNPk/6d12SKjZElD4zpHnSQ5gl9oWLlnZ3ACKfZZxh2Dlf9\nGZf3SOpps4pVqbY5hYPOUVrjlMtbnQFrMQO0embsbnRIaKxIQpyu90O86brK\nuxKsPqrnzOcBdWEjAQnsifLlNGtGsc/ZXvfEJMUZUdh56rbJ1UcsJAjZ5wcK\ns4A+/MeTxTyjnLT+AAkT+0b+vQyvfCJM0NFyOzVFbG6itKJvBShbzDetpEGT\nELUkFoCIv+pWs8egU5o2YG19/frnchleH7XEnh2DRfAMdyInMJbB1dk3DxK3\nomBkJ19DEf2Tqa39nX7ZAV0n4VxDJRK/MPLC7H/zjOyt4zKBBSDW9g/mh12o\n2GBotOR6QWqtjiMbagZ0Ybn/yuY00ys68Jgvy4MGVoGge1262dFnzoNWL7hl\nM+WWvl+l+DKUt/DGtfziNVxMnM5+pAUgT9jG9x3t4j0SddIiZ63gFB4o8OsU\nLKs4vzfb58aZjOJXzXuv+WB3Bc4EcbMNpbYIcLE83+XunLULVlxsW94cOTyL\n72KDgM8gzvUPRoaKizU8E/cRQCyytDq6x3A8y2psvqFlhyVgVsbRRz5C9VD0\nxdUx\r\n=sfwj\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIB4aJU3gKf/5xu5IPp/Wz1BiBsc47ExflBMEG6gGn1vJAiBOn741/ZtIfrtCbZzxQ7Y7GnPEdX/bD+LBj2zx0KsVnw=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.e8742f5.0_1587423230163_0.06355365639024058"},"_hasShrinkwrap":false},"0.0.0-canary.e794932.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.e794932.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.e794932.0","fusion-test-utils":"0.0.0-canary.e794932.0","fusion-tokens":"0.0.0-canary.e794932.0","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.e794932.0","fusion-tokens":"0.0.0-canary.e794932.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.e794932.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.e794932.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-CmZyDjfJ5r+7vNytJnkDko8Mcn8TocWIPclyUlb1PfQeN3ri07G8V8nVmpnFchgvgwuXQBY82vvOft05OiJ6vQ==","shasum":"6d7f6a8b1c65b215b2481f35e7c958f92b3cb5b2","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.e794932.0.tgz","fileCount":25,"unpackedSize":61643,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeniiKCRA9TVsSAnZWagAAoqIQAIhNO3NrXF9y24qYPi2p\nKrftjedSl0fFlMTs3FtwsophrEwWBTBeZxKShBGzxIiiQzusIr1qsNIzgy0U\nOpVph/jIpKllQUB8tVgIaTSrNgKjDj+V2Q76zrVDmdqTffjBscRvwJz5eG1K\nesqz5XbV0OL3EQmCV1kHN61X2PDzUSdk168X/8+x2J8LEp+xDJPGbSXJLI3d\n1zpuwtSGozn3zUSSyDDH6hBzql9TH4qtGNekbjbhIZ2757ynyjYMjeeabj1/\nq7WuJc83bk3yK/IOUKmC3tF5fnlyMX/ctNDvuDM2npYQHlNAO4Rfy819chI/\nXXcACyEeJ1OQbNIJsM7/lRd7HaX+MmJ7hY1/9qrm2pwOlFsuUcfkUFxmBy8K\nBRByN+QzRk7Vax+AQuP3BdPmdhB+WLTx5dJw1V62WZpi8b0dN7vWuOjHGoTJ\n523V8vYAvR5lUFkpXfjXd1V91CbV6GxVuIU1t+M/PV6Fr+R4gujdU/keKmuY\n1EBF8YfQ0wRuWruGG8fvNenyGGxgAu66+ymjG0bMhroD/hUdbmMtxBr3oMCt\nmXu/UPdbayiRuCF/5Ia5HjwIFW68bKwjBA8Sy6n9VteE6m4x+J6ZO3/KwDSz\nW7aDVEFK97Ce4LYkwF+wTAz0ytu5eld48IqOHziTdDjn1RbRNkTJuoqIyvra\n7RG3\r\n=nTc+\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIDK/gpm/gvjxOXzYkvggA24C3NVhrYk9L/X939HiIroPAiBCgq/AqoCv8z6pFBinbvpI2l96WVAjdKSLMakphqGMuw=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.e794932.0_1587423370042_0.5438550821897783"},"_hasShrinkwrap":false},"0.0.0-canary.e8742f5.1":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.e8742f5.1","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.e8742f5.1","fusion-test-utils":"0.0.0-canary.e8742f5.1","fusion-tokens":"0.0.0-canary.e8742f5.1","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.e8742f5.1","fusion-tokens":"0.0.0-canary.e8742f5.1"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.e8742f5.1.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.e8742f5.1","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-wN6BMwtQAIFSB2fchOFUhcAAYsGZY1fvNxoD2+FrXmlVWMzEicGoOOLyeh0+GOw0aGtDHtXVKoNrlvGMbfhAoA==","shasum":"d9901b96d979494b7dfbdad3b629a96ec5a7a3ee","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.e8742f5.1.tgz","fileCount":25,"unpackedSize":61643,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJenilRCRA9TVsSAnZWagAAZ+YP/AuLFj2Cln08hq0DZtBB\nbvmxJ5L4tIDjTg7zk7vLzuYcLi2DCXYu4tpM3S3rsSvv4BuS4PenGCbdr+71\nVCY5fNt9jF5GFd4icEULY6fT7nVUJIhAmyRItkTBhy96zyaLuY7A2IcYu5fD\nruXbTPZq/kVr9TKVzspVAaawmH3yKGvfCwNFdDNQ/D/hpb1ywRvRlLw4GpI+\nJQaFTI+nRfvXcDomKWqO/fwDSXYGCvsG1wJCutACc8gHEx4bltQSctCKT4Or\npJDsCoh89YkhBrehw8fwdkWJe2rtcAgSifo/oJrcLVhXuFEl9iWuJXBb0z7r\nWxHsML18jKIPGDXx69UXrrpLCzCdSQE/W4q4UjX9e0thGZ6EF8dc1O7Tp20k\nqjs/qF48OM0rSu5xmR2ldCH9qaOO5t90CnnrvlJ9QR9HO5faUVnGfP8LiyPl\n88aUt35lndXv8anBkkIn871eLuU+a9T5I1M3qKxhpONsyrTgT0poENek0Nen\nOaN8eqe6k2afJhdsVjVmMIlxWizFtoanuT0sq5dwbiRI301Gwzz5bDTe6txc\n26s91i2lw2uuaugc2LkbC5F0maZrCNCEAffZ0blfTV/lyJ13mbVtfxCwf9qu\nW+zIMHgBW7t6x5GuUI+9PHDkz8sEWPwctbfy/6eJi38tyx+rAhQMU18lL4ne\nd0nR\r\n=FNSd\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDUCnNEQFlaacbTurXB8F5cB8LX5x/XL2NJF63QuYF3nwIgeZLOtgoVP1ENlNoPTDbukQSyBZryBXfuI5p/sy4nL4M="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.e8742f5.1_1587423568850_0.18302718568437149"},"_hasShrinkwrap":false},"0.0.0-canary.7debfaa.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.7debfaa.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.7debfaa.0","fusion-test-utils":"0.0.0-canary.7debfaa.0","fusion-tokens":"0.0.0-canary.7debfaa.0","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.7debfaa.0","fusion-tokens":"0.0.0-canary.7debfaa.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.7debfaa.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.7debfaa.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-jNG16qlVjQXT/nbgos1mT3M3zrxLLoIco1Dwc39fWY0AHYT9PFOFUl5idXNX8O0Y3+3fML7X9V8lSW+/w9mI+A==","shasum":"36a4ce3e0d036f88945e8cc67771985e8a74d306","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.7debfaa.0.tgz","fileCount":25,"unpackedSize":61643,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJenjX9CRA9TVsSAnZWagAAV54QAJDHmzb1WEkVLnaY+8G5\nb60E25D5rrOgBRtAw319jrXqCP5yZVyMZjHy1hpyggfx+IjQecaZCtGm2aeb\nx488BN/wRcTzgLrQV0FDVEObMMxDbSgmO13t6vdgYN1EkcgRtkGVoW9+AC+r\n6QiMwaIHWGwEjLkoOsY12t6DK7FaEDpz6zcNJNJFlO8z4Zu+Qx+agCJn6PSh\n6VzcHmNugTVnlqrrTo6RTKZviEnLD26TQ3YLug1bJP+IOumngu6astCvDKa8\nUY/WYkh/SLbWLQFeA4Tx5rAyT8ExKkVnLow7Q4dM57dglxfACincoBP6EfbR\nqyftKWpYd6NXWD2Bd/eM6Hotj2FA4SKqe/0Iye7yT9xG7pSX++Vz7yjVUOD6\nSvQ+oFgeZbdSsWuWomHhaUPoW4z37tT36YZpEoozVi7Op6w06v6/XTPrnRS3\nqyl7v+bHaErhLnIcZjXYm2xSH05bjw3M/rDjsXCnTzhYYKqXPNgrVVyOhMCP\nwKWXsX78GReX36ATvFZewCm/dEoWTlfTQu79iierm3I+j8CxCz8aUbemUeb6\ng3oHn6YdUuB0crP8oLSLVDJOWENWyb1/4u5VIfE3o0DdZ5HKsSvdUJnM+/nW\nhNl93cEYg3hZ9y0exMlZbJQD2562f4XyTelCkhqb8XUq/CY3e/Ws8Ebxo86z\ntM2+\r\n=ICIR\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIE3BPnJMEzYeYYApaoJRiAVBP77zrUARVLmhRIw5srbRAiEA132QVQDzULACr+eT70LLVJqUZGgU4fzfxVlRNGMePLw="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.7debfaa.0_1587426812949_0.05560178705217189"},"_hasShrinkwrap":false},"0.0.0-canary.840675c.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.840675c.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.840675c.0","fusion-test-utils":"0.0.0-canary.840675c.0","fusion-tokens":"0.0.0-canary.840675c.0","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.840675c.0","fusion-tokens":"0.0.0-canary.840675c.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.840675c.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.840675c.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-mApDvfTxltCQ8UH8Ow4eRD85BsV1piihESHCOReMkD107DLHtMkKAvgYDyLzWD2uakp7OtEWBiJu6rLdhV2vFw==","shasum":"1ebf1120607bb10a179be1e9bd1c469b885ec4bc","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.840675c.0.tgz","fileCount":25,"unpackedSize":61643,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJenlWDCRA9TVsSAnZWagAAfvsP/R9WfDUKMjLij66bWXtS\nM6ihnqKAW9nOANeOAyZNZ0JOc+W3UtiRTmjaSJxb68xPPJZDR/cU4Q0pylhh\nWBu1ZGOI810Z7EC25phsw6BBVpnNBsRBwrDBWiRpIsupEfR7nRCZaRMyoz/i\nzxTTR35oQQgEr6s5la9D8D4LzPFy1aehn53cDM10xbMUlCbDSAzj06dMNa+x\nDFn37z0sAS6Y1eNVc+RH36YGf9RtadfWtQtCSsbzsnjmwb4dylIY6uqoQHyl\n3wqcudFhu23CVj6DGwnWj9sTUWzvLnKHlTmQSapr8Uzt9QTr9hHykU5Pc9td\nmKVihl+ZT1vGMT5kfxzXaylCWlVoIoeem7msstflH2Tf9NpC2VIBPK6uLdTG\nTq+Hc93WmXhXDlWMBXrfoTcLN5E9ClXbw91HFLWdVV63FAJBqQQ3YJFefw34\nZw57XdBJxIuaNmpQ6+HGRv2jemtbGVUN/HJFaQ4Qqt6VOlNkcHMALR1EOHXI\nPHFW8eKxqsQgaWvUUIMjO/DsLksdp/JM22PoyCyrkQ0LuJz9eAtTWo0cNfiO\nOSnhQ8GHaV6hxfUja4DFiUUxxAIVAulr6Q8RbTt5mVZM9NsE48QCCbamif/H\nD15MwSIgRUoyvMcFxob5wUcM1n900EPiENLwiKFeMeKuDMm6aMBUAmTV77IE\nlfnQ\r\n=lVlE\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCICUa71fzKcwCfUY+7Va2Eo20Ytb1cWIfHZHxXenSfzD4AiEA462oUi/RxmLn5X3U/IVzmCUBRh3uolGnRsl8cZeWVhc="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.840675c.0_1587434882734_0.16441154351192178"},"_hasShrinkwrap":false},"0.0.0-canary.a3a7eac.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.a3a7eac.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.a3a7eac.0","fusion-test-utils":"0.0.0-canary.a3a7eac.0","fusion-tokens":"0.0.0-canary.a3a7eac.0","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.a3a7eac.0","fusion-tokens":"0.0.0-canary.a3a7eac.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.a3a7eac.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.a3a7eac.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-reA6x9yk1XRrk6mQBu7czX0LoAvwe24iUy7OSMKm18GFzIAHeeXeowTYfi/OoguZDkzfjt1iSd07BNnnNjy3iA==","shasum":"c72118e7f4f22cf1df9feb8c57a7cd6a1b7f95f3","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.a3a7eac.0.tgz","fileCount":25,"unpackedSize":61643,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJenynRCRA9TVsSAnZWagAAcoQP/36msN0CQuwx3HjpgWhk\njhJFjSZUO3UKqPt5/+rtJM69Pr9Si/DOJS8gT7bx59JClGUfPB2oocwFQcJh\n5nt4b82lupWxAsr5Z9H4ii1mYQ2JTUiFzNsoSJagkftDIPxvd3H4Xr4q1PzK\n9qMJZ5/eVvUcCwooojLs2ML1ifN4E5SYK7KY6aBX+sNs7G27Q65BBe5cpAo6\nfvOA/ub2+lm9RfeS2Gnns/07/BDrlwwhLY447bZCwENcAggbZLiDfCva9ZUt\nM3v9tXFuHtl6Jh7fZX6IGFEB6IIAtGNNsTTXo6b2qoYF9mFUQzznoNmD8LBu\nzRR8XEPoRZPMQifouyQVilFaHkpMh7tmZc0E/iQqd4wMF7mljSoJmZTYPxSO\nYv0Cm0+IqthmHJO6/ejChcNAcwmGmwiJWpj996QdjOknESdiKTXBE4lCShVf\nQN3ohw3MqUPm9da72fgesecM3JYWnHfuCep1IjFi8UZtaOdBmUwKaiep7qOB\nXCLwoVqYhHdFrMAFk01ohbck71cUhGw/eR+k/EbjmfDywa3GUSjrB7kbvz+/\nfFlIqqaHWJIeMFtJWDbAu/12pIpR1nVWJyDqJB85p/5UkmIGflDGqLTLqxr/\nx1rxP58tceNW7fEMcpQ3zUuaeP+VvnPy90lDZKLggG5nRrm9xfqEZBM+uUhR\neFeT\r\n=UtoV\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIEn5p/LM/CqLnv7Wmke3kTQKEasz0MJ4zLCyHVRf130CAiBWE/GxzDxJSnoCMi1BqOnkJUBXgkrBXn1n7wKGOvxRgw=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.a3a7eac.0_1587489233160_0.2663565296068606"},"_hasShrinkwrap":false},"0.0.0-canary.f69e6b0.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.f69e6b0.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.f69e6b0.0","fusion-test-utils":"0.0.0-canary.f69e6b0.0","fusion-tokens":"0.0.0-canary.f69e6b0.0","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.f69e6b0.0","fusion-tokens":"0.0.0-canary.f69e6b0.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.f69e6b0.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.f69e6b0.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-5A/hgqWz8EgXgKWd94CDyr+oRviytkjoQPlryLwTgDb7kbWdqlIZbyccbBydH4T05wC2+gggaR/1EGpYBob+CA==","shasum":"97c6513d0415da2c03bdcd82c5bcb72c96a59b2e","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.f69e6b0.0.tgz","fileCount":25,"unpackedSize":61643,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeoJCQCRA9TVsSAnZWagAAqgsP/2gtGphOSRkoWMwZ/s5o\n4GO3Q2mmajm/C8I0eYWydZG4myagEuJas64+7I81otgp35dgpE2Cja+yJsys\nXqax9rPI48WUDkghmAI6rieEbNFcC5so6VO5mG5zHjPUGxona2aoIeaigG0N\nQFPFg9hPw62zFcScmqjfLLsHqDc/xF+6ByH88WetlUL55zKoxUiN8dHWZLI6\nF83dWuSWbwqsmW2vn73DpOAudQKrBjAKPL7Ebqh1hhmWSPcDmXt2GtmmxNAY\nHVfOsNn1/0MaUzEWbipRWnfw/Q2xMLctNlZjnaBScDRDpUfu44xrG7RuJKHg\nOznOuWOQaItmEJjTh3qufs2DWDMTY5vGg8Rloh5v1HkKjc92GS+5LrZuMEWI\nlm6A+kxToCrDZT9kZdfnMzJEZByp/PyuNIumLJ3NSAIAfOEpiJrAp2dmptvL\n2MDbB3tFgcMxdBZfkvhB+Y6XxBhx66hEkb8vgK8MFtngg07N+DtBUfmfz8wt\nAgoq4G7+9BgZHENGTI0TRhepy42UpN2hgE3AjN2UURk1fUWOlcyLkH8m8DUH\nFoKlC4PgGEmi+TZU2ySRCaVkCeDCqsul/m4Zw8Lu2YoTC0fUm57k9ktXB38d\ngbQjW6ZyC0YTXLXMXR4zdAr8C2IVWMtj3JbJN4l1z8tnCEGm32pfulDWUoFA\nvDX9\r\n=voGw\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQC22S4LPAA6CV5jcVnUCbZQipPsVwy6qx4bnblv/cK7wwIgWYpQg7taT5IwDy16zlcf7OrdsR+4z4DfqLE7b86wGZc="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.f69e6b0.0_1587581071488_0.9349438551149296"},"_hasShrinkwrap":false},"0.0.0-canary.1850336.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.1850336.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.1850336.0","fusion-test-utils":"0.0.0-canary.1850336.0","fusion-tokens":"0.0.0-canary.1850336.0","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.1850336.0","fusion-tokens":"0.0.0-canary.1850336.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.1850336.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.1850336.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-H1aXOSXYcD1WiS5SJ3AGQxi/pg+SARpRr7byOyBuWINMjh5npFMDF0VQpEZqQLoReFEfYwGlRveZPZIMVCbcWw==","shasum":"60101500e2adb954bb2ca4b9aadcc2c6b9cd5e76","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.1850336.0.tgz","fileCount":25,"unpackedSize":61643,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeoMF8CRA9TVsSAnZWagAAP/YP/iz2N+NHOTgaH6XRxfmP\n8ag/Mzc3vqJayFaj0LGDLAWigCs7x4pBQQl4czlE5chh5CI51VGUJbmcJ9Oe\n85+O2D8irZx/MLHiHCFJxFerJLS5FOQBZGGvYvAnu8bldOvltUVhNG/C/uYR\n8RdMvLkAlXKYxcgSHXREx33bxKb8BnLKX3OypZ+1EUNG9+y/Gp+kMLBiFzI8\nmu0TL1pdfd6Nfs/9CQla1lOXnrAfRwe/DN8xlUS0Zwh7+KYqvcpytdmSF13I\ntSmS25CFtcz2rCObxIPl/lzV/28oHaEHqTJJGDuTYKs/kRLxwuzCzeU7aMRB\npDoj2u5RlL+s+AjSs72MMcEvnwiQVW9QlVbjJ0hDuGwzQiNF/Amz7vg3YVsp\naX1MoMlFEspId+LdvUlx6yC3H0ZcV03X+V1GpSWT2Zhh2BhTjPRmrKtP2wlA\nybrHz4DGNf4WXLxtpFgPcXEmtmLMkcy3c98kyWV29OSnxfxBNU4jZrKVRxd/\nte/DvO250YGDuWIyjnMt3jfshxDA3sYQTi/B4PUrcNDWps0hs0JV4rC6oeQP\n2gLADZu5GqUZVLves6I6P0Vi8hBYCajFnzRDXQVIdsj9CFq3Dq9OWKJhFkdM\nxzo/kBRw0PZwDQ1BVrVi7Kn89tJt/SR3WFbHmVKK5QscCszZbV3cd+aDu4/M\ncpLA\r\n=slWn\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIASUpsUYdczAzrZjUwu9AufjYifKP2qvlcaN/qJXeNsQAiBpvkHm+Jz2XjRO3dJzL7F22ACLzG7LNAFWlFrHiBBYQA=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.1850336.0_1587593596198_0.9121099322769108"},"_hasShrinkwrap":false},"0.0.0-canary.2dbdc73.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.2dbdc73.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.2dbdc73.0","fusion-test-utils":"0.0.0-canary.2dbdc73.0","fusion-tokens":"0.0.0-canary.2dbdc73.0","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.2dbdc73.0","fusion-tokens":"0.0.0-canary.2dbdc73.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.2dbdc73.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.2dbdc73.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-ZZnLWDBqP0msA3WZUcTtZ4tF9QWCW9HNLvP85BZsztThVEi789mBZFzlhVT66XIuPHikMxoIbE8ohZtPyMh7gg==","shasum":"e1ca748cd6a38d2ec8b038843af3b2cfc3efb414","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.2dbdc73.0.tgz","fileCount":25,"unpackedSize":61643,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeoOEGCRA9TVsSAnZWagAAOnUP/iBgBzd6IPa3/hQ1QM7B\nziokPrZdIeRDpBkMEmrOVUD9oyCtidM7LZef0MLjk98vuWTGO7SxfL//4na0\n/QXX76jOkBplJV8SRS7fkk8UTqnMWM3L46rlb8+rfiu5GgkpIIsXOgFQsOn4\n43/49Bu16QTwq3n8AOWxyHrzRIsEskYlVxN0yQOg14zb+iKWcd+HxlVS3/Lp\nzVvCrAq9tTqzSbaGp2KfIb6JwW3nMLsSEgcyM7cdplxtPaulJns0JCcs1gLK\no6H/OvxVjIXSzzRgraZpRg4GiANh69jL4JWNIkpB3R/kd3j0fIApSeEzCZ9T\nDJkp1+XoDdaJvVs7VT2XPxq9JOiLDpyNIiv189y86XSWbK8gld7I0cmT5258\nJUrFnnHhRRBQyCuFWCQXSO4xu593YmqudZoAOELP/OFFpKItPLkF+26Neytr\nXZv5Jhzy0lcwx9FcGmVbq+mi8veLQ9KcCqBIgr41gCjzdUvTXm/0k5phX0vu\nOv1NhvuNIj5KAfQPDiGpZ93bh3MsiELxbn3jYYPqP2pmCS0t95YH+nUHkeaZ\njg55gHZhgAK+mmi8z60k80PFlvCQOwWg2/ovNI19poTWUGPWZYFrLAI1Knrj\nzwR/xfGtSMH40cmx/99w9n24yYNusQNS4SkI419kwktUHhoy7LMYGBGQWrdU\nVGSP\r\n=M/Wn\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCSp5pIS17ZKqdwrZ5zgLGIa16YocYawS/4lNJL/mZINAIhAKkGAu/XO7+Ys6QcdFHE7Xhy0j8LjylFcrdzY6IOE3Ly"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.2dbdc73.0_1587601669809_0.41472827808712265"},"_hasShrinkwrap":false},"0.0.0-canary.7379dad.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.7379dad.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.7379dad.0","fusion-test-utils":"0.0.0-canary.7379dad.0","fusion-tokens":"0.0.0-canary.7379dad.0","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.7379dad.0","fusion-tokens":"0.0.0-canary.7379dad.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.7379dad.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.7379dad.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-mDB2rmWt3VgFlAvKWYmdRylq9Pw6VTax19XeqrNe98GNhOXvAWDB4oKIWNms0f7CvapoP8GBGnqOQqZ+JEM0vg==","shasum":"050b74868ffc4cd3786450de0e0c08877782a920","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.7379dad.0.tgz","fileCount":25,"unpackedSize":61643,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeoOXVCRA9TVsSAnZWagAAlg8QAJW176HO/qtVhIwMMSLU\n3bHYZy1mgaBkWFyFg70pGw5iRgWr5bbEtQoc4CsChJs30o9kP9mKko/HSOTf\ncAI99KpvESdZdkSLZ/PAYv66n9EzadM/ROGKB9vwYjvSRYu1emxmNKBocO0p\n2NZOLqWxc6O0T6GQVWf8RosGBXALj9ojoRHBIQCEdrM4tASEHv03pSlNnMgJ\nB166mpsU8m648Jxc5gmn+ZfJ7d8XhtJsbVETHmDtR3oKMInRx1VAE9uKUDus\nfW+p3TUoRhrloCee2uTE6WanTLuKD/MY9FXxSO7qBaiJ6NcxXfvSwxUZwAvO\n33CMV2pCfj51kLkKT7zyf+sp24wfJE9X8JL/2MthUSP5bi8AeOZIKOSl1M2X\nVQ+YawilbMwHOrSSkQ1pTpvH8UFbVdLnpeDdoTTt1NnTjOlHAgbA/EgWuP5N\nOcHceN3pLOEStT6jKU6jX20TxpXEaU6k+66IqjPmd348OvNjZFHelBtZLrLU\nLhZCxNcdu/5dY5iHb55xWv/ghEp9+31JBMwvo6nBaRNQ4gitmHTAkiBXSkEa\noKEstikZDt1yAeg/K5CZZ6lhPnSioeSMH8Gban+y7enA2r/JOsbt/kf2782M\n6QtzlFavP2Zv9DtZewgXFiNCtxSxif1uFCqRlXMAj/t8UHMYqWB9O7ZjDHcb\nPhEw\r\n=NBF3\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQD/xY5ieeZocBNRCLBexYXz+u+OstPa8LnyvcvyFTz/fQIgU8ywonm8G9P+3SqczXE/Z1lJgVshAtU4H2Kf+JXwDMQ="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.7379dad.0_1587602900787_0.8159128919765832"},"_hasShrinkwrap":false},"0.0.0-canary.22b9ab8.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.22b9ab8.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.22b9ab8.0","fusion-test-utils":"0.0.0-canary.22b9ab8.0","fusion-tokens":"0.0.0-canary.22b9ab8.0","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.22b9ab8.0","fusion-tokens":"0.0.0-canary.22b9ab8.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.22b9ab8.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.22b9ab8.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-5uxOfdwDt8BZywh65mE+tTM5b0ddQYW97CYY0k586uA5FzeksmcVoADHtEQZZj7YZRZ6ZZ/GQht7N9lnsxpm8Q==","shasum":"cd530cc02ac839ac0927ddac4ca0606daa0a75c0","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.22b9ab8.0.tgz","fileCount":25,"unpackedSize":61643,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeoz0TCRA9TVsSAnZWagAA/YUP/2rIyu/14QAqFln+yQf2\nUY913/PMvyM5izcI5yuKTaPHiYVvedGU0BDr5azATqJ0pGzlrciPTyITGNJv\nAtRutph7MVvBTV+QQ7eid6Qzrv5XpvhkfiabK79ErjR5l9KeokP2sGOELc7w\nTfF2e80e6oPw4SwaxmxbED6bM5zgGwqtWBkTueW0L7uEVJDZY2FHDUtPw+AC\n02UseqDmrqzrDz+OCtNKDUxzST4X8ttwTpwG+VL8F64Bj/l0cbVsJ+P51v+d\nz92erYJmRhxLFnV2aP/usr5vGA0F+Utt5g7EFntL1z1pwwaoMFISAg/M3rGp\n8C0Oaxh1wkPlGCDtgw2DksuVSQCgP6Sz+IGdiFToYkcaMEBJw1Eu8JLsiJPf\nlTvt2GtlyIKJB9jW6jSf1cmav7x4moW58bTEbHfqjh9GDu5WBBN3pUDPF01Z\nSxaH+0yBRbc30clFVxXIPhPRI3A5Cr+IXNTacOLkE1dYMvhuFNJHvKuGfS33\nWTGKlYcshAp/43kNrN6DWq6eeY+2wCu1rXAp/PeJoKO6u6LzA67BYl20YWLG\ngJ9f4fVriIezPk6vg2YaTUiUCwUYOyNPX2o4fWrSe9WBiI6q97u+qEV9cBcJ\nlLummni1UTM43gCWo+f7/AW1bHYb7Ce+8iPr5mNhYsmDjHjs54QhfIq8h0DG\nBnY6\r\n=8wq8\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCICgzOIrl4DPFsqJwdo1J+b7HJaIqs74BRFWBGhCJw0iSAiB+GsCLKcKZ5LJCt/33ARIV1UbQiRL6/kcqD5JNuPSsYQ=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.22b9ab8.0_1587756306875_0.4564070605864241"},"_hasShrinkwrap":false},"0.0.0-canary.69f59b4.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.69f59b4.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.69f59b4.0","fusion-test-utils":"0.0.0-canary.69f59b4.0","fusion-tokens":"0.0.0-canary.69f59b4.0","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.69f59b4.0","fusion-tokens":"0.0.0-canary.69f59b4.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.69f59b4.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.69f59b4.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-Jepmf8/Ygv+Nh2sr5Wc/0rDbfhJJTTufF65Y8Q0qKa3cAktR1xks/Rc9stalBtu3KPXvTtG3+XTMnNKSv2w9vg==","shasum":"0a5a004ddbc013b116a3414dab16450d70d29509","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.69f59b4.0.tgz","fileCount":25,"unpackedSize":61643,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeo1NBCRA9TVsSAnZWagAAPwMP/A+lDTuiXWm2KqwjmoSC\n/of+bH7RMbMPeU5ku4T/18CVnJGtU4J/5uMItZw8hBMhQVsZbSI7QnpOt7AF\nrO84Rf2dGi6gSIAYczr/nkApKXFuwMamf967rgOhSnMdcs2Bgg11d5b2JbLB\n8SBrwKUyGl7L7wbGfaGgaOEHeydA2xUjrVWY4URo9WvzM4BT+kvjQ3+3aXoF\nJOOvxlNWd1fkxUfeTxCM8tZxGudOzDmsmqt6K1xYGDLsXN76c2ZEwHv1jvZO\n6tDqCcjbG00I3GhEQTMkeMgAEMrqFuoo4h2gnXakAJmtWLSHxDW/nYgW9XW3\nB1Oq8Tv3jQThHrI8EIVmeAOJfx11Hiy/mjVybm55yNgQcCSZDxKuN62IN3jA\nLYg8+uaMIl32zMcVvmrCpxmfM/Wprl80M3Wg1t11K4GP7uZFiL22u/rXhADx\ntodiu+a0qXMyR1574t1l7jkfilrcE2FXy1tHfP29Q21A+KomrB8tbh1A66qE\nvKMfJPlvLbX+lt9deYlzKCkbMXp1VIMh/a7SQBefKIXAKhNE8jbxJfJjalez\nhhu1tXif77qt4OFOBb+vundcSNqMDK5USiJbKJetqS7W2epOqrzKOQ4lF7kt\n37eElWpZwdRbbm39WwpUbeA9HjK41oW+foSZQhEYyHxHVK2tQMnuUyFjsWmu\nok5u\r\n=+CJm\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIF8TZQSJYYGBZ/TzerpYG1f17APMDqQW8fFgo5wS+3cZAiBpcUywvT87jlhr9RnRWDJ5RrCiHnsVjmsMnPwb3mLtFw=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.69f59b4.0_1587761985464_0.38144103484740044"},"_hasShrinkwrap":false},"0.0.0-canary.3d209a6.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.3d209a6.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.3d209a6.0","fusion-test-utils":"0.0.0-canary.3d209a6.0","fusion-tokens":"0.0.0-canary.3d209a6.0","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.3d209a6.0","fusion-tokens":"0.0.0-canary.3d209a6.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.3d209a6.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.3d209a6.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-dmhPv6GIieIYeCJEul6/eyA2m3yw/QSAxzLz4rvLF9wF9L+ds3puJtuPBnmqY9/IGOR9dXsjsCT66dobnf0tZg==","shasum":"a077481ad50b29bc8d543d51933d120a9afabf4c","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.3d209a6.0.tgz","fileCount":25,"unpackedSize":61643,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeo2AFCRA9TVsSAnZWagAADOQP+gL3PbvrbfY4f+McpylN\nq2xqlJtwKxJx4vIHp7PHHH44kZ6xd3m5FCuuWh62M+Tn4RjvjlpqTsUCL0FG\n0+l3QuaRSGBH2TGmTBp5rG2crls5zH+ow9bh65KRS+UJXI+JDGzURhIRT8lR\nKUBfpnB6qW47b7wNsI8nhTxQGb6KPuXg1/1fYKPvtFnN9aOmRx4G6szt+7A/\nESQuOuILZaEqLRL4dgsZGWtHRIVO4zkkRK6fT6REfga6MwpSlrSylxwS7/1P\n/O76KDdqkMUk6D+QGLKwL5Wu8VpDdaA68S+vs0nnMLPzu/c5zbfLTKAAAbh1\nE4Fcwu0sL22rdNTLzzrxmIoeAKOLi52JhHwtqzGJfsCHsQQnsLGKGd1B1O3I\nNrFFDLxVSNaB2TQaZbL1uCZgtnpsc+uDk88QWiCiZm930auiztVwd8BGH2RH\ngQVgHZ4xV7BLH2IG59MVRItUZHOujWbMnA16cBdeiNYv75vmkqce/qtJT1JE\n/Nm8J+CsAlszQ95en7q/ysjuITlAPeXUhQplHoHyECKwnKOLOFbD1stAIuJE\nIFFES1eImvvPk4XV7lEiPAMZXFzKPf8ufKfd1BIzYNshtMRcl6OoumCTB3Ak\n0rcii/6P/lyHKBU5ypHltgP/bAP4Ys5rym612TVbD3D4LlFccINkizBWhCve\nTPYN\r\n=+UW7\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDN66cn7+QDmYqBbWvKTxdbqfMDXb2M+6POpPzuHN9ElQIgdx6e4vkJs+msc+e8sOjE2PZKyT2wJdpgwWIqG58qy4o="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.3d209a6.0_1587765252988_0.95414115571797"},"_hasShrinkwrap":false},"0.0.0-canary.70b95a2.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.70b95a2.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.70b95a2.0","fusion-test-utils":"0.0.0-canary.70b95a2.0","fusion-tokens":"0.0.0-canary.70b95a2.0","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.70b95a2.0","fusion-tokens":"0.0.0-canary.70b95a2.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.70b95a2.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.70b95a2.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-6Y05gVXMPc+v0iGyIRFaR+19sxGVCsb9tcEK70TX+udfa/+zG4qClH66oCaxoPRZN2jtxN9ITR5TKI0SV/UqmA==","shasum":"d587ced2f52a6af7ad20085234081bbe972e511e","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.70b95a2.0.tgz","fileCount":25,"unpackedSize":61643,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeo3rKCRA9TVsSAnZWagAA4/QP/RQNo93JfHbxafAtRU/r\n07PECmiLZD1SJlF22QF8pSvH6i4oWlyU2v1r9vvO5+2oLeb5hd4ZT5PUvXvi\nyhff0UwrqQG0nTW5edvbWHGbuuIrowZ2HG+tzKCfT9SBaLDFXPT/k/mXHwrO\nMCdXYwNLPao3Jkzt8EsSp3pxmyDXwV/6CyDORCzHChyA7J6RolnfcKpcMKKq\n0K3ZhV1MoHKUCZ9mYTRdH7zsFLemyh/qBst7jB7KQSY18f+PvTYOCP8cns3S\nv+9dt4ZmThgVrKlAPN8VxhogDilnuZsh7+NNdBkXydWn4WdwAyk2XCD8gwX5\nMFT3gRlwkwZ8AqTNzeYZVd4BF2aS22s0/J26AvAhBQifygI5eSEngDLsfaSi\niNQKa92UoXlNjIfmAFksaxb/9Hkm1m7VoWFvG8/MFvOFx/axyZFfyBo/hM18\nIGKP7djszru5NmXKD0dG7ShAhq3CSSCvDy1WQ0AFCSiUdiExLD2MtDyz2ReZ\nEWubikHjX+soZXqMXDBjjA0RYWnk1rdno5rjLTavp2toKlfw87/Kn7Kfp02w\nrj5HHIrROUxPX++hmKVg9bJvavz2XVYodtNSYhZNriEoLlsUlwdvaI8qJRkd\n/yFOygmKckRdmFu4ewkoBs8q6Jz0fDgtDde+LJfWvkifkehz+ZBaXg+pTPW3\nFPIY\r\n=qWqN\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIEag/BA8Mpq4tu6LIy/vJVGex9YIZDpihyeVRprts8WVAiEA8JZJlI6APOo3NQUvElQ1X5Pexn4BRH+23e6J2xLzSDw="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.70b95a2.0_1587772106322_0.02406981882461401"},"_hasShrinkwrap":false},"0.0.0-canary.99a4452.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.99a4452.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.99a4452.0","fusion-test-utils":"0.0.0-canary.99a4452.0","fusion-tokens":"0.0.0-canary.99a4452.0","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.99a4452.0","fusion-tokens":"0.0.0-canary.99a4452.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.99a4452.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.99a4452.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-XCOL4zxj60/orWnsFuKfx3Fd6ICWhYqDJ9UEKu80pbNzduXPIS4/2yGzsGk6+OVwTPseTjt2bA2cbr/rr43TdA==","shasum":"ac074f0b5778a91d0f06f27dd190b2d252d032b4","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.99a4452.0.tgz","fileCount":25,"unpackedSize":61643,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJepIHSCRA9TVsSAnZWagAA3jsP/0dmRNkVrdjaws1R2GCZ\nfEeA5YAdWjqZ/dJkmjjiNNdAXaaEbGQnNPn9uuFgQ8vMejjIOy7uEQD+Lu1b\nsRqLYQvGe0bRGE1mC2GG5O6o4mwBa6zZAYV8vvFLjNamabSA1W3t1tiSj9lZ\n1vM2hlWnJRkqlVYZL+/4kQ3TtbKSnMjf9+3ADsfkQiAGiAeizk8qxMam9yOQ\nQSuPImfs3BxYTDbpdKyjBiaBJ2rtOav1IkoNXwlaa7hKyp6AX8Cw+1UPebqO\nTQL4sdaFu4zN3Kgvjeq8NIUtt6ad3JZzF7Ke2sNma8npFPXN7AtgxHjfQ9gc\noTUWbx2tv3ZzziGL0FFALsfCfgwbmoF+UiA8hItgaZmCBwHKbOwccgAnfphh\n84xI11GHXbw33MBT2W5UF024vxOz177O3Qa0aVFh1Lz7oxFkyKITbVzic5s9\nXSxQV7WhSK41JgveGmkOAwsSbF80f2pBvZyDgSdxsdWxBMuYi3Ghfi+smSAr\nQM5sgdPDMMA1Ter4DxvpE4Ql9W3Ff52/vP5My1oBOKAq4+Uc14cYzTbdIbhj\n5wdvas1leRK0VrZVIaiQFQ44S6BpBZ1TrhVp1Jqx41OAFJ1+uf2yV6e8mqsQ\n1xuKKXF34KVlNtNCk+cbciABAv0hd0hCfFzyPG3fncLhbtuhgrXhLY+/myg7\n7/fO\r\n=XUQU\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCeSlpXslQeizrrLgZ5Zh4OZWVtkEUsqecFkpQKdroCCgIgA8gl447ta6OacO2T/4prQ88xv4DH9Cq6rNK9dGyucto="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.99a4452.0_1587839441873_0.5293771082712984"},"_hasShrinkwrap":false},"0.0.0-canary.649174e.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.649174e.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.649174e.0","fusion-test-utils":"0.0.0-canary.649174e.0","fusion-tokens":"0.0.0-canary.649174e.0","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.649174e.0","fusion-tokens":"0.0.0-canary.649174e.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.649174e.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.649174e.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-9pOdzmwvyjGiR8ZBIi1jZhUwI93qR4lsuG5APztYDIPZSN76hhkivb7Z51blZiRO1pT5mO1pEypLKiB7IWh8HQ==","shasum":"e3ba978846de0d917aad634e3808363cc86689f2","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.649174e.0.tgz","fileCount":25,"unpackedSize":61643,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJep0AaCRA9TVsSAnZWagAACsUP/if7Zcfn2tF+J5b4GemK\nqnHGQBpK6YTXVaTonsxfbaYejon4laJqPMcoy+NBZDLc4mpzwZmzCs9iRvQ/\nkyLYn7V6FklAWcJzducmd6AvREbw6kwlDSDlzKSCZLDtWRz9qZPm8njwVPII\nDjKQ6f6xEBDs7K4Pb0oSKPdusDB32Ohk2M8gA659J6ZKATWGupgh+COLG7IK\npvWBUoGvF4swQkRF6+wgIqnWOuoqQzAT3LVdmXdHDlRxeeaIx9XlAAPxXxF5\ngqmv6tcwDTS5dM12tF6rRkY6a/qF8pvpy4o0lZqbxAauhDWqwSduvPOXTFAN\ndH48NvdddlMwmlqNpu+k7HUDIzxK8VlLF8blF7FLvUmCHdyKx9Wez1EFZ1yW\nkoZn8trlyz1YWvMNJerexf/Ghk7PgZVZQBZ9eAgUSxuiwrZS8BJFlUOZ8shY\nR65DrpH5yu4impr7yvIt0C7MlDDd/vWUy4vwlauiT9Xu6Ktijc1A/jw5IXOy\nYSfdqbITllWGC2FlruGm6vDBr+Mud6bRAaigIAX2FsvHvX4m6qPDDgbSNIoq\nYWYB1iNa1i4Krc35xEvo9hn+C+FjN5aI5Ece2LkyAQL4xFZK6QlNcoLdFVwv\n9NZIC1Zwf3q7dR6ppv2lj1IIXwZ3xfBwRhpgc2P3vLpCfVyzhMvZIIi8l1jD\nopbK\r\n=pL7u\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCICA/cMLCgQK46Y+He7IFwNkUjRNFvyyzbk9mb5Uc+F82AiBBtzNQsc/rjyVLEX3DcogzKgSuT/wbWnfsps5Gm2Xmdg=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.649174e.0_1588019226071_0.782919776139293"},"_hasShrinkwrap":false},"0.0.0-canary.99a4452.2":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.99a4452.2","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.99a4452.2","fusion-test-utils":"0.0.0-canary.99a4452.2","fusion-tokens":"0.0.0-canary.99a4452.2","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.99a4452.2","fusion-tokens":"0.0.0-canary.99a4452.2"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.99a4452.2.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.99a4452.2","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-b+TEZRyzZmpSejdpyRBhCMX/D3IMVA/z6WR4puoxtgGPGoUUJMb+HARrnCZ4LGACIXpSyHBaSz0tOPlOQhcOUQ==","shasum":"5fcc593df7a16f9c97e2d954a0eb60b39be463b8","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.99a4452.2.tgz","fileCount":25,"unpackedSize":61643,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeqHrcCRA9TVsSAnZWagAA6B4P/1ro5k+rGbSbeWHze/n2\nc5gt/qJs7y2X4lZ8TUhl6hLyardEOMpez4WgOPke7L9FVQ6OhBV8aISLd7EJ\nUcLIwOwmlB1ycv8PRngSiqgow49KrIsZAN1naxSFEdhnC6Gi04oL+LnybSdC\n6hWOGErs0UGBb8RcF05wOAKZMq2Aq+es+hXEnCTQptEBwZGxQ2nCJX4cWW+d\nBz8W5pOPhWSEnXHMTGEDOYlzao0zpzrxyCqPrb6BXZPpEwkfegmgFDI63LGw\nm3Q3dE5Zi+6q+DYi0h8ihQMyPXy8VM+unCcY3Bx7CU9pxsTpKI46nNshGlPH\nl99+SrHfbD1spEF2A1BZCPn74BZL54w3UooKCSUIwiBC1+nDMXMgfLhEM5JD\neRXS6AftfBk+P36+IPgsrH5AQOtSP6qQYom/6QHixZQctIrcky6vhXqkLsKU\n+TYvebT56WDL2ixSayNoKdviNZnzhAR1H41Wob5sQ5j4+Ekakj5Iv8ojHrMd\nX1nSszxgYPJaqIaxw3aqMAJGY6c1P5Iz9MWGb6BEN+2MKd4BdBwtlPUMCYsJ\nHEezWEf4lhZN/LHsHWeU/Ukeh91DVapG4+lA8462+/jdMQkoz8sxNCc6lWk5\nCf2xzKCIfSO2kgrmLuQncuR7Jkx8IiS7tBnHMB69A7YBd9b7kKeqWUCuxYMR\neFoZ\r\n=CSn4\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIFwtXo6AzqpXxLcxTfbY3vDr2NcEmn9aNpdqoeByinTAAiBtE0mr4O1+EnrNIKZjhZDsLaCA18r8/U1QvpTP/O3iKw=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.99a4452.2_1588099803878_0.5771290823804767"},"_hasShrinkwrap":false},"0.0.0-canary.649174e.1":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.649174e.1","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.649174e.1","fusion-test-utils":"0.0.0-canary.649174e.1","fusion-tokens":"0.0.0-canary.649174e.1","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.649174e.1","fusion-tokens":"0.0.0-canary.649174e.1"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.649174e.1.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.649174e.1","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-hcWlkaMsDMNArY/Qhu4R0mswOh1gHR3Kp5RywnBTOJksk28UxIWMUtITBwlLt+PjXnkvtu7X2jCUfdfbBTjmjA==","shasum":"43523ecceb1693f76d0367146686deac5431364f","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.649174e.1.tgz","fileCount":25,"unpackedSize":61643,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeqHs1CRA9TVsSAnZWagAAHF4QAIqaRVBe1L41S1aldc+P\nPjexQdQOhEzABiDx4TO1ZDnqzfKFmftiBQtCwFuv1Wkd9ixqlPfpavNnU3CS\ncR4FwEUeVmbq9/G3p1CegNvc48DHumG+Hk0Q/Vb1BHFJHOD2NxVjOz9lruoC\nPpvNMRy1D1Gzl7XRNdp9o6Bda++ot0P6vymC4XXFALKyuCspKA/lB0JpPYzq\nNKwkUBkxmN9py6XMCgfB/UcQ62wDNEyKL8h7IgS2dw2/zGd/fo4P+B1xAmzt\n/0eAeZpmmHqfKqVlsaT+6Ztp9dXdVkeIpRp30SwgFNCjtDd/ywSFc9pTFsQ6\nwADFvRDNtOLdRleo4sNoe8EGrJ+DWrv9ObnQBq9M/oXjOKtzKVMaxZAuJ0GW\no9DcnPeQSA0i+Fh1usLShAG2V2Rnlgeg0zovKNMXQy+com4QTr+ktaEumL/F\nf1CCxKdSaeDHufdzw7bf5S4FIPFYBAeZXHPcMiPGcC600aUoIft5fgJ/gwi8\npQDiik7GUjxBIci7kQC8tps7XzT+nYIv5mIkOCo83FuBcZwHCPFiUhb3biQi\n+YMuTrGOwblOEJVDjxAWFKe5oPTG+NSW/QXHlFS7gEOocjxGQqGp3ON3m9Ui\nq2TidDhaoCJBdR7uIYZ6prgt1NCYFTWXMCMg+ykXpYRLTVUENuzkMb0KbTSL\n/B/n\r\n=TcTi\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIB+UwMCzCvM6oy5MR+abXpwnnnjLPpD3T+Qpn9yRp9rZAiEAh7ZJbzCKgyhgBqR6eYDh+6ntccfmRWYGk7qbjaZ1khA="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.649174e.1_1588099892793_0.18893146647591208"},"_hasShrinkwrap":false},"0.0.0-canary.2450eb8.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.2450eb8.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.2450eb8.0","fusion-test-utils":"0.0.0-canary.2450eb8.0","fusion-tokens":"0.0.0-canary.2450eb8.0","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.2450eb8.0","fusion-tokens":"0.0.0-canary.2450eb8.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.2450eb8.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.2450eb8.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-KJDvuqfPpTo0bcpntk+y+0stt4tsEH9EOwKHVzw+S0uM2vK5Cm817WfoNYy7JrMIyrhoNCcMlhm1fi5leL5hMw==","shasum":"2f8cc53ec1de16d23b4899e409ed5846b966c632","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.2450eb8.0.tgz","fileCount":25,"unpackedSize":61643,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeqH3rCRA9TVsSAnZWagAAb38QAKKYmBdWIu4o6B82c19i\n/ukb7Lg6LMTGzsF+gy6GHZmsse5ekev1I3Jd3PdW5R6qJSS+BfMTit2XoOxs\nTdQKQWf7ybLuBPBvDu6CCfVKFkOElHl47hpl3wTZ9Pw6XA+xBXpVl02Mhsi8\nL1+PGF3RrCSrBcvfk2FImSEVgC7gCMXGs/iJPGwiozg9hiNxcxW7Ckvpp73L\nnQt3m1SRk6P17a0bW66JudOX9j5YzVl2CxkfLck+LAsfBf0/vIbIKlUqEfwJ\nMGWLagbU9DiHRov/has9q9BaZXMCLe7tisW9loxb7I0WCUNrZ8159XIlJVXr\nLabghx/3umBM1Rrh43SpX7u5OGxjWB2Gmm+VRFqCTbz2t14FFqjmQqB5acRs\nbGxNeQKm4SqzEwcZkwfo7ExozS+1Uzyn4uU8BE5pEJh043Nbt9Tug4AAjUrh\nRPjwY16mJd8shu0JlLzVzN87/n63OJiVaKOyMQO0MWQe0C+2zjNL3BQcomEF\nCtbzjkfNRXOYrGLdBf/8yiPnj9uY/h/tfYMtdBrcU4RN5xiPFK8twjlZCasI\nG51/3ZQaYBR3qYrgSnNACu/iczV4TsgiKNGtE1rj0ZRyPJ9e92Wp4ug8305X\n0ppBiGCYkHVU8hgHCqPFOWBj7k4RXgeDqWym2/i5Fs1Z8NZp/x/vEA4SDmgp\nEQOi\r\n=Wpxd\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDIPvAl3+kSZB4/z/oyRFnoT8AtWICX5xAqTq75BUtV4QIhAKcmhFHaHQuNhYb3N8hmSkAi+UJRi1E5rDTno+X5XNa2"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.2450eb8.0_1588100587168_0.1282997004477533"},"_hasShrinkwrap":false},"0.0.0-canary.2450eb8.1":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.2450eb8.1","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.2450eb8.1","fusion-test-utils":"0.0.0-canary.2450eb8.1","fusion-tokens":"0.0.0-canary.2450eb8.1","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.2450eb8.1","fusion-tokens":"0.0.0-canary.2450eb8.1"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.2450eb8.1.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.2450eb8.1","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-+jpvdzPmjqW1Wtx9y9zXSWIVmxDSVQyc8LkB7PYHHCnVOWlb75MhDyhnoDv3ydJ5ileyGBZm/saIq4TgFfc+Sg==","shasum":"e29a287313fc4f756b50261e3379ab74775c161f","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.2450eb8.1.tgz","fileCount":25,"unpackedSize":61643,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeqH4zCRA9TVsSAnZWagAAlkcP/AjlcjxD0rEo5WexRb4V\n5XmmQCqHxIkizCDcUxAg5DXFl+i2o+N8Ifoz2CrfcnSXtBTLGxpprnIrwqt7\nb7k7jlThR/HtoRLeDdYNePj2JwhHgAX6laj1NT/4i5+MymWuwr/e9rXbK1NC\nYqQP+/oG6QpI4GeM/WNCNyVKsGCWmI7RJpDpufpkqiXeUmaVYk8kr306t85n\nc9XP4jdCA1hedAJn24p82astZRGuTlIKvMuz8gBBZX5KhvfnOuswPsRccAOm\nDyQq2GusFf7A0OFAHXwofD3ksWYhgn8y8iMbN/o689CUlBJu1P+Z/FWtiovz\nF2C7UvEx6CsH8wZ0NzPWedhG9CDd9b8WNlnSg+FrxsWPKKMFM8WB9BW9qBvX\n4VpFaYvJbyrPXo6qG+JjbpikgMklPFgcuFUhKlLj1ed+YRpk2MUVIz9bipy+\nUzBOavwel2XnP4qgqWLMwOlDLX5Amhfw2xj6S98UL1RS2xh4ALQyIjK8YF4q\ncmYlndnn3bR0F62Vk7hmbU3UUNCr8Ec4oym+XZNGEM/WHZ0ThMQ203vklCGM\n+iTqYzZzyGonLbMU5vRSTlehC1sma01EcmVnxOzUdf7gS0YMBT5pGDL24iqb\nwyllPXp6kwoja+50xwEP8PcoUZ7wLVtvB/6PWUa3eSYiWdPmkZrZbxfFi8Fr\n+T6G\r\n=qTUp\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIEsW7STgBOR6Qc38wzIEe1NOj7iUuS3XI3I6f/O4LKcxAiEAlUqhlluyO15cWHr7iOWUS2GlT3052egD6pY4KoMigus="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.2450eb8.1_1588100659266_0.4931967789932288"},"_hasShrinkwrap":false},"0.0.0-canary.3b3b756.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.3b3b756.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.3b3b756.0","fusion-test-utils":"0.0.0-canary.3b3b756.0","fusion-tokens":"0.0.0-canary.3b3b756.0","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.3b3b756.0","fusion-tokens":"0.0.0-canary.3b3b756.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.3b3b756.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.3b3b756.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-05O5O5xCsVyHB3F0818RK3GFEPah64TU64xdYuHUhkIxiInyso/cs025NlN937b55xrzkH80XWJD0T0J3Yspew==","shasum":"8a4cac2bc86f4742ffbcc9ce8d1af9a4c182ce44","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.3b3b756.0.tgz","fileCount":25,"unpackedSize":61643,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeqMplCRA9TVsSAnZWagAAbp4P+wfw5IJSM0RcpGJVm+Fq\n8RwYNdIOTLL3U08xAf/SAbKcZ+Pmug3rTvrcsaQ3S7tzdlqJIVDmYR45oF12\nRAix7SCJWxjxrMwTg/ZfVEPB3OLesp0xyYYezDyly4YTg1/GS/j+ckFpxJvZ\n2pOJvJUZl2qfFlVKb4Rjp20u4hC/Chtctjbk1Se+CmK46ujZeCW+eeM3H3zE\n/aSIf3+i/Bp9n7myhV2n0S57javtMyjrniyrED+pJHh/WmJmYA9CKKQrnYf8\nWSENY/63HOyDhFuxVNkxZiu10QDm+XSZ1aZ9gIK+MEgyQDHnhELGTs3n8TlJ\nlbkDZN3EkFyeM7krdVrp1PG8+7jif7hS5vxf5kRGlj4vXJUnpWOqeWltFcvx\nYtwf0wtcmgTznButMKC38b8zlgTRPFmUGv7TzviWJlOck6FhVpM+onyLsoNY\ndi3cNnhVs70Bpn+6gJUj80ZA666x4UaGsNXaqzOwGuqmTWQFcvnlo69UGGa+\ngbp8adOqr49rhpS2ze52hfrp0oWDGgx4PJgMlmC6dz3jVIsxV92MbhmOSFom\n/xXsrnK91NJJ9of9KUdugiEZgTKHdhrnkcItWYdFFkvMLjBA+Z19L5UeCsKM\niVQOtyFM93gkYKPn19ofg0nSlHF20SLFnd8JH72a777NrsuQuvMuhdQFL2NT\nWDJf\r\n=eyHW\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIBtW2j8gnEmVZ6RT5kCTBZRKXZLsmwKNhETHOWR7T3rBAiEA6oiuzQV32dkpHwed1q5pEQDCKIDlrRDEzQyURgMFfpo="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.3b3b756.0_1588120165294_0.38853250247337967"},"_hasShrinkwrap":false},"0.0.0-canary.3b3b756.3":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.3b3b756.3","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.3b3b756.3","fusion-test-utils":"0.0.0-canary.3b3b756.3","fusion-tokens":"0.0.0-canary.3b3b756.3","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.3b3b756.3","fusion-tokens":"0.0.0-canary.3b3b756.3"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.3b3b756.3.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.3b3b756.3","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-W7NourzZ1yB2eDt5ojcL1WfQq/0avv5+cpNob47D4u1gf2tC88i02zbSHjrsDbQ868f8WD+goftjPPR7DukPoQ==","shasum":"9b895b9cc4e24d227097e8f4b62883b2c6800a98","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.3b3b756.3.tgz","fileCount":25,"unpackedSize":61643,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeqN5CCRA9TVsSAnZWagAAb+4QAIPa1Tz4hjXsoEUPkqZh\nWPksn7uwLB+UMRqDqaJklk7bIqUB4+TaEEwktA1EJkzWFOCBCl0OBNcZm6vo\nwgXxgCqByPcpBCS7EdKURd/43E8Ti0tyW9X2NwLBbngiVQWec6LUvyJngSZM\nLrOdWYO2Db40zMsYGvrHpNfnwQZSo0aWVmrVt3FCtpwsnuOJ2/c8PuZWPZpO\nmqnR0c+7vYa/eE/uRHWRPHRC47uhkWf7rRQ6EKywnMATXiRV6cdiixeiYCIW\n2UIWEtdihO4O4LfOhOnUueLWRvReG182jDeJPne7LMw6TwIgHaXTlz1idGNr\nwKWWyrcrDX7yQgrUFThKDDFHsYXa1E/TsD1eicmnD/FiEqkTwifGRxw5hwyB\niF9IDaaHtFoa79HlxHW2f62FMTjaRXcfYg2lKzbHSCiMVAF+YUJDTDcb5aU7\n/NRLqrHuzFfFzGlkpEFi6659+TGu6V5JjuYjECKyW52Pwg4Jv0i0uLd9k2Q0\nnGyqfRXA0W7bVu4FtQ70emr9cs/tyllS7e4m3+OhwqwNC+OJoXENd0E20J2B\nWc0qGdvlNCoUobqNyvPvbK22S508Rbxr6o3SnS4RFMbOjgPQpkRJE+qhu9Mn\nYPbR6u7Q68R7DZ7DXT59czXE+4nMx2qHXhVwVaTd1yZrL8itDEsGmRaIi8uX\ni7BT\r\n=i4JL\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDnr8GnM3LDA6OVE7X3jwF7vQSIaCaIbfYInM65KQTftwIhAORM3d5t45Fc3g05rba9jNGRDQ3Vz0IxjSNrb/2YQMBX"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.3b3b756.3_1588125250296_0.22620673672297964"},"_hasShrinkwrap":false},"0.0.0-canary.45a5f32.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.45a5f32.0","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.45a5f32.0","fusion-test-utils":"0.0.0-canary.45a5f32.0","fusion-tokens":"0.0.0-canary.45a5f32.0","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.45a5f32.0","fusion-tokens":"0.0.0-canary.45a5f32.0"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.45a5f32.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.45a5f32.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-mORZ54MjSHLYotDamig/EuzYO61uKd0/H48pXCgGDjijqjPrYVUhH/LhsyAq2ItzlMcUdusrFbdz9gCHwm1C8g==","shasum":"5e2408967420c74ac00e962e671b53682e35de6f","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.45a5f32.0.tgz","fileCount":25,"unpackedSize":61643,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeq0zOCRA9TVsSAnZWagAA7kYP+wS/xYIrE1eIrUc2tHtW\nyi4QhqcemUPizwuTzEHp7Dsg8cFwUOBufYEhNYUf4kCGZy/VEslK/whMQ7sS\n1NXhP72PdEFxQurCS9Iwv3FZKsKUWUvcwEDxtoKRie6qvDYBy2amfz6OgHFv\no/6rILPzdf2DWWkrBJaVkZ27ImOYWaM/dRyxc4Rf4Gl+YOGft150UvdFdbth\n/p7Fhk5AhiH3bCNTr04W7y3YFXK60J36zZvM5f0cXcqqof0GPGWHIYgq62oV\nM7O1fBJbnDiXouyJ1EVuGKrSoNccH0FG/0dYVJI2WOKedh2OoYqzQe8drZBr\nFy2vt0c/p1QJmjZswthu0SPdlqauZ/c9URpn/KG8FXLGzvWkCo5xtFQnKjyA\nwSHoX0Esw/I67OtZGLyEVH/wLFIpGZKc9fv/7P8QDICw7qLWAFX4+rW+/gLf\nIdCu2c0gBxqC2zne9bwxaqZa7+Y4ZerQ2jb8Ng6nQBjj2bChD44aorTLvvaR\nLF0s6BQtITzHvz5yjptXn44TQklpeYwJd7Ki7XSV1Qt2Kn4R0lZjJS2yV1M3\nqt08Vw0phZ5OIs93QiOaPV4IkW8aYp01x1OnFRCk4moO6xbRwAc9HTHQUoMn\nCv9tAHYsHaiB486cGXuZi6kt1crD3P46c1zPw0JG3Zo++JoVLTz9uNqrxOJr\nD/RY\r\n=yqL6\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIEtwqtiPKYQn3UjnL+F5FZkntcK3wboxLwMhoIwoTaXmAiB7VYn9Ay4CfgOw6n2NmbOb3QAFrxQh7xOyMHIeyLu0/g=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.45a5f32.0_1588284622217_0.22940563694637017"},"_hasShrinkwrap":false},"0.0.0-canary.45a5f32.1":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"0.0.0-canary.45a5f32.1","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.45a5f32.1","fusion-test-utils":"0.0.0-canary.45a5f32.1","fusion-tokens":"0.0.0-canary.45a5f32.1","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"0.0.0-canary.45a5f32.1","fusion-tokens":"0.0.0-canary.45a5f32.1"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.45a5f32.1.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.45a5f32.1","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-k3Ubh91U8U4lOCz2qQfiQ3OtdUlKW9iD3xKXlN2C4ea4yPTdN6vlbiSkFnF04PMOuw+uNTi5nLCyP+MYHzIaCA==","shasum":"e924f2f3609e87a29cd5a8f88f9eca81c45ecb51","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.45a5f32.1.tgz","fileCount":25,"unpackedSize":61643,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJesFbvCRA9TVsSAnZWagAAaaYP/0AfwEUtcLreXqNh3QQS\nru4jY0NOh5+6CjbaesYBIjHivYh6jYWS5s31CcxtKfpx7ityYQABIOSKwg6H\n9AhiYfGSqfDjtZLGiYccbapXFgWGTopgu9sxKwH8LLcxYglmu+9xlW6YSbkV\nAlWEZ39DafUaz+e4e+/cUrizyalyi9Oa7avLDlAoH7IBjYj6C38Hseh5wbUy\nSYoSoWBLFNwDbL6wT4ZVC+bcL3BWGRWQCaNsp4N1WtKYSaPtYK5QPome8YRT\nCg4FX5At2pqZuYiprMIZqIf0dYErHdKgeL893cJiG5tSwByraMnHTHuHxLDK\ntm4/7yWuUAY83BlidIlQ9rf2fUo/Qq4M415/IHOsG7mA5cdJoDyBZsTHnVtu\ne2gn+evJELqLhids9t/zx7MI7EQsDF5HsdYEUMEBMfhNfeiLn4eCAqlrz7IS\n3K897zErpI9bhnLoZwm+/CQ/VHnpHrfmYJBZG4f7yx6tgMSrWsJ15DCOrtCW\ndTWck2tmx71zz9dnF4yiazcJW0Spz8VjyhTHuIfbfsNVDi9nzWMX5ACSlpA6\nac54eNMjSXnncW2h1OkdaXfRdK0RnydhWwyIlezgtAQjdpYZCV2XF+5J1Bd5\niVsBfMs7Mp29oc6+MPNx2g0Zks3YDZn5Q+7RrtHs/z/IpXnzDOZZAZ2rxhME\npbgh\r\n=6kKp\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIEn0TK6RymHJvO8/tsknxu0SJlXv2pwazG8B6OoN1N3xAiEAsa2FJtbGnXQ5NYCX1arYqJLockFKih06zrT/v6OUePM="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.45a5f32.1_1588614895258_0.29666121781923827"},"_hasShrinkwrap":false},"3.1.2":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"version":"3.1.2","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.6.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^2.3.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"2.2.1","fusion-test-utils":"2.1.2","fusion-tokens":"2.1.2","generic-session":"0.1.2","get-port":"^5.1.1","prettier":"^1.19.1","sinon":"^7.1.1","jest":"^25.1.0","whatwg-fetch":"3.0.0"},"peerDependencies":{"fusion-core":"2.2.1","fusion-tokens":"2.1.2"},"scripts":{"clean":"cup-clean","lint":"eslint . --ignore-path .gitignore","test":"jest","prepublish":"npm run build","build":"npm run clean && cup-build","flow":"flow"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-3.1.2.tgz","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@3.1.2","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-N4A5fZFFlNDD8aTClqI2yO/7Ehz8GNHdVTroaIPPBSFnVRbUoXXEjh9KOIhVBpx7iTSgiol4OxBxHVquVOaQUw==","shasum":"594e5c5fa293bdc8c48edaeb1d884eb424f716c5","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-3.1.2.tgz","fileCount":25,"unpackedSize":61541,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJesJw/CRA9TVsSAnZWagAAeZAP/0DekKhshHydXVlMxjVZ\nNPmMXJVGf57rPb2YjT3IGA3iGaG7mIJI7PG7iEm/5FDMJb2yGAflemXd8jf0\nyofMheOqVqr5xlHqXKgE65ETtCREgkXn0mD7FwjmghHWUSMmdJNVE4W/FAlZ\nCU4J+6SbK312k0wY1LJgJf7pYTRw7HqRQ7gM0hL44e95A3gnJcRb2hwY60gf\nlJEQiJTNJeifjiakyPtWzgH4TaB4jqUdthPvEnE0Q2oQFUYgLWzuzMogAqOi\nmU9ZWk+rre327pjC7hLoC9aWH1XyaQuhxOQBHZR12A6EhlX7a2nfVh3CDzBK\npdeo4immbHqzX/bRNnE94poyWHHCeCQNhXfZrO8aKZAsm58ZiQ/NtJRp5bGZ\ns+WhXP/K7H2me7hE9b9tVX1APiTyUAE35VI84uNUN4x+WdJ9olpWD+3AVIRE\nWTXQ89SBM579M/FoG9k+NtTjSHXnTFnsV+vxwlVt/PnFnsZNFmZJvCesrDXz\nL54p06MdERJgTePNuM4bxbGecr18J1st6NT2NKgenjLLG8Oyq0nktfsWNG8h\nD5anKvsLfz4nNs6ciipYVGBtfMXrhv6S5gUlU5L080Sbw2mnfQ2U8n4twWgm\nOrEx/NmWrmuF6N6KIJyBtvICY6vnGfnshV2zUHpw1WRX7GuZuamaG+xJJLvB\ne5fN\r\n=IOXP\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDM4sJozYqrP+SI922s42uYpaN/xA0pfHukSbFiE7LxbgIhANdZ3hJFZCjvmzNjMwX+jcjbbH9LzvXKpkXw6zu2TFqc"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_3.1.2_1588632638741_0.49221860916442517"},"_hasShrinkwrap":false},"0.0.0-canary.4e80a7c.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.4e80a7c.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"0.0.0-canary.4e80a7c.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.4e80a7c.0","fusion-test-utils":"0.0.0-canary.4e80a7c.0","fusion-tokens":"0.0.0-canary.4e80a7c.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.4e80a7c.0","fusion-tokens":"0.0.0-canary.4e80a7c.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"build":"npm run clean && cup-build","clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepublish":"npm run build","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.4e80a7c.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.4e80a7c.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-Ub3q936W27+TWF5OizD3b9SBskUpK9xMczQMH/jNz/jt/q/7ipbwMtz5Ca6x5+5FgonrcfFihzgyeArb7BWMjg==","shasum":"f440be5103e81363aab3d90efd6b3fbcd84744df","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.4e80a7c.0.tgz","fileCount":25,"unpackedSize":61661,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfSDJlCRA9TVsSAnZWagAAb20QAI3fMw8damttG04Q/Jcf\nHFYk2i0StOxFGTjikBTqS10gYBkkxvR1opEGLRbehl6HSrAaCfsLz/LwRkD8\nv/7FEe/s4hSHXu/S/WZuUCTmAdkmvu85MKA+CsoykrA7/uu31ovM3IxpKN1c\n21BQ8fceqjR1v/xLzHXQZOKLsbLHphmK4jLDn6or8/3Ae89UQeYTZ4foyCSJ\nihHNGGPaLfFSoDa/BPgERl/JXk7Ccm8A7YcfvVptxexup85PcskZuQNCgS92\necK4XnERka66FFC8VkQiLxKqb0y/y7ayLV6ON1cKbY9HRWEqjVCBcJmKPYMF\n42to6TArz3em/UXvHxYX6OXL2I0VlhADqaEv7adkCqzbInv8QUPR5MWW7ozS\ncHVkdZDhXAQNJrO8M5k8pU+aUKKKGgy7puSnnCGvyberDXDjN5CSgfSLzBMX\nCQEdirN/xb2Q+4EPtZjjvC+ce57qx/uhb0llwfkNWgtzQhRzuPhBT0CQYHGX\nIRMGmbyTYt236Qgfjn5gBPdwLLYoNmUvyZ33eu5E7TWqN9q76+wmcKZhHQ94\nY6l1wUiOJewX3zn8+XnT58zwb7KuuLu1XxWYyPK0bLGaaKUDuEeBjuQz4OiT\nmpI9ArKYjPt9j6YEEVPg6cYQejbanqD5hj4Yiemug4WvPlgBQFWRLefKJ+gL\nKXrG\r\n=amIN\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDMzct1SNBiW7D08oecPyLxdpQaD/S9LfD5tb00d0PhiAIgSg9uB1lOznFFCPfFXZYfkhdAKiFAlvTY5KQsMRrlV3w="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.4e80a7c.0_1598567012943_0.5659667668036423"},"_hasShrinkwrap":false},"0.0.0-canary.4d0772e.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.4d0772e.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"0.0.0-canary.4d0772e.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.4d0772e.0","fusion-test-utils":"0.0.0-canary.4d0772e.0","fusion-tokens":"0.0.0-canary.4d0772e.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.4d0772e.0","fusion-tokens":"0.0.0-canary.4d0772e.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"build":"npm run clean && cup-build","clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepublish":"npm run build","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.4d0772e.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.4d0772e.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-8kix00RrimUCcpEwO2q6GBMql2kXVrM10MtuS32Z2BNNsv8RGXauZUPK0PRj6ZSlfwpF3YARmDJfa2IDHdgCLw==","shasum":"e89031419e970e9112073ff84fba9e698572331c","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.4d0772e.0.tgz","fileCount":25,"unpackedSize":61661,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfSZv+CRA9TVsSAnZWagAA1U8QAI+/NayMbFtvIrq2GWNu\nyv3aagJPnu0FGA81a1nZAiGB9jKjen9YMAFwe2OI9QqdMvqe3TlrdcDZQGBO\nRngskLUFrW2Oy++ZKNLVdHoyBKM6B+qOZRFOmMYmIuIlrWoxhKF58+ClAxzO\nO7kPWANzfWoE3dKFK01zgtNTWSNVxZjACShxjPCLzvVRC86IG7WeJKCEppeu\nMnYjGSCK2B7KT89QoVNDrY8LbTt/4o83wOOqzcCeGz3tgwnDUtcV9cor3acb\nPm+2xugdJ7ExoMRVecQMLAsVcxmFW25KgBWjgMhGxN6alANqapx1m8M77KOI\nHUGnEtElBYOnPGMbhbimrQ3+Z48AMOqpM9GHJ/Jp6uCehsdq5vcethSyTJjw\noPVsguUytJY/NOsG2JzF+xhn2wvdO88oYEr69vwUagsBXgtRlVVjSDhMvKbe\nfgj+I1dR0w2m5jLGOZuTcrhmdUKVvJFDOMs/yM0kLtAMFLfTgTN15a7jIijw\n/9fc8vwjyKhNCcUo/iwgSPgXDhwT6whKZGTVVZC+FZYgVynX3h32h281lgsa\nhA5g2jQhYMJAX0cvUFIStScam5C+lA0H4o1SaJFjhTibBAGOchIc9dc2H6O7\nK4PyVpgXY0rGGmj82zq7bjyXsx+nIup3luSW2IroGcZ4elxAaRyY1ERAwsrF\n4iQC\r\n=sbuy\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDqmlZVcciS6HBxmDW6NUvatgiFhkIPfz3qQCUVJ22aOQIgWxEgzM86U+PTzWJg5GuBV1YJUj0txvImX0ko/siH/Xk="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.4d0772e.0_1598659581830_0.6465539564681824"},"_hasShrinkwrap":false},"0.0.0-canary.8a530ea.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.8a530ea.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"0.0.0-canary.8a530ea.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.8a530ea.0","fusion-test-utils":"0.0.0-canary.8a530ea.0","fusion-tokens":"0.0.0-canary.8a530ea.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.8a530ea.0","fusion-tokens":"0.0.0-canary.8a530ea.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"build":"npm run clean && cup-build","clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepublish":"npm run build","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.8a530ea.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.8a530ea.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-jds6VRXq8qVrCKCyh672BnMoPXGg3aG2fBR1uakUV+ytwpmECFpWveLEKqEdN+j9olIEQ4C2nY9CG+0ZvgDw0g==","shasum":"26dd91e80fe31f15c2f50857ee99f4095648811c","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.8a530ea.0.tgz","fileCount":25,"unpackedSize":61661,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfSaxeCRA9TVsSAnZWagAAHPIP/ie5gWCStQv2lXPExqXi\nUCrUDXh301ftgceux46X1I50Gzk9+CP3KHbGieyM+wtUWU65cjfWQpT+sFjO\nctv2++6FBK1z0TjEMyoX/hla19X9/gRfSMvkpbkKleD6D5ZiCWnGXhCL3UTT\nKjMR8JMQdrJ+2QJy0m9/G0WIaowuZI0CK4i/b9DBXgWUEcqKn3PZZWwmuhtz\n1jBoWC2Ltd8CXeD2uKqjnk4s1A/Z8xX/4eDW4VSKv6jlStCKzJEKAF2fuPW3\nPh38IxjqyObhMfHOtu7UAFPrmzq8xl63AitPZi8aRHCMzOVtv0OOtYekUBM6\n9wzpv0Uu9+pi3KwPMMPNii7gtT63+lx6sb2HHFZ40UZUM/flj6MkC6+M/p7X\no66CJDjnSICyC2DJ3lqq+SGSybinCU9w9tK80YqlewNqBe0X9hdAVu3s/ehA\nct4AiaWvElt0dsnrh31Vy56iZD4CJUE8flZwg4p4WF5RRNfKu2+n6cq1j0GL\n20heCmpa5GuOFJRJ/ivw/wWguAHGVsuKbwICNbyfX2VKmpSyohw6ir8/FZyx\nDbW+mSkEcaqCSCTzSTtw8fwFMKgy3MCCGs/Q5YPqJK/NeNlJxb08Zlet1fJF\nz4y7vtd9isJ+AbyCxPHPuneBbzDbewig5+gIacIlAHlTIGLGKGKHEX/IIhG7\ntiA+\r\n=1PY3\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIFP9thpA+87MvX3n2PVceRnp0ytYUbPfsyF8pJL6H6scAiEAj0vIPnu+VfiGOOy+I3QLTiMr5EyTEA4tLtv3LcQZlZk="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.8a530ea.0_1598663773848_0.45539816537151"},"_hasShrinkwrap":false},"0.0.0-canary.3915f48.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.3915f48.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"0.0.0-canary.3915f48.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.3915f48.0","fusion-test-utils":"0.0.0-canary.3915f48.0","fusion-tokens":"0.0.0-canary.3915f48.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.3915f48.0","fusion-tokens":"0.0.0-canary.3915f48.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"build":"npm run clean && cup-build","clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepublish":"npm run build","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.3915f48.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.3915f48.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-TvUVanmjox4em17IeRA214OxkYep7QfVTTFy/nBv2Q3FY9OBmtKB0fwFgb5qudAGpib9G/rGGLVYcqq/ysKEew==","shasum":"3b7273738f9277b8bf2559d94f96ee370c77993e","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.3915f48.0.tgz","fileCount":25,"unpackedSize":61661,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfUq01CRA9TVsSAnZWagAAzxwP+wYb4Lg3nyJ/Rz2I/8/e\nKx+h9vOELzde/9PHapc4nVNNwmS+724fSe+l5C02Cu60sxaXfxK3/gJtTQZ9\ndsMe2H4guIYv0xLFIo11Gu5tcNl7Lup/ML9AxZUJyYbiyIMc3uDtMoDndGHm\n6DKFsWaCDE+TMX6uTND4tQNRUaf3z4cJfKdgUzXn562BwR/OYD4YkrV62550\nAyMA6Zg+PT5AgVQCZzH5eJl3xbQc+xiXuS0NUYsr0VzMooIB+Er799EBYv3u\n1t705Yu9SEJqi2pBJSIxkSWdug+sOdLi6aXtFmOsoJyYO2MEb9e8o6FMkEje\nLOqkjsVDFBQNVtss1HUqsxgITFWWzSsJskDN3Gb3TMMVw6Bgi9U15vHyIZ5D\nLi5oN0DZ08X770xvsK0aExADTEI93hPfp1Xgr528Kxl8Io8tcE8jlFjuASHr\n0AojLabVgI4+Gs5UzQlan9/IcR3Znep38C6dYy/Qri6UvgLk2sU/SfDYN6in\nkfGati+h0hQr2ik4qocy6sWDs5grlnDXXduDmA5x9IEDNuWvj72suh0QqIQ/\ng0ucEwmgGKG3mrROi3Xqz0EDHl6ZbpRNJ01y48RJvjYzruqantRpE2Nx0G8o\nUnzUWW2oLgzRIRDiuh6h5GATKRHloB3z2onn0VTGoE1Ni2fpeAh1jMo05b+8\nMmSX\r\n=m3XO\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQD+t7TuhBa3n7Yx6blZy6/Kqw5tp8pSWLeUdb4VzW7eVgIgQpaRX0sqs+1Q3q0aS5ltiDH8yFBawF9c+ymgqXiJ5jw="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.3915f48.0_1599253812681_0.9041868979292584"},"_hasShrinkwrap":false},"0.0.0-canary.b3c0cf8.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.b3c0cf8.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"0.0.0-canary.b3c0cf8.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.b3c0cf8.0","fusion-test-utils":"0.0.0-canary.b3c0cf8.0","fusion-tokens":"0.0.0-canary.b3c0cf8.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.b3c0cf8.0","fusion-tokens":"0.0.0-canary.b3c0cf8.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"build":"npm run clean && cup-build","clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepublish":"npm run build","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.b3c0cf8.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.b3c0cf8.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-NEN0FUpizg1jXJ/8ENnVLXyy2hEIsdkYTEu6IV4I04577q4w4PDhw4LU2R90VxWSYUo6fSlxRyd1Nxh1qC6wOg==","shasum":"7b3a44729879e547bd98e38940579216cad1ea84","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.b3c0cf8.0.tgz","fileCount":25,"unpackedSize":61661,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfWRNFCRA9TVsSAnZWagAABxwP/jnJ6Yd1CNib5m0d9AAf\nQTIp6zbZPz97xu9DZjeRc7fYIQbnV6aeigHJ1u92/j0+tF6M84y1D8IhGcRG\nVq8LvQFcLETepiCSHlbDKd5+ik1iJnAjV8WX3okn1je43L1vYgakB/OvKoKI\nHsWBUBkFFU+A/P5lsOlhIyhpGsrriNtfrZGoV0HCuCoG0LwsVRfsWO1hRC/5\nfa65ywxChLt0G+4Phq2pCGgi4kgcT7t7Fer9lmJlN7LT+88B1+VZSrIF8Tve\npPRlRFDEUXmhqC3o5jV1WGHAbZz6b2DD6cEbagpxpZv+U87CLFlnhTid5Nq6\nae+Mrqe0OTGLm7oP55XtIbhftZ9Sa2mOk6m+uGdmotkwuLKjGF2Y4+OAVqky\ns3kLMFaOhdPylIJoKLnROTxaZ30MAhRJ6zVSY2eisU9uZH9xXRCpW1jDo7T4\n7li6B5G4marZfV3Z74F0skoCE+cHaVYZA0Kudsrcq8WvowXdOUgNK2E1JdqA\nn3jbEXTQJX+mdkYvjVNJ9mgPRviD6MZQgC6fb1pbEZ0qKrpcWBY/rkgDWRZO\n0A/qvpVAm+0n0P6T504W0rGhG183JDdB/3WOCldD4GYbv2Pz7nVNoCb2HcDs\nitRoVOUvZhaEbl7qtZz+OtXtui+zaqfIBDSSskAtqSXLez8o8nCEsfKWEnbf\n81Uu\r\n=TZbF\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIGwwLEkGoD9jBQED/RFuG1BgaaaoVEtux6KZggCqNYiqAiEAzOZCxio3TIOB7quPnmUsa/Q5TdU8Ey7E+8PX62OcR4A="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.b3c0cf8.0_1599673157004_0.5670970961684427"},"_hasShrinkwrap":false},"0.0.0-canary.42048ff.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.42048ff.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"0.0.0-canary.42048ff.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.42048ff.0","fusion-test-utils":"0.0.0-canary.42048ff.0","fusion-tokens":"0.0.0-canary.42048ff.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.42048ff.0","fusion-tokens":"0.0.0-canary.42048ff.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"build":"npm run clean && cup-build","clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepublish":"npm run build","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.42048ff.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles csrf protection by adding a server side middleware that checks for a valid csrf token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtection`\n\n```js\nimport CsrfProtection from 'fusion-plugin-csrf-protection';\n```\n\nThe csrf protection plugin. Typically, it should be registered to the [`FetchToken`](#fetchtoken). Provides the [fetch api](#service-api) and\na server side middleware for validating csrf requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This plugin is generally registered on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.42048ff.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-JR85ZlysYFCwEdMpIeydLU/mPHcrHIuYEtv0skZk/CUGQc4XQ9lg4dxyT/v0JTBBglQuxxK5zdvAGWwEdkewWA==","shasum":"704fe110c9393561aacba0503255e8d7983d3664","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.42048ff.0.tgz","fileCount":25,"unpackedSize":61661,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfWyerCRA9TVsSAnZWagAA8vwP/28WgwUgWeID6zVN1rdF\nMds2qui4T0eZTRV6trfQ9V3wv1bb8N6fyk5ttPXA68eIOeYGLDB7L9WCnX9/\nPPLjPKwE/xzEtA+LF0aTkE29LZDGQVzlAoxYLKpJEj1dqCFymYeanYr7dNv9\ncUPJwhpfWboWLMwNUfok73VEGZyJMzJb8qo7vRfXG2P5bJUFFQVu7gCMWaNV\ncpu5VpEix/pOg4doM+vRs7gusI7irxOdx5mgl0tbVjRFoBDKgffGgcxAQS3V\nlj9EIgHQbvnpB67O7byN7XPAFonvd02mVR8glIYqkpwxLu5QWbA2iKgacUuH\naHUL6F4OyWAxo/UQ+Rb2pY47+BWXCQx8ElK1LHGpXboStPzWF+UEu6fodzqP\nsmInmNbhP/D/VjGPVgqyjcWsDvEgHtD7ixB9K6+yWCCpmZhByEb5m7oKp83d\nwp6ozgakjPKb62yLMZ4t7SBn64DWTYIbcioBxuICnMy+HutKCt1Q8ZiPyss4\ny8SeQDOiRp0MmrW//38FzIGf57dJSXYwT3ksU4Y4toCTtLHtJHMyGXwJOUFF\nql2DUhdO49qGAXKc0Hj0+/iGZEOl+hFAASz4Y3E19JDRtFD4RpMLwiWPZjhH\n1139Vwirzjd+F649RurKoNAKFgoVjaxyBsXThJ/ELmM+ccfQq6y2NGgi8+wW\nBcmz\r\n=NOpq\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCFivZ93l6OWZ8TDyfVGoRnLkSmASVCWNTDh5dUA68f8wIhAO90kqcrKlO0vUVF6x3Ff4EILmYFmSFjYba1c8R2ZOWD"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.42048ff.0_1599809451351_0.8820377148088077"},"_hasShrinkwrap":false},"3.1.4":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"3.1.4","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.2","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"2.2.3","fusion-test-utils":"2.1.4","fusion-tokens":"2.1.4","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"2.2.3","fusion-tokens":"2.1.4"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"build":"npm run clean && cup-build","clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepublish":"npm run build","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-3.1.4.tgz","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@3.1.4","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-S/ZfXIO8RtyO3suFxwfNAcT6Tz+gmOKvMwxE64GE2shepY2RzowVS7XTZi0abjnzxAOR9Xr/H4wEtgvQTV4yWQ==","shasum":"3f1b8442f91aee9e76d4ccf32cdb94dd20d9bc92","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-3.1.4.tgz","fileCount":25,"unpackedSize":61542,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfYpzkCRA9TVsSAnZWagAAIlsP/iqzoedbHu4B0TqcWmZg\nJ4qqDX+AvpsFoQJpeMrFSMyw6YfFrDaDmq0nlvSqC9CpYYbAbmbdQYS3+Xx/\n8GYzypb+VtCEyUcnX/u7ZlqXJcu8KxUF2Y6aEJWbZd5Ur1eHKt65JJwZSJCa\nTYZXisX6pqvX9gsqxM66NHWQ0RN8v3dVqLSR16u6J14C5aX/Gy9bhWu6iyAn\nHXQcdgwZX+odKlKUixc4IV8xtQNmtllxzUMi/vrKokPMHmrZEfOpFNOLRO2U\nBMQluEnb7DkfBiMhSylRm2o/8VG2LchikfzwOUGmy0tm0BsZ3YCdbWjw2+pF\nrXbU5CT9/CPjzyPeSbUOdchnNiWbXxkYGRJbKCBw3TzzRhhigcacTEYO5c1U\ndPKi0mzgbCiCJh/hF0KSZpYZBgzEMxiLUBmeqdUHosOHViFo64uGFiWnNKdx\nQDwqjwMgczoG7p7IK8U/7AvbKGJ2ODyaXDIBuO+OgunRrjTCn4GmFwB1p07v\nq4z21OGtztoklFOF7C2H7a1uhoQQ1DNIEOCi6ed4psRxv5D9UFjlUk7j9Efh\nXXURenr7+TmwAEA5CWlDKFPDWNNYuE4/WFBXKY6BmIyMm0J4bygmhYF9d014\n2QaVAI2GL1SmIjkVnh6Z+Ia+SnrsTWN507oVe8pSQmc6esXZGs6ZLvW7Ltfz\nE+ur\r\n=7p69\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCICh5zppN9Rz2UxjwGYGY44c+6lYMd6BIXBq2Gu7Z4wasAiEA3gGAaFTzpBZBCyCHSEHVFnRMcM7ZdCeNbtqMarVynbc="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_3.1.4_1600298211951_0.912738463312118"},"_hasShrinkwrap":false},"0.0.0-canary.a457e26.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.a457e26.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.2","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"2.2.3","fusion-test-utils":"2.1.4","fusion-tokens":"2.1.4","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"2.2.3","fusion-tokens":"2.1.4"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"build":"npm run clean && cup-build","clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepublish":"npm run build","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.a457e26.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.a457e26.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-VXt14DRHHMn6eYDtjhDI+XuSHCW65cpM9PQJ4UZlD+EBAR4UAIY1swjFxKXdDArIxpVK8mCxWl71e/OnrXrZbg==","shasum":"9c041b3fe1f55209098c066070ac6625c26f36a6","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.a457e26.0.tgz","fileCount":25,"unpackedSize":60061,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfZN4YCRA9TVsSAnZWagAALiIQAIb+QiX/FcmaY1Qnf/JJ\nMxbk1c12fEgzxqHwNxcHrEmDDe2ba74ge17jL7DI5OihnXpm5GBWiaGC8LmR\nfkWsWv3sAxRp3Qhu7zEPeXpZfpABm9K2tONrtKucxHkujPSqastxNxD9UNjM\nv0Af/Wt98wtok1WiCB8jGmMuuDyYdYmnDCU9ffg5cpMy6Y0KOSfsSjNCKQ5R\ng3/NjDjDSlbGKyp2Zv3wFvnuH3ar7jXtnSiF75g9/N9jtoYjtq14E/kCHr/k\ndXqRaNmO70vLxpcur7Ugq0iXfSE4MqHg6Ga/wm/g+Ej+KCSpjKxLljhB++pu\n5J/J9RFzEBzYvTiNqu2AEtUhddnT72R/NjLWuQjMBiNK6EEOxcusKvFhqNB7\n71xuOLjlDjPHACWXFbn9TmFGheCTfv1p9UauZB0032D5KyGVcm/kKOCrC5xe\niOSOfdAhG3bBlKO73iFdGki6kTAnurNcxP7DPf80YEgT4EM0Ve3hiI4XixwP\nyvLeFaQ8tBUtzAaFQP3ICF8IqT4HyDwRjgU5RtZyk0u0etQaAL1v2qXO46ti\nny9LjVp5MXrTgIzd+HvKJirwFmRm0zXZ+n3IehhLxZunhBaUle/s0zEvZVbY\nl0aRvlsTLaKzMskBD7svmetyomAx/CYHouI8QgYcotKKqelRdtXDY3VojLGR\ne5y5\r\n=207U\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCoqXVCRjz8KI9CkB21O81uUOtBov+2fKQEbJcsIWe/cAIhAPf9PDePBLkhbZmoIy2W7Oo3kmmE1gHxT+/3uz8gyDkD"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.a457e26.0_1600445975611_0.5146703160334043"},"_hasShrinkwrap":false},"0.0.0-canary.a457e26.1":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.a457e26.1","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.2","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"2.2.3","fusion-test-utils":"2.1.4","fusion-tokens":"2.1.4","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"2.2.3","fusion-tokens":"2.1.4"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"build":"npm run clean && cup-build","clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepublish":"npm run build","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.a457e26.1.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.a457e26.1","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-2mD8l8XVNoigAHDl6OAhhMnXbu0ITqfnhYXreJoFQEaL/ieuTNVP5Nuf+sGUphw6xhLICpf1VJnp+D1CEWP4mg==","shasum":"c444f84a28e2c62af2d32cceb056a70ed2507d96","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.a457e26.1.tgz","fileCount":25,"unpackedSize":60061,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfZN99CRA9TVsSAnZWagAAje4P/0UJ5m3Kb7wxY5kgMOAh\n987xYBRoo0dQbriVkpOBBiKFbXyFR3NIFtls8U0VstPGQwC4+QONmo9VNgNe\nnhnGotaXkVpTnJthtj2flYEbBDCEeZHTPuXI58HbAHGWDKyvxcySdb0fESH1\nicMV+1+bUVUNJ4Wu4q8FnsKh+xiUvmZ3Xp3RJ8xg/YBQpHfvkO8FnhHykyFi\nV7wHIe8Lj1ALPydoSnwA550d3MBoEBXTFtobtl6Fit7Hn9gXEmiHHKrA54EY\nKFZyNaoUmV7g2bseLfb+u9Gb+IoxcFc8mstdFKqvPoWxysBlnMnDb5jx432m\nWblGIMIuVmoIvEq9MtOwgsvcDrlFsc/5+d6NiEV9H+7zO2dhs7u/bqSjMxBb\nVhZaR6gNPwFpfV4Cph0eeF76hpl/GmhJb4D9V0/T+CrLSSrJTHwd3AIVXBl5\nN4pjamht0SYMBxYVgdetPHsAG4Qa8BG3A+OQEZaRdA7FkBHeH+LR1hOfjgow\nU+XW9zXcJ0SMlnMQdnSkw4WOlJuXyiDKH3WvqIUj1FlBnibQqR/ERG0G9HeQ\nuDOxcCiyMEJwVZ53fAcj6jT3RkBrRYV/vTt5lVbKLBNSmz6+kcO5ptWq5fym\na+qMAFAv5tuYLz7RA+eZmff1OShTyljpWIl8vna0F61TZyZj5GWqiDuG4s5/\nH+nv\r\n=HdYP\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIBq2NZGI7kRuJgaa/+hzcj0xKx+aMMlQZbI8Qd8BqEo5AiBje8lku9fxhUS1U0RMmeKMe8zVzD9N/9wb5G5t41YV7g=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.a457e26.1_1600446332479_0.9580440887785022"},"_hasShrinkwrap":false},"0.0.0-canary.877a3bd.1":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.877a3bd.1","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.2","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"2.2.3","fusion-test-utils":"2.1.4","fusion-tokens":"2.1.4","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"2.2.3","fusion-tokens":"2.1.4"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"build":"npm run clean && cup-build","clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepublish":"npm run build","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.877a3bd.1.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.877a3bd.1","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-lrALumt/5hBWGJ90n63G+gR029Ow74oEK8XDPRwAR5VhaKvVYsmyOUTLaYYrzLvE5sT3hv8puIH5VBYsQYadkw==","shasum":"3cc09c6dbfe8c16b1efe3f864cf8cf22d9505878","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.877a3bd.1.tgz","fileCount":25,"unpackedSize":60061,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfZStECRA9TVsSAnZWagAAeDQP/1m1fu9sIWu14ML4kaOo\nVTzOlsZkGrW/4TunxBOwpnhdboK0O4bHlvj/tjeCc7qVvEmdBSIgq0JV4LN1\nWZlfIXpfW+6rsXu0PVA0sayN2e7i0fCebCtoKfGJ6HpEtlZpwMFaRBkS4ZWZ\nRLE4hx49s9n7UQNriZNABRQdHmjIQQoJJ51Ny/FL1pQsUb9hs3TA34yciM9T\ncGDdCJVBQU+/1YKos4RKFCzeqEyABAot568w2OaYfqgZaAKPmgOrfJ+wdsKy\nmtmJ8fxwthECHCUsgniG0mc+zC/tSXVNdwUV/tC8yFPKpvK/HK7U4Iq1WorV\nqzkuD8OUjn2BOUAA2zSBfW9uusYqtuYOA1jdD7uH37e3fujaEdItRfV5+5g8\nfErPg2ov+HNDf8sXf9rWcQsy4FKkq/cfbG79ksdzPO/8ytRkIIJsq3auvork\n11P/7u7hT/+G29cccNzU1odN+LvCQGq7mGaRlI/XpioLz2wMEvOGiNisdOku\njBtEF+MhpQTyL3mFChQaSoZzYjsoteqn28RpdJwKLc12w9+jj/YMz9ANHi92\nAF6Fxr55IihT4wPH7ZimulSs6QHFeR6zUBIFt2K570C1+7M2mCYymy+pW8Rl\n1vd6qgKrotCHcP7cr7F0N1IgRmbwhEWfTz5Q0OxsXjB9fc7b6h70lQxt9J5a\nPWiB\r\n=Hh0X\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDCs3omf+f+irYOllJm/KpuESV9F5MrTjfUckSaU3kuawIhAOND9EjvMo4hWe/mZDsGeRIO7SNR8mdDlISRVs8ifc1H"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.877a3bd.1_1600465731672_0.7269076630392253"},"_hasShrinkwrap":false},"0.0.0-canary.877a3bd.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.877a3bd.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.2","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"2.2.3","fusion-test-utils":"2.1.4","fusion-tokens":"2.1.4","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"2.2.3","fusion-tokens":"2.1.4"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"build":"npm run clean && cup-build","clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepublish":"npm run build","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.877a3bd.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.877a3bd.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-K5jxKxc6B5+vD4ux8rgoSOLiXEOCx3lTdb/a12X1vl/goydWvEFs4it1MDbft7Vva0n2emeuV5Ms+YfZObs0JA==","shasum":"f55bcef780bea841e219b76bf1cc5bcfb6d7bfa9","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.877a3bd.0.tgz","fileCount":25,"unpackedSize":60061,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfaOAKCRA9TVsSAnZWagAAUtUQAIIL3iJWoA2hb9TK8rfR\nK5VKs4hIzwJbQlUzreOO/uG0eiHEhNrt/w2fBgni2eYAm7xY0ikwBNv7fC82\no90xjKMOcABxsEDuJhnUWVnopKAy4tYlHunQKNMP50++3T3QAQmmKlQ/cRck\nlIRVclFyP5Vjur2iINl5nTyY4UB45EzoGTJ4XRAml1jpLMuDnzO2VHtSjGRO\ncXrlLK33vDW9LQU2NfwMMBpKk75TnAe/1G7njURi/ZBNfmp566/5VrOOa+Ez\n474m3F09vwrEvLvtPWMkqbEGV4y5YkaOS81Wz8QnvvnKFU5dQwfQhobKXaA/\nFtcO05REUx8anm17KXgz1jr/6ZNlOx/Gu8+4UHPKQF7bOy97kZ9Z6D+l/uov\nZN8uk5xRJZ3ZIzngWDp2Pgyui+n2vAF+9pPbpcbB98oE/51HJNGLHvK6m4vY\nHlAtOarsN8MLRUaQ9CrDo0W8YBjGNh+NPEm3iLz9qtMNe3VaSFvZ4JqlfGSo\n06sJotL1FOekqjnRG4WaLl5ekSxO1Hv/2FTJO5cq+QeXLKmPVyQvI9IIrGRG\nsHY6IT68nvoOdgqK3juMoMoPDkFdDKrW4QFAUY32gKMHrnFA6iiolrwVU2+C\nMlgZqnhPMRSrDcwhcv/3N3cRcvQlB+o4M+Xkfm89PulzGgoeXYX7rxQOH+Zm\naKtZ\r\n=9QyI\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIHDJofuNqAL2CR3ZDqDDYyRoasnHHbxEyvoefQOz15KyAiEAuMm1StJ8UuOLH65trlt75ahYbGKHYSI5lQGpVbcSSy0="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.877a3bd.0_1600708618175_0.24195072630261416"},"_hasShrinkwrap":false},"0.0.0-canary.4c67dce.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.4c67dce.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.2","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.4c67dce.0","fusion-test-utils":"0.0.0-canary.4c67dce.0","fusion-tokens":"0.0.0-canary.4c67dce.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.4c67dce.0","fusion-tokens":"0.0.0-canary.4c67dce.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"build":"npm run clean && cup-build","clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepublish":"npm run build","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.4c67dce.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.4c67dce.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-a2mo87wFbEm+zPwYOMsKFiibyw62Ug350VpLS80Qo6jf2cHZvgzybbQR9ZHzDYkS9WmUFvXNp2divQsl39+XCw==","shasum":"58196643a56524e22b84bedffbb249a5fa75d7e4","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.4c67dce.0.tgz","fileCount":25,"unpackedSize":60146,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfa7bdCRA9TVsSAnZWagAAZWIQAI90giV+bRo/ZrCkGEzT\n70YWDNNnP9SA0qOFv73Kf2Sa5AGYPvccx5gCVP9vQm6CXXsBNZRYTJDQ+pwW\naEFwBFa4hPlBhZ4d2QN6+NN/JrSgwKkkpn84bcw37TW9qCIjN82NwLQidNHj\nIhVYZKX4YH4Y5wMQEvKZXVMp2ghPuw4Kewk77ugP6yCYbzZH+clhL/XhDtqR\nCJHZCqw8ok+z2IxdwwM2zdfxOyxddkjP+Au/Rgqi199I2Kz8RsTrnOa4ZtGs\nyQbqyFoE3b4Th+i4b00o7Inz7JQiDl/1aE+q5xW4KRgCl/D9fI7mEyXuUKdR\n0nxx5o/5yC/50IyBcyC+PgGwLCdHS+0CHWYNdCoMcmT3M+I8NG9B3dC8FC21\nbTZON/B5/4uMyz52Yhk/HBpBobmG39MS9zZwbdDqDCNdcG8Xq36gY/sshFR9\nR+kKkOv5mv5gKf06jnyJBbbrOHoWS/WhJBE5IIfZWNKYJoYTP05ZGhwA6PqL\nAhbssBnfHg5DKCN0kl/ioYbTS4qmHVFZtAHtJun5Av5Ue/9lpMINv2FzWyej\nNSpjC9RwLxzh0qLKa5kNFYv63PBasJMmxYVcaoiuwcF+tspRhSehcaYE8hDm\ndiUMpV7MrQOz2ZY6q5/jyELYb0sQQIUNGPyT0rlydm6EJqC87RRgx0KSnQ7E\nIaRo\r\n=cc8w\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIFXKQR/08v9Gc0YMwbI8yLuOeAOW5d7oQx+B9R4xyp00AiBOMUJrSFLg5If8lWkWkx7n8ctgcLMsWpA4Kl1kay7ucA=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.4c67dce.0_1600894685153_0.4869429356567716"},"_hasShrinkwrap":false},"0.0.0-canary.ffc634d.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.ffc634d.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.2","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"2.2.3","fusion-test-utils":"2.1.4","fusion-tokens":"2.1.4","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"2.2.3","fusion-tokens":"2.1.4"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"build":"npm run clean && cup-build","clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepublish":"npm run build","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.ffc634d.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.ffc634d.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-r4uvRerYsyhItbWF/niSug+eM8mV+lovHjoh2vVS9vBcN6Y7JtHwC/9/5S8kjV7YiYMepsO6fJ2JbprPdwkbYw==","shasum":"774d6913fbb7f7e7fc7af072e01f6cf75fca21ef","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.ffc634d.0.tgz","fileCount":25,"unpackedSize":60061,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfc7O/CRA9TVsSAnZWagAAbE8P/1BbXtPF1GbJLbOEQLCJ\npaT9PYUM6rFb4CNYPE8gHnQeob5Nuan4VIYL/9mnDGznl2vUPkE3uFL+TTUZ\nol8CuxOfdlbAI7A8l+E37PfIDDhtbKK1pSGitsD3IAvRUcwThhGXnuQ/CoUR\nt9FcOKVpOSyNmkeidARVBPSDTS5kQOOmhs3cnsjf3yX9Gv1yMEAKHxe6uzyn\ndhog8O7ZCxHDO7mOpeHwVxiBJcr+AmbXZeTlyEUOF58/BS2ZS6RBju/pJaGd\n8IHk4/NjtcxjslUUF2Qwe+uKngZ6CGTJORTsV487DAD3hU0efNvHLeG+2xxz\nJ/t/Mf5y+o+OZI/LvgoTorb+1r4X7WXfg1X3AT48tIeFcc71qOPqvihTJbk7\ngF61nZynbrVMsezK0OucYYzECczADMsIhPZ/uay/YXtww1gOFaSEGu/wOU7v\noni3um5jd6V9ZSjBp1PnrxisojkCfKWFs1E+mfffWqsYnRjYJ+TuD8U5MFqC\nkgH9pqpRPh+K20NHoOLJ3TKYloqT4OArk7xQnTQpYdaN9DOW4XpjFbcLHmwo\n9a5TZvKDD8oFLNuVrR5YxPyOnY6oyLDay7xtAK9j0vpWDIC2tv5DV6GDhldj\nefFuMDIO7GymHhCwPEh6GOLte4ohVrMGH8mwlKJp0ZG2/hjHZobu5OpYHlH/\nEM3a\r\n=ajdg\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQC4tIK2yAvQbZklRUYU0N4zGUs3R/ywYrCzwrajl4zIPAIgXXZs0OLTN+fDlkVOa9gKxIdI983EIhAqoVOMFeCPtJI="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.ffc634d.0_1601418174389_0.19597364964385822"},"_hasShrinkwrap":false},"3.1.5":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"3.1.5","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.2","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"2.2.3","fusion-test-utils":"2.1.4","fusion-tokens":"2.1.4","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"2.2.3","fusion-tokens":"2.1.4"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"build":"npm run clean && cup-build","clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepublish":"npm run build","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-3.1.5.tgz","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@3.1.5","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-e7JJvBO780fq5WGygVgJDwI6qO7iQOFEYsKZgHDpKIe4C3At0/4e6n93KHFKJELiwLtKu+xNI0QX0NFSnz73Lg==","shasum":"4095b95399e1157a469994110f9dc09b43033133","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-3.1.5.tgz","fileCount":25,"unpackedSize":60044,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfdOhQCRA9TVsSAnZWagAAPW8QAJb6HoLxcyutWGrXO+fh\nk0mzaqWzaIPqEZxQ+hvwNuLsY4wVPlJYuRSlpKBdU55DU9UUyXDZoQrKPmAC\nzy1Dmp7VTwXTFm32CPtJ/GW2ZQY2ADIJz5Dr++n/13q2BRUJyhiLPDRA4UO/\n+5W10rzzGm26bzhZEW0ymeUDbined7syiJNO7I6MZ2cBR6Gv+Iz4n+XST9l/\neu67OrtDYRgni62TknuC/+D2JwNMMtw/Hf9So8MnA+vpZKPA0tmW1i9BVq0X\nlC5QRYoFf47JvSPOMl5EfrQXrYSc3DdwSuUjL5hHe05WRusew8akv2nx6yaZ\n/9/gtEXNHbnqeLcNe0UBi/pimX8EpxgCbn+Z2LmSPcm7vBy/k15FDWOLH41C\neTx8T5MbczmX015bgFywpmg+ccxxuzsbaccIBF8AMmhAzRYgtAOJLobHzHpY\nQaKrpxgPyEtIGSuuCBbP90DvrnNoTI2P7/kcUIRELr2tmqqWcL5HfaySebyB\nggPwbEMRGxeR2NcqfWCsaRYV8GD7jOLhbgaT08yI3QK/R/NkyIA5rRBsdm4T\n4d7Bv/DPoeFNxwSjXpzBLyJ8aXaP45m7FJFM7aen1R4U1VlGXJhVHXX/Q/VG\nYRFPHv6Gd5ImPGp/lE+ox5Q6TiO1Tu4OtxvR+Iwq8hf3623CrVBTcBWP1F6h\nVwmI\r\n=g+On\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCSw4TM8Trb8/hnol0/3hy+/85DCTsghY50iutzr7emxwIhALHR4g+ZI7OqMNy2mCetD+LUaKiBZBtWsuFTFzCa9t3F"}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_3.1.5_1601497167709_0.5986216028906057"},"_hasShrinkwrap":false},"0.0.0-canary.4123cce.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.4123cce.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.2","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.4123cce.0","fusion-test-utils":"0.0.0-canary.4123cce.0","fusion-tokens":"0.0.0-canary.4123cce.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.4123cce.0","fusion-tokens":"0.0.0-canary.4123cce.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"build":"npm run clean && cup-build","clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepublish":"npm run build","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.4123cce.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.4123cce.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-Pq+KabMFddxM2PGyNumWXUK13IJtZUS9Yyg6yJj+Ubd6wNyfAatDjS6NEM/C549rgPzxSdevLrCyVtGX8Eu09A==","shasum":"735ff4c41132b91c7af6b379c5909ab74f9a8252","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.4123cce.0.tgz","fileCount":25,"unpackedSize":60146,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfkfI7CRA9TVsSAnZWagAA9K4P/3A5+Q5sbfVcY/DicDrM\n8tTv1OGji+DTbiTRIZBrPL9AhQ1QKTZ2QPguHRY5VP3Mg6eQuAFQw4CkCUPs\nuNSt03j6bBizaSuVWwgNfhqMFWFdb+2HsxS/iyxxcZvw0xo+g7wuP5J5K8hh\nZRLevtMopJwMdx0/OKJWoh5GEp9tlPjGXrGN/lFfU4nYIXmCubMHNA53/DEu\nZn+Hg5m0eTof7G7TJKCNB2daywodA8t4gIV2L764J5K5AmC9kO1adSOhBlBj\n3AcZlEcgOkoxR4TuVR//AQhGjrpzIG7jDmq6WW+e/afgbyackHcbCDneiGmE\nrfskVt3+CofpIAgQRW+JWcJ7JU0wS0ADmG3iVtFkrfwVFmYZaWS+cKQTmoph\nXgXkDue86GHB6fRXpJiqh7VX/OIAaINKxUx5FGsYbAq1y51rQREnhnCqhEju\nGYih0EkxtbsEQJao2sW0sHb/4hEc3HNMPdNkM+jvRvMUIEM2MpZt5HWs5US4\nwktMryIoGr+3khDgIaXiC+IFQyLjdVK2NiBMKLcAw5ETaMSm3gZeKxlSv9BK\nFMsjg6IHv7HUe1zPGwa40iSYqQsI1TSCubBd/2wQVfZi8Vdm35yWqsZdbLCy\nyT13s+lNbBwtB/+udV21Ebcb9YCYPyBAq1DK06CiOr4peqr6ju2DW4xvKe6c\nC3+e\r\n=CtDl\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIGOBbYmmFwd3ShxtnHRJxhn+6O89Ax6tiFQ/XJ21B3GIAiA9jkvONz5Cpdlhqbb9HIWrsqHcrNZKcWGOizIg+gZ4+w=="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.4123cce.0_1603400250869_0.5752635293924295"},"_hasShrinkwrap":false},"0.0.0-canary.17e330d.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.17e330d.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.2","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.17e330d.0","fusion-test-utils":"0.0.0-canary.17e330d.0","fusion-tokens":"0.0.0-canary.17e330d.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.17e330d.0","fusion-tokens":"0.0.0-canary.17e330d.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"build":"npm run clean && cup-build","clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepublish":"npm run build","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.17e330d.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.17e330d.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-fuWFmaBtB4mIsgczq0UADJZ/M8dzlkQjAMv/Re2o3bJJvLuoW56O2wxd2zQQEHqvGTmiey/98bXRMijit1Cyfg==","shasum":"cf6ec2af1424d718455285d5601822f0a2b50b01","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.17e330d.0.tgz","fileCount":25,"unpackedSize":60146,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfl2b4CRA9TVsSAnZWagAAntIP/0JbKDwj1uGGG79dtxUd\n0fXDaegk4BqwKmFFkAJyBioM9KCvPeHoZA4Te1AGMtwgRss19ktXJ4Ld1c9t\nEs0IwY50kD/LF+zfN1/rQbaxd3uJfMR/ajH4LxIvbatHB/+1mRgbqkHpKeem\ndYbK7zwiTeFupMQs25Ket6OvIzINO4Qot5MIgWgcZEPF+py1eTXPSWycLgii\nxR41p6w06mMn7oCqJ4l4eKo3SK8eELBdqFT110zWkLDcTZ/wacETJjd/0yDK\nwAPzthYMmSxlNpZSOlsOT7XUoVDVASB0ZHiohsQZ7gPau9MZX1oMT/OTuiXi\nb8GwWC89GxdfvOaxDWaC/kRcrxHV2VTtIJy6LTeDKGLy9EY7EIH02wbxbvOW\nUERanCNl2goNfcBUEPTN1UH505oKJULPJXTwdogryIKSJkWltdXT9MyzjPfy\n2ekO48K5315RT/ndlbscMMC7o+w8H10C3c1X4o5g6AnBJS7uYfbIYjm/9WEO\nu9cbjw0LG/bhNi7zbV1XMOHewbivjc43HRoHyL48Nc0zrMRYaSAZBxamn/To\n6cIzA3fwQjfN5Uz6TI5IXZM9Jjvf6VqWEeFn3fry92e457lUdfM2Mr+pmhZD\nG7976f59xlBLsFNdus6BDX9RTOBHpgbiLYrAjYN4spjqMBKp2QiTJxA4/nMM\ngynE\r\n=uIrJ\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDKqVfbNMSr2XiAOe0MUItltbOo/JGe7NU7Jv6ILbR0DAIgESbcWDHYAn2tZx16AeHX6Q89p+Vq6TW4mcbH1xKqefA="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.17e330d.0_1603757816127_0.4665039936231776"},"_hasShrinkwrap":false},"0.0.0-canary.318c08c.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.318c08c.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.2","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.318c08c.0","fusion-test-utils":"0.0.0-canary.318c08c.0","fusion-tokens":"0.0.0-canary.318c08c.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.318c08c.0","fusion-tokens":"0.0.0-canary.318c08c.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"build":"npm run clean && cup-build","clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepublish":"npm run build","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.318c08c.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.318c08c.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-Wl6zcx0UyGdycV4kND63brlyOKabJDsNNMn7UMGvxItFYUW2rsokverUkzDq5y+v99RUZUlkzjK4TZwiyNYsWg==","shasum":"b55d944bc757c5fb808c171f6561de483d30af51","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.318c08c.0.tgz","fileCount":25,"unpackedSize":60146,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfnEm/CRA9TVsSAnZWagAAhokP/iIbyApDjvltfvfH1WlA\nZarWfamo4+XhvRx7lEI8ePlnnv0TM6ktQVZgZjDXdnrvJ11pGHBawzgTVzPe\npEDz10otfzGv9kh+rMoMQ84BerBucvhm4BBnnXfUVC14eFfumZ5VzRupYqVp\n2+ZF+JTNWfghKjkwddn0KtyYPdL2/aHkMZSF2flotfSUV3GFo65yMkrxSin5\npRhCIadGLl7afRslzpGWMdsyb2gG8v0abkctyQEG2brOiZPKptcStZY9LgZ/\nxKzwFligrPwekEui0l035piQJjYYnrSjlkDtx4CjcwO979zWd0ntKSyO/CdJ\n/FHHMk7QUNEsXPL8dWPEs4B/8UgrXiYUx3E6ZU2zfurBZio9T5Jr/En+jSYB\nWEuoi2QK90/tUf6sZlu3l8R74gffuWcnsEpYZOowwiE8+HEcFbqgzNCzf5UV\nhAYIbAI4fcaMQxU2dmkbmS7vC3EvOBNyWWwxRW2fn4bKmh0qoSzRF/XdJaKt\nEbY9qy3OGLaTh929q7pnHZjw6V06bSC8yrz/Goa7o4SeC6gFnlPGfmC/zA5Q\nXIcDLpQP5O0qt+1IaoTHfzYxHJsJ6dTRt1S/sz5bmK6ZAwZdRsUEGYX29Jsm\nzaIQwu9pVuuaWycPGHmK6FgSnD/PCCrFqkpE1TAiPOAAPZZVA1KP3mt0sBh/\nMsre\r\n=0ALf\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDMSBqfBtVSTkJUG5zQ3J3Xia8XbrOuYp5toBrwBaFMDwIgXk1dlqNkjdq42agiZqLcepdw5vjzVCS5shhaKXHu0lc="}]},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.318c08c.0_1604078015354_0.6014679556350293"},"_hasShrinkwrap":false},"0.0.0-canary.e74b783.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.e74b783.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.2","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.e74b783.0","fusion-test-utils":"0.0.0-canary.e74b783.0","fusion-tokens":"0.0.0-canary.e74b783.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.e74b783.0","fusion-tokens":"0.0.0-canary.e74b783.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"build":"npm run clean && cup-build","clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepublish":"npm run build","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.e74b783.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.e74b783.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-OUP4xPJOXqTuRfr1T6B9l+UG7UDDUArnauYAbyXspn8c3V7+nEIIAzr1UtKPyhtPby9To21OD1o5ww2J2V86tQ==","shasum":"b36ecd3ccca475b487a7f770a9e28f2fd901373a","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.e74b783.0.tgz","fileCount":25,"unpackedSize":60146,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfovtyCRA9TVsSAnZWagAAdH0P/icOXu5Zq7DTZlg+SYMb\n9v21wau0lW2nTyq6MjefPO+6OZCpAsOlGoAHsrM7Cx/JslCAFGwM3O9OdLkZ\nAzz9ET/IbvlQ2VxOBvxn+zHpwBkLQcULMJa3P6CzAncbi7uvVHlWipGDX9vN\nsjiMoZ99Neurg1pJX71bbhNu8sdNwt6XmEKXe94MlOsS8RYlBRl0jtA92lOP\nV+yzRUY38WtiZ5yuY6apiSLJWEEusNJ+vRzOM5EvrI2vM4WmDmszQz49zCa/\nv849aoSlEGS9RtGzGpEVuf8GyIHAi9LQsgdkB4qImYC3ROQ8iNjO5iUbBO1K\na23ZIHJa3J0dQaxOFJwApCGG8UDjEZdVqpu1B43O4EoTOeVAgnXofkLo7X9C\nOLTJQpq999dAM4pTpXfyN5dIJZokWTRC9P7J0mVfQApEufngEpsXPMNfC99h\nc3CWBNp5k0ayt+lR1V1NXNZfPwoLGhzyTSP8iDBs94Baz13aWmeWBxaC9U0l\nQMhPOcDCfLnYKog2N/KmiqeNimUFBB9mXhbEjyfItr3lpa0UmfljA2ZUVYMr\nvfz9e0SFOiBG50K1dt0UCt8Zo1d9xPydVvZY6YS47Wu+kMzvfHKe5u+pdfeJ\nAjVXib+6Y1Q4MgSUqmvqkSy73gz0m5ULNl82ncCyrkA9HRsUd0v1mM6ufgDX\nKTOy\r\n=zhhh\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCgXd20jRZdDatYcJMWCDSEO7qZTD5ZuFpsoa3Ga5tE6QIgfS42l5TGvN49S93BARhLmTDz+gDIxO36R4UtzEO7f34="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.e74b783.0_1604516722509_0.8436004581288394"},"_hasShrinkwrap":false},"0.0.0-canary.a33a9c8.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.a33a9c8.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.2","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.a33a9c8.0","fusion-test-utils":"0.0.0-canary.a33a9c8.0","fusion-tokens":"0.0.0-canary.a33a9c8.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.a33a9c8.0","fusion-tokens":"0.0.0-canary.a33a9c8.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"build":"npm run clean && cup-build","clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepublish":"npm run build","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.a33a9c8.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.a33a9c8.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-kAHTPF/nOkVQo03WUofZ9nNkdqAbhOR4iKFj981Ymk3AM4VdfGpSRj7Si2Evt+1r1J5jY5BRWKEv4AqdTOZvbg==","shasum":"6d8d90624d019025a8c841c582a2baf8ffce2851","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.a33a9c8.0.tgz","fileCount":25,"unpackedSize":60146,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfpassCRA9TVsSAnZWagAAw+MP/RNeRZ30PH0EFTATXyga\ntwRdd34xNSLZ6p7fmntVpjERftSyZgPVc5PcStGgwMrAZKb2S8ch9M9+AW7n\n9TyWba+cHqDT9/pnU76KQ7q2ylg9BriHHVkeYy7hDHh8QVhARCqE0UjrR1KH\nSbU6FI9voDOPTProOylSDqk1c9qwbsYu10aAOqx76HIt9p0mP701Skmx96Rt\nf3dBn4zC5KBPnGOwi8pfW9RM6bdGTe7dq00ec5N1yRNjfAYRSU00zbcIorNv\nf/ZVQcpA3zQzGz05pGQRdlY+WLQigPlPH5GRfd1IAiWq5PSE0OONNpEkUfrR\ndFiKJzjs1UkAn9Nkr5Gw2eo3kpgpqCijjdes0D/upxvYf4M/vFRJjyjBO7dF\n9maR029iOv5ldZW1zFdjpzcyziRcydF8xVQE6FDq0Ih2DqwUXDToD+cMmfKm\nkNWb9CN9493HNE+t25TDiz5wntqrQKu72EnwPbjrzCKnNdl+4PuUWGCNgVDC\nLXwLC/UuFg4oQ8r0CNSlF+rRwMxxYnqz1LSZUJgZpRhHPhUqfUPiwQtUNwqj\nh2Ko9KNNrW+DapSatsYg2+sT3fIeGN+lfjiK04+qIfX1DYx9kkzoHEajfVMH\nL0m72z/dYtc5ZoGOUeRN8RXwuVO0eEMaudwTZ9np2dstr2RY07RiHnYK3tjI\nYq+I\r\n=vKZl\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDXm9FtxVJiuQttlxrrrdj2+uRobARnjwXB1e66XIR1/AIgdhli3eqSAMKTQq9Piqbw0AMFpV/BEVag9cyNTV+6VAk="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.a33a9c8.0_1604692780266_0.654604848272774"},"_hasShrinkwrap":false},"0.0.0-canary.5a2a7a7.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.5a2a7a7.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.2","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.5a2a7a7.0","fusion-test-utils":"0.0.0-canary.5a2a7a7.0","fusion-tokens":"0.0.0-canary.5a2a7a7.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.5a2a7a7.0","fusion-tokens":"0.0.0-canary.5a2a7a7.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"build":"npm run clean && cup-build","clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepublish":"npm run build","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.5a2a7a7.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.5a2a7a7.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-Pe9rQ50R8muS2vw8CQfs/b+pnOXnUPb1KeCWZ8xeCbqjI9CD4X81u/F/43taI1yrxov25OvDq3Ire9sZQc1syQ==","shasum":"9640569a19c77e1ec84f74882b282065c2b08b22","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.5a2a7a7.0.tgz","fileCount":25,"unpackedSize":60146,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfpeT9CRA9TVsSAnZWagAAfbwP/13zoaYTpAetjQz1w8xl\nwcSXjgwVH81R5YeeQmulZLZazU69YHBb028r9OU2P6YK81ScXuo1+0OMhZCl\n2gMan+MCbHQMSjJBb2LkkObi1vf+6JpKaSV8V5Z2Z6Dej1M4hO5GGhr8sAVa\ngQPMxdfzZvAZOe8tfKafSOjl/bla74ZMGih0ZnOfgQONFiDyFdcl5x9gvIET\nDBcKc3NYEd6oMCNwNF3X+Uzns7Ve60Lf0j1Mu1fv3J6FkOMLTx8p6zybUCVn\nA7yBBtHkEPyha7i48J/uxINuq5rGGHjrljWQbosvanPIF9z55rGqd4i+VxbN\n+jW6tVQeMU0aAuN5gOri2KLAoeqqunpp8T92QCj9qoRASqe0PqTBe4SGEYw8\n1pQs3rnel1bDlEL3gKwbWVd3I1iAUg8ddWLuSdS/DZgMhCnxco+iKLPHyX5D\n1Z72wscaw66JvBrjXgi6lDlgUP8bwYQmZ8DNeeGSe8JJ8L59VRhIBAHve6q/\nJ+kmG5d7JhBXoFrgKNY+Uopv+YtDfCgeGPdo+OrFa8QQxoovkWMnMbwgZ6W6\n3d5Ufv3TlOwUo7uYu/Tf6s2SrelcnOcWcUHtFxwoYL1hInZ1IDOvbYUH7WFO\nmgx1WDxD4s0NqRRP0zRowi6Nk8flIYN8hgDVLLzvAxpsic9egRG+WLR9m/NB\nIRza\r\n=ZLPv\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIHIffVSuw0VRnOq8PS4cG9UryJI6r/yjMUfy0Awbpm2RAiEAzP6HU9hFcjmxEtrZX0Cj+oIoTGRWu6cLgguT/HhmMBw="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.5a2a7a7.0_1604707580704_0.2761785418399576"},"_hasShrinkwrap":false},"0.0.0-canary.77061d0.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.77061d0.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.2","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.77061d0.0","fusion-test-utils":"0.0.0-canary.77061d0.0","fusion-tokens":"0.0.0-canary.77061d0.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.77061d0.0","fusion-tokens":"0.0.0-canary.77061d0.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"build":"npm run clean && cup-build","clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepublish":"npm run build","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.77061d0.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.77061d0.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-E2GKfVx127wjFvHpo0mb/1+11b6AJqk68wlR/zTMFyXrN2HtgI9mfo0wIVMb2j9MKLxzfqs0wx/hOJpcXBEApQ==","shasum":"a562a1c0881a0e965c7d60f55d26f4fdd6041baa","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.77061d0.0.tgz","fileCount":25,"unpackedSize":60146,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfqZMpCRA9TVsSAnZWagAAEycQAJP+opuMD7gUUEos3/61\nlOtdDy74TphvIQytI/OZn1upOUuBFfUa06Iyl+2w3v/me1SOo5mlyYy1EeI9\nU0ae7zb+vTu8UCvzac3EMzlDDCtu02Y5PmXFCDJgpup66xnVsIWKDgIFKKrs\nCEbHhlMhejw5880ZpEMhxn1y3bqIfaqTtqAMQT8kslrr/jDYg2FDwkRF68W5\nkUao1DcuP5CpInMVhKFgGRJtscyMIiBUB2Kh68HAYyL4s8RH+gbvpc2rCW8q\ncAoTltZf+ekjH0s7Ov0OdyqcPeB9E/gyvegcM8zT+yQylNwMWv19/RRxx77Q\n/qSVNQ1HAT86aPIL3AJ2y92HWnlMXlJeQPkDLd/f6RFdvYG4g2LEnCbwVHz7\niKGRVCkZzFR9527jblyDrLPX4/GKmd8+y1tfhmYONAe4ERmlIn4EBv1uQVMS\nP3W1vSlhEMeBH8IaKpLsqMgtZK6kCPS41kxHJcFwLGvSK21FhiI6sAqX/4kf\ngnmv3/DuIBDMNOtqLAsmsxjQ/VbVWxc7dPGeHuE9XTQvYIKrK/DHEYMJsoas\nqq9zbJqG6qIsCB4Mz4MeME9M13LQIPmQSKoRGPBJfnZdFGnIkRGXM8yWRieK\nVdOcBH57TbK0XS9Lnvt/OKx+coL6lrkOFy2/Tt7HqWiwrqlUKpNy7Ni9odWj\nWXIt\r\n=bniU\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCLkU/IL8AWZhmlWo5TouMCYcdi3aB1BJnopehJUZzLVwIgT8c790HOM3dvWGz4PmJncy/fh6J67gX7Etsz/hmCz4M="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.77061d0.0_1604948776685_0.38166512719214696"},"_hasShrinkwrap":false},"0.0.0-canary.89ca12c.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.89ca12c.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.2","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.89ca12c.0","fusion-test-utils":"0.0.0-canary.89ca12c.0","fusion-tokens":"0.0.0-canary.89ca12c.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.89ca12c.0","fusion-tokens":"0.0.0-canary.89ca12c.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"build":"npm run clean && cup-build","clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepublish":"npm run build","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.89ca12c.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.89ca12c.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-waWuaQXBD7+QXV4VCaQkW4bCvk9da31yO/Ri8fBQJYmVPkjWUTpQIBrQzaqfZBv6A9z7wD6BMKhIRpkprlbeOQ==","shasum":"1a767914236e625c4a5fd13d6a2b9623dca039a1","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.89ca12c.0.tgz","fileCount":25,"unpackedSize":60146,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfqu3KCRA9TVsSAnZWagAAES8P/RkARPzaA9CoqvVIWNnT\ncllj6aScahbK8KxL0Mt+VS6bA4lRIvHqeKAiTE+MqqQqh01SZtNbQ04FZmeW\nfEV5gCARzpjGZdLtrIXBSB9zn+bVPZZRgk7JzlRyLfnl6RfgL/kQ+BW6xHix\nokCHTaCXqH8IcTvhZKtMy1hVed8YNigkPBqEKHFsHTPJFO4iK/iM12XIioPx\nC5HUnL6yE6icR/EO7H0A/FMTWIC74yrRqJCKthnq0mmh9hkLhmhwsBIT4Npt\n40c3yqggmrkvpNBV1skE7cbUfxLsJlb7twaoHyFbhtxfipt4qY5bUMj2ZKiB\n5cytSpbuW2MHmDZQwINWZZExnxBREnb+lRDQ/Dd+lAndW0fxBqDNAne5wvwr\nd+JjWfBpZoa7UuslZBw/NW7AZSWLHVMzRjNYF13ewOib7uBemYPxtBocqQ0w\nnFr5DyArvmA5NLyOM4QF+ei1GoGhtYuiXGzJ7Qe7Mm2wwQHa1Bl4a+DusQQU\ntYnRNI9vv83HvHeOSVGS7UqVkggoKT4pRFFpBjaHTxJCb4O1S7Ny6wCENPxb\nDLPsOEyS88ykzjfb78giGhTWgFpmOq1pRkqI9F9o/cKOpRWvs8s/veTC80y0\nMz+OhI4UPvynxn+KpKxcblSaXjrztt2Muxf2CWEUkfAfaR5BCgPYCxGYXdDC\nivEs\r\n=risE\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIGDmQ8RZHobBCAHBfrJ/sj3VC6lKNT/YBaQrxQ0OEu0zAiBdXgVa1x3oH8FCUceWUcfwI/OCkPJqSwsNJWTieMSzlA=="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.89ca12c.0_1605037514363_0.3017110910615717"},"_hasShrinkwrap":false},"3.1.6":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"3.1.6","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.2","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"2.2.4","fusion-test-utils":"2.1.5","fusion-tokens":"2.1.5","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"2.2.4","fusion-tokens":"2.1.5"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"build":"npm run clean && cup-build","clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepublish":"npm run build","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-3.1.6.tgz","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@3.1.6","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-j3CGcDGIcreZnNmfsPMKFL4/nsbjAiOyMvexwLNiXZ3SlJyZFVV8dcScHEsNVsr6FAHVqJ3pTypTvFTG7G47Yw==","shasum":"628388ea8f5b133d75b4dfbe10107126a1c045e8","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-3.1.6.tgz","fileCount":25,"unpackedSize":60044,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfrtqiCRA9TVsSAnZWagAAQqsQAJhvvFkd5MiaiUt4mV+X\nmrggfPjhYvKMBdxmwL958gufNVic9s1m1rUNuB80LHkdpqQs583t+8lnctwO\naFUV3AaeKKXORBYQ3yg2gN4yiq/282w2vtWNKACjq14tiPFJbboTXg91X9IL\nbmRLzpPricL6olGUDdVePqj+E17jxCmA9gF6O0O52e25SyQkKurNKamRCEkt\ne8jVjMIdNwMipgUqV2r5iBhIPrP1SDKXA2U6s/TLIijKLwt8gqQiz/1BrTnN\nRU3fPf8JHmCJitAkvOgjp0wGxjKz/TvXj5qCOGnqU+l6RykZi6C45ckffwc1\nlc3yxkN7zTDH4rOxyzyGf/3S0YhPbdr6BKmSwpR+55ixHcM7QCTNtWb5vsI7\nsKGGNshDKwLGE3huAVq5ttXJy8Zd+O10bk8hIMJW5Xf/rtCJFQ96gKmzZgQt\ndWEuJACS/NdxGi2nVlISDH9JHosjFT7AVvEn1DRWOXE6jevTBfWMXYAerTNr\n5oD35Eh36jV3/ORg+2k0uowc2Xw2M5LDusBXTKb9juji+iwVsBi2LVN7ye2A\nIliAVtiw7YIeRbL3xt966fRKFK5NsTynR3PidcClunbr7hQI6/zQ2JNLLpOk\nTf9BxdjgVaJh6EaziP2LKu2NGdWVPaQyQx8leHjD03BXJvtdhM1tIZ3efuw7\nB8GA\r\n=C/OS\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDKhfEG7y3MKMmi1k/l17MXzPh1k+SBJs8grzWjDLgmJgIgSiN7fkI/D9q6lE003ckPbJxoXb2gvlRmKA0Wo8K6sXk="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_3.1.6_1605294754070_0.4915888149109331"},"_hasShrinkwrap":false},"0.0.0-canary.770d485.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.770d485.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.2","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.770d485.0","fusion-test-utils":"0.0.0-canary.770d485.0","fusion-tokens":"0.0.0-canary.770d485.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.770d485.0","fusion-tokens":"0.0.0-canary.770d485.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"build":"npm run clean && cup-build","clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepublish":"npm run build","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.770d485.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.770d485.0","_nodeVersion":"12.13.0","_npmVersion":"6.12.0","dist":{"integrity":"sha512-99XoXdDEFvcPn7PdZozkAutXXX6QMgTI8am+C30zIOJCpCq51FJ94kQvlIOJcRRxnYVX+akQgqcpDH9jJw0tmA==","shasum":"d9f81293496beecf29c3b5a0730a83e237e8fdb2","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.770d485.0.tgz","fileCount":25,"unpackedSize":60487,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfrvmbCRA9TVsSAnZWagAAqWcP/2rr98LNpP8NH8cCO5xy\nhmzFZazDSM/MEiPUQpZVEVN6fea+x+QPOe47mSqwBtQdRonAW/yf7RqyHHfA\nGzDpr8q+DkysjA50YS/ng51Nwmlu9Sn8PveoNEpidXA8H3Nkf2uZmm45lM8c\n6SBV7Vu3RvRDrJ45Si5Vw9b9We9pUqeg0IW2P/m/CGo9rbBffIMOojkZrlsk\nAoA3Xkr9ogAxUvlLH0ZFxIKAxGnxTvk2V4hVW3eQEMhvR1GmCPP45IRzHGoY\nIk0qFUFXt9PWY7t8SSJHfvtcsF2eEZ+M7afKLAmPjE+sBmYRnEVpGY5NJ4VS\nlDWvinV+fxSO5o3k+RKbRwhrhB/Aga7HAKUN2uiZCnr9QbD3OqAMDVo2taR7\nM1k2VAfx8UF3EdFDo6EFNzVWVro8S5ULnD1aYdqcmd1DDu6ZSKmEv0LhMc8g\nnHuS3jdNY+YInEjZ6+GTsmkTnLx1uZaVxau1Gqwcp6Z2xISC2m/348X0brxD\n+IoHDlr/hJmh3yb5rurj/CfWuUipBitnbPdSuwHZblNCFkKotWpAy9yM6oxr\n1S85omlf4KsRax/cIB7BAFFHN84e8DY8UIZajWdVM52QpWtuX/ONOFlZIytP\n16MpQCGT79ps76nCVKmBuAStEVZr3bNlAmXVeiJwTx4gYSOUBOe1x8VOdY8D\n9rbI\r\n=s78k\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDDNXz8qqthOp9rj6+hrhvjgpPeRt3jYulOwsAPpxuuOwIhAPfexfB5w3BrqygO249kQyW0LqR3nrZ5aj+oEundiypH"}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.770d485.0_1605302682725_0.9563745328714304"},"_hasShrinkwrap":false},"0.0.0-canary.6d664ad.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.6d664ad.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/plugin-proposal-class-properties":"^7.8.3","@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.2","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.6d664ad.0","fusion-test-utils":"0.0.0-canary.6d664ad.0","fusion-tokens":"0.0.0-canary.6d664ad.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.6d664ad.0","fusion-tokens":"0.0.0-canary.6d664ad.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"build":"npm run clean && cup-build","clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepublish":"npm run build","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.6d664ad.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.6d664ad.0","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-1yayUZKoCTbi/VZ8Mn6HWBeqExKwFh2vexlEyZuqG2wwOYtSZT6dFKi72gWYD1imCBcJQtX/mPZkeflruepuyg==","shasum":"bfcea924b324d09dd82f6e3b6d89a000097cda89","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.6d664ad.0.tgz","fileCount":25,"unpackedSize":61048,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJf2o83CRA9TVsSAnZWagAAlHIP/RVb1K9sCV0hy6uez8u2\nxSvW2+bUtY011HbbskYQE1zXJ/JaUuWo77WpJHWCeA5qnPCEWBcHjso6Nafy\nZplwO4upJQJE5TRSgmJaX2VIjUmca+sl9i229InQn4yHFhNG4I/APDT318hK\nPBOfVY153J7KeTrMkYhStz9ZK20R3uuBH0xBwbs2HsHud7MasVbKvAgzW0SL\n+/C/sObOv7pxm4JZUhYV1DvgX7WH17Dh8ruLKc/bKcfk/oTi25LpNaBtZfHR\n21Q5LgWSJdA1T1V886ySOUzCn1o0KVso0Iw6s6aVA1tn0EN3p2qo4jkX7fUB\n9XUw3ioYD57WNMqOi/2wdJ/gL6qYDifZUhqhZaqid3DPVE+WWpyMHePP2kcR\nviLBfsKAEV2kcgWHWA2tUhCAqe+SSM4LZQRd2Xt0bL5qMrvH6XVHTZerCKag\neJxGK23w3uGN66mTdaSO4+UT39Z9WJjZIum8Yh/OJOMFt2VYePtuN4CWGUZQ\nxVYXOX00KDZVk+mXgPfVqpWB5OS1SapTvhRjtXMdMwkSu2M7T5kvxc0OAby6\n47k/K0OhChQ9sS21Ou7IpQHPKwGfoSA9DYv8Y1EMFXaIagfun2sXSpoQQac3\nRcVnp5YsOVkgO9A4m+G121n+S/KY7TtBd4MXKrNesq7qqirRVBWoMkmVREfG\n5EaH\r\n=xF9A\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIQCBVVGimjbqLN64ypOim3EoT6HhlXtYp7ePwW31XwPIzwIfVO3+g8TD81pb+IlCQH4Ob0Jf8F36PIhdPprf/ocFNg=="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.6d664ad.0_1608159030512_0.38611313430384264"},"_hasShrinkwrap":false},"0.0.0-canary.579111b.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.579111b.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/plugin-proposal-class-properties":"^7.8.3","@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.2","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.579111b.0","fusion-test-utils":"0.0.0-canary.579111b.0","fusion-tokens":"0.0.0-canary.579111b.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.579111b.0","fusion-tokens":"0.0.0-canary.579111b.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"build":"npm run clean && cup-build","clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepublish":"npm run build","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.579111b.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.579111b.0","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-hBrg7pWS4X25A7mDxzz/0lAvTlUiX/kPMQ6DKHmeyJ2NXwFFHW9CBq/TNxuoX0o3wVSctpdhrriOlHVCBWXcPw==","shasum":"e1ba0b136e50f935e2d835a1516b466eed2ccd28","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.579111b.0.tgz","fileCount":25,"unpackedSize":61048,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJf2sxKCRA9TVsSAnZWagAAdpYP/jQPLN36EjjhoPtUdUAr\nJHc8AVHxgQWu8ObJOTaDNakp0Rn6ss+sQkOEkL5N7oJHvkHPcFnhr3t5+zKg\nneLMTFcVuYg8yLDrMMPZuS3DlufFzUBO2WXq+aIoK0dFG4Y3++vt5rJFDRcd\nSbTHTLmO6F+XDTXqbWcgeCaJYbpiy2iHZu6qfgcyfzjS9OyMS9casXfBKC7r\n7/fAtrE2xy2DZ6j6AN2TuSPA9o18r4Zy4No+089a4Kr3oJdoUCeSu2S9n1+l\n6bPUB8mEIfM4pormQv+YwXuZihZVTrCLjW4+wr80g8CGVdDkF5gP+AE+EDP8\noRpvuk22B0dlDhpnSiEmRm7w16uuVa5l++kKG9cR23DUka6Q5pRke7BC26Xu\nv3ZSA5CmlEJC4RDx9HBMec7ITtxpU0tpKbJqKLDWooNRVQaHljF/+/5/rJ+U\noBWqCFlQgD8YDpMC35mR3WmQfjCwEHV+p6wrtRM1f02Pb9pjiMK2Yf7rSb67\nnTLLJ6Lz1pP3uiefXEIfD+fYWZp7rbd9r6MT8IYTds9BUJoI/EYjdOYp/Fur\n0tEZZFN7QxtPTTALXxAnmVmyFzZQsFQdvddrMlTo2b4Rj/5t1vk/7Z3jFYj6\nz7NCE0kkRr9WkOwbx16FfUH4wuHUu1l3g2HVTk8+eBVZm+FaGfuQIk4CMio/\nunOu\r\n=ixfo\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCICBbmopozLqjB0G69LW/6apPLaxqe4gExLh+mxlq/+2hAiBveuzAitVnr3RZL/Dcp7GC8XWUPsWGu0VBgR6zzNmjQw=="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.579111b.0_1608174666315_0.7462114318445037"},"_hasShrinkwrap":false},"0.0.0-canary.2eb76df.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.2eb76df.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/plugin-proposal-class-properties":"^7.8.3","@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.2","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.2eb76df.0","fusion-test-utils":"0.0.0-canary.2eb76df.0","fusion-tokens":"0.0.0-canary.2eb76df.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.2eb76df.0","fusion-tokens":"0.0.0-canary.2eb76df.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"build":"npm run clean && cup-build","clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepublish":"npm run build","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.2eb76df.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.2eb76df.0","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-4X1dm7gkjlVD6x/CIuSZqwi4Wer/ckBTqMS31JLgGSHEBrTt22oyq3xBgh/L9P+wEkOlNDqdeJzz6bP5v+2GcQ==","shasum":"db5476f9a42e6576e548aee240f3448939feaed5","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.2eb76df.0.tgz","fileCount":25,"unpackedSize":61048,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJf2tWECRA9TVsSAnZWagAARI0P/3A7C9hmDt7oPGx6mhrk\nsofQxBykYARE5OgVdcrJoyao+cmmw9mRX46tyUYAg+Czqt1JEXBkg/TXzgo7\nlKFtAw23W/pu83mIPBADinjOZjcQXzmCxoMgwq+tM0o0pymfYUluS62wtkoE\nI+EjS8KwKr4f2XkEk8sbj2yx8KS0MSm1xJNJuFDZJxQMm0N6pjyMAsSQlfof\naLrQ5Z/NzVVPlHxfO0kClOWBD4LqTeRGYnQp8bkvCZ9RQmwcDrIAdSuXgZbK\nP+xR5TkZedthFSOV9VhlpsGyjwednnzdD9sB7/pzoyI1CvDLjjB9sYXpIvlE\n0vzV7Yh8aaVWJxKS7XDWHcsmGePEyp9miUrzKmVJhrbyFfYDfjWnCdqojcuG\nYNdd6OXete4htidFLlSnWt1954wS7qdSq+c8+zZi9T0643MG3XUQPyO4/MMg\n7ihfUn5pDwREN2k8oJ/EL++KZ+YwhoOerjrNXY/CPjZZ2NScgHhxW48RjRvG\n5h7W3A6VWEWJEB8bpA8vFTEZbh64bT7PRT1fKbE9pRQkhZXAwFR3oF+UTMhn\nU2NCZtvS0IUgKrrUUVCYPG0rtw3IlPAw0KGf22CBFhcjXA65UeDu974IXw8K\ncg4i0yidkbZcJjpcjWzKyrvW4hrI9CUcg8ihbztDOQeAqsJQyZ/Hg80hpcpv\n8ojg\r\n=Fr7/\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDSPe8HNIRFtiHEmTzzv9kg7qDojD9bIBRdPfSCATeQMAIgHZZclVc5HIz5j07QJu5VzODwEkW+qY7/AuUSBnOSABk="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.2eb76df.0_1608177028266_0.3969513709905055"},"_hasShrinkwrap":false},"3.1.7":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"3.1.7","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/plugin-proposal-class-properties":"^7.8.3","@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.2","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"2.2.5","fusion-test-utils":"2.1.6","fusion-tokens":"2.1.6","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"2.2.5","fusion-tokens":"2.1.6"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"build":"npm run clean && cup-build","clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepublish":"npm run build","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-3.1.7.tgz","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@3.1.7","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-vzvVivYlaTdHj82g/820EBO1ypwSuUenilbaiGOPeIAYthu9QZLLH77rojsATa5zao3eNh3bX8Nks/tPCG+XfQ==","shasum":"e6cd3a8950db9e506f4626a50f0277eed40dbb61","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-3.1.7.tgz","fileCount":25,"unpackedSize":60946,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJf89elCRA9TVsSAnZWagAAcFIQAJ0C+D4IHL2z8wyrlXrZ\nuB248AZTEbA/S7NPKdgQEPeIu3Yj+yq2fZ6n7cV91KdZWJbvaiNWiOSnMq2I\no09Lv49PvdE73w8pPz4oHpCWNvoJguqfLW9KI0LoKF+n3Tc4DYX7wAw6sEg8\n9XnyvGWoFe74I1XTv02Z9FkIEQ33EIwK2joF3hVPo2fZejDVDPwrLbuNt3Dv\nusLPDUsIfrM3qKKHtOag5X1b0gvbdF6cQkJcxiS6R2z818L2rN+LGdO09zVY\nmECtt2zjhzE/sx9i8kQpWkHjSdeU0pcsDWAVCzmWm6bRLwsyc4jLfsig5ORW\nKh/KVjhRWZkM3qJ3m0gHyceua5D7AVVOe/IjjS8fY+T5XUsNfNuZc4TUP/OD\nb/2/TadAxwhssTHYfearFmGUZ7cXui2EYwdqpeQlkI8No1t18wSHu032Vd1A\nTWlgloWpF1u3t0cf10QjgmyDUR1/ASYCmR0qDVAHCwgq0lvSR2TcW4lcBKOn\nVVgu0BERqdGi22OQT9gq85qpN1vjDn1E1wRJS/T7YHM0Jot0mkOW+vo+3/vh\nq6GuIdkjLB4Uz6L1hn1L4a/+0bV4vbyDFm8vZvsS39IWqtw1RKHWSjMuK9JR\nOW0IiDVbFWs2IN4lV1uiHcAA9siX8sUWhPijH6xkn6nRPrjnlZ7becwwZQNR\nr86d\r\n=toQY\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCICkcp6OP9DnajvQZQm1/vEZ45IPojra0nsSLAwxhMVpxAiABynGBcUcs2g1gUzPeryFnTSzCNARRTKWW2OtGrAEMNQ=="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_3.1.7_1609815972529_0.5238842380096382"},"_hasShrinkwrap":false},"0.0.0-canary.4cee1e1.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.4cee1e1.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/plugin-proposal-class-properties":"^7.8.3","@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"0.0.0-canary.4cee1e1.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.4cee1e1.0","fusion-test-utils":"0.0.0-canary.4cee1e1.0","fusion-tokens":"0.0.0-canary.4cee1e1.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.4cee1e1.0","fusion-tokens":"0.0.0-canary.4cee1e1.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"build":"npm run clean && cup-build","clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepublish":"npm run build","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.4cee1e1.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.4cee1e1.0","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-eTb4fgUP0mzGISwNMK7xT+RF0xfBtmbnj/t8OdpYREI+XjupNOr55Hnrnxm2sSLeIhI+OTs96mlU993ozHgopg==","shasum":"e66714400492e24facffb1a79e4eecbe7d07f04e","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.4cee1e1.0.tgz","fileCount":25,"unpackedSize":61065,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJf9N5QCRA9TVsSAnZWagAAR+IP/1oKBdO7Hr8VZ0DhWX9R\nr0cQ7R0m5RAVn9jOzy3LYMxdWjLwxLwnBH0wvhqjpHB/2WJ7e5HpDhipJVmv\nrX8NHB378DGa1LqC/aF+QFjuESGLn7UURbbYy4qolMJBmUjnD/idr/ZTl/PS\nneKCUC+WAUgXFXmtv5VJaCGrYBgi7Asa1Eal3W61jUV1sIaazut+uPMcp9Lf\nY4wHsySIdzs0GJOED2N0MYTwnsa2W/OVm9ppZphDHLjMHH5ujPGcKaZEaLph\nCRHJv+sp2hdVYxiCQl4nQNHWOxEI1FVwCZrCxuW0gS1aHENigtB+MpfnKTWa\n8AUsClJL1ND0qI+wIfsyjdyUPKAETWzyQkIy7LRL9EzQZN4AQFClBtU7myAF\ncomUTBFJEkTVHlHuu4ekoQJZnCgZhV3LvqqwYR7rPStCgtjcyLRSu19JEegB\nTYd9M/16s7p1P5Q2cfaUBWpdW3Wi/FDOzO+Ffq6DW38Fo2A4c9+pV/Gq+rEF\nYPXMG2obHwxicoNqH32pQb6uqWjPyCcdOi9K/JYbPhgywCswqr9nOivD6qIU\nPoGNaqyrx4brN4i7+q550J2PuBXZIvIzPHkgipHHieWhebRkhWlDytAqLfTb\nUcCUBsNSx2y1b0qip+paE875ZAnEOuaSd5aodW4wBxDAws0+WXA/F408T0RE\nbVtE\r\n=dLwY\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCgMNptmQ4yl8wPVBkIDk38D7gqM+UPm/jVzdPXjOvQ+gIgCfUPcvQatdCAOv4GMMjqGS/KpA0oq9OZNusY+XvSGEg="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.4cee1e1.0_1609883216246_0.20601931121532724"},"_hasShrinkwrap":false},"0.0.0-canary.b936566.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.b936566.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.12.3","@babel/plugin-proposal-class-properties":"^7.12.1","@babel/plugin-transform-flow-strip-types":"^7.12.1","@babel/preset-env":"^7.12.1","@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"0.0.0-canary.b936566.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.b936566.0","fusion-test-utils":"0.0.0-canary.b936566.0","fusion-tokens":"0.0.0-canary.b936566.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.b936566.0","fusion-tokens":"0.0.0-canary.b936566.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.b936566.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.b936566.0","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-uFceKUCJWeeLUizj5V0WJNlTFzsWlT2tICKhj7CAt2u2+9uenb4Q5oC6viwyYzU06ByE+W/miHEfxa4W/8mKdA==","shasum":"1c9669524251de114209efcd82b28371ce73e4c9","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.b936566.0.tgz","fileCount":25,"unpackedSize":61154,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJgCI/WCRA9TVsSAnZWagAAkRAP/2S6YPVByqniLJ0lJ1Lv\n8rbYLysWZPZAKX200+/DDxVmpweRYD9ga4m5y1DSYxzWq2YDGKNUQFqV7dPX\nKSYTc2wyk3zGMrOEk1t2l08BZpZuSUrCAWkdxg74ZSWttFoJqYuR5FpzvwBY\n1yXu+f0f23sI8RC9hd0P0P9/ytBDsl0AiIP4qWL3I/O3KdpSa64qd8ixorBO\nRm7BJiRj35H8whqyAaN8SoP3ORpYahYn9IRRGm2GHr0kNB1xSJZAN23dT2wV\ntg8u/lu/VhWkqFQWtRhIi1HPPffWmyxgsQURfNqEwV1YSo3zRZZnvlsBAIJ0\nI2s7BFgPcu2K+arMb5V/vxbPWhGK+uuEU1Gk+gCQe5MPtF2msPt3Cy94g7RI\njFOWx88/vEmOqYFBspJjAziY/ufqdzuOXox9nMc1jjOrY1yDR+UwXF58r+iW\nsbdHw/N3g0+AqHLzUtckVbTicVj0xMMjVliAYo/yp/YtoofLMhWStD+E1VOc\n2S0VLWSR26TJDCcOqTUuluNHoO3hdVR0+JhiC3XS789A/dn0lzwciTW/4NKx\npFQ1App/L6yOZE0CsTmSzFLZDy5qsP6xdH+FIkC+1WugNpsISXtgSFnm+2Fo\nwJymjmBOn0iBCYrqLsIjGcQwvvTtxSUXNLUcYp/yhePOkdaqYyk0GVnCpNOD\n3Qna\r\n=DWx6\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCICEf7vOXjL7C7l6UKgRFAJxlswL7TmX8vZDHBSjhWnGuAiEAyLRkfIzZyWYocVsx4jh0vQcSr3JcAk/fW2iDM5z3ja4="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.b936566.0_1611173845913_0.9506153873795946"},"_hasShrinkwrap":false},"0.0.0-canary.7d3770e.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.7d3770e.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.12.3","@babel/plugin-proposal-class-properties":"^7.12.1","@babel/plugin-transform-flow-strip-types":"^7.12.1","@babel/preset-env":"^7.12.1","@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"0.0.0-canary.7d3770e.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.7d3770e.0","fusion-test-utils":"0.0.0-canary.7d3770e.0","fusion-tokens":"0.0.0-canary.7d3770e.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.7d3770e.0","fusion-tokens":"0.0.0-canary.7d3770e.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.7d3770e.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.7d3770e.0","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-SLnM+IMI3rSSa2lSJMExnwiYFDltDmI73KTTSh9IPakOc+NWBRf3K+x9smq7GbLCxww3ttEHwP/5kMW9h11dKA==","shasum":"84321bd11b5f217f2da70e2fe81e9a79fce08358","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.7d3770e.0.tgz","fileCount":25,"unpackedSize":61154,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJgCJmNCRA9TVsSAnZWagAANaEQAJCHj5khXdi/dmOTiVsa\nt3fzN0jWK8r4laItsLNV5VQvHIbRkfXJbGkZFIVpOKSZhhkZbajYz9cKVxDg\nThPxWsklVf2GR7MhN4Xr30udoNYqNpr6p9/8IO6412L5YgtGR4WMlbPxqNSk\nx34PTyuy/NdhGyus/zRyYf+Pw1hsSoUpOzJudzDQfxDVuWq/Dn5Bs+Sp0/rM\nLxIlCtHDycxp9XGBN2b+mEwA182nACNsq9/6zpu/gumPSBAczRDCjOOct+m1\nbPMhB53HrJn0JQ7B02QuoOQIl+zOhZ5ibaYmltZdGeePT6O0jZj6SdB/vqr2\nc7eX3r8M5Ol5cclKqWuZOEQ3LaOVN+jHlRttTx6osiElXIcSenSlu6GxzMNR\nbgmN44kfXcHTIihwEST3zjlrZ6eBHXPihzzX1BZfaSzHEqrWbVmW71z1XPY5\nL3hD3HLmnNeFQ0O2CXTB8x+ZqGOfo+HNeBeLOAdHCSdy6CY2RTqMYIhGPGkc\n36qw2O4lbKeWiUAXn8yXx/Uvt8s3hMuXbbwDbRh7JuwJK0kDBrAJ/7cBkHqw\nPznBUQVi8RuN939fbCrh/qwF6zlCT4iGZinZohqMFIeTaLVqGxHaGTzw85ah\n+QZxry9PMLF1Y/hror4L2uLXfKmI+7wQ4F1OSWzk7k+rTD+ld8gC6iN9GJ8m\nXl6s\r\n=v9/O\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDOmOPRdVJofNmkhv9ALF8TPci51xcJF54U1HpTjhsqEwIhALIEFNQJjNA8b3Cj7Mut0EWAvubGiDqGdqlZqUTH2hm/"}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.7d3770e.0_1611176332603_0.8390017570026305"},"_hasShrinkwrap":false},"0.0.0-canary.c848126.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.c848126.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.12.3","@babel/plugin-proposal-class-properties":"^7.12.1","@babel/plugin-transform-flow-strip-types":"^7.12.1","@babel/preset-env":"^7.12.1","@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"0.0.0-canary.c848126.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.c848126.0","fusion-test-utils":"0.0.0-canary.c848126.0","fusion-tokens":"0.0.0-canary.c848126.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.c848126.0","fusion-tokens":"0.0.0-canary.c848126.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.c848126.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.c848126.0","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-Zf69WXVnAxX52mDtdw0oFs2QJnFZ2WyKPlyA0aRKnHvYvT5jlDwzDLlYXdH6ByQVqTpS7oug0DokRCPht++LNw==","shasum":"b6f7c0f06ed5f5cc6fb0c917d8a713de5e3b1743","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.c848126.0.tgz","fileCount":25,"unpackedSize":61154,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJgEyx4CRA9TVsSAnZWagAAhbYP/iSX8zj2koKKa8kwgfci\nZh2YmMt7b8C2XwpjVktHg/fN69PEHO1Pfh88Em/BBYxwWslE1RAk2axroqAt\nKp1lRyFGEjt/rlGO5bZiZ48rmXMJBfRbx5zILSny37iMP1kHz2a+uFXaz92L\nobac86dBM3g2VK9WOF7wM6l/yvIMBVu21yzbWdnT9vSbTBJ3QJTj1Yln1xge\n/pmwfrn2uPQfjGQD08VHHsUfncwCsBOXCfv93y0nZPWXAg0+pnYRh3jtdfF7\nmmHXlcuDqHxgq1eLml0/LahTy8FGmIHItwoBEa3NKrGHrKALhH7nlGoBZ6w+\nqZTPiAD4PjdBJqKJ+MPrvgJF/r4NkxwU2mAFv16XgUPQT60uSFe3LXQZDLqS\nA9emc34TdXWfEMqa4hQ7wFR+UMyoKuLkW1R85V70N1NWhtiYl4KGAAg8hMz5\nGybUkPSW0sxpBbVoj/QHL3ByzVtKAN19XswvVlH5FvDWdXbC4AnWA4Ie26BM\nDbeSCr3rAA8MhVEfy+8dSJHrRT3F6nxr7flIfcCAi36fV45OJaCFzOoDj+4t\nGyj9eVgtzlj3uwcrtI526HvkYFRtG8DXf4xtxDJdDwZLxlfsw2l550tjPlfm\n3jJ4zN6BuTlb1TS7qHdxP/wJ5T1udPTrbfMkRYDb65MlB84AjodKbJNsdGAa\nao+L\r\n=nutw\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDtIG9w0jpdyrShNd8ZYg6OnEG/g+Mzpn1mk2Ukjed5hQIhAJjkOCYOhrvHdZuqvmAShirVler/+bi1derjzPTgeOvB"}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.c848126.0_1611869303652_0.2080869059314514"},"_hasShrinkwrap":false},"0.0.0-canary.7eef88a.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.7eef88a.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.12.3","@babel/plugin-proposal-class-properties":"^7.12.1","@babel/plugin-transform-flow-strip-types":"^7.12.1","@babel/preset-env":"^7.12.1","@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"0.0.0-canary.7eef88a.0","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.7eef88a.0","fusion-test-utils":"0.0.0-canary.7eef88a.0","fusion-tokens":"0.0.0-canary.7eef88a.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.7eef88a.0","fusion-tokens":"0.0.0-canary.7eef88a.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.7eef88a.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.7eef88a.0","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-6NCjkPHLaNMO1bjYUV3NJoERw2JwjuTWmWxO6oPcEfHTj7Wwejct8hqQuFV8x0IAanOm6+LtT5vxIPbN/iF5eg==","shasum":"bf8c6806bb969f4b00e183a6e4acd87e2da88856","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.7eef88a.0.tgz","fileCount":25,"unpackedSize":61154,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJgSQTBCRA9TVsSAnZWagAAxPgP/1wiqPAPK0nqi4Y+500B\nip/PzZ4dqfLV6+ui08CijruBz8/Wnus9pYndDWVCeK1a/JmFS6WkD8AaYB6S\n3OwkRk+l4O94i/+h3iqJYD7R+XWP42yQUD8MxC5XYwJkjVo2LiXmsZXv8uc3\nWgwcE6yonfZr07QW/a4D4OyQDfX5SOwOrtqvMID0n6NEINKAOW7Yie++DOe1\n0yIKLm9LNF6vRv+2CFu9+ukhgzr6RsokCtvRKSz6QtaL7vSYfDOo/8q+MCXx\nWjrGtNm9dTIZXQas2a2xArFN1r7zGB4pTvR7DRIGtSkWeWAxFRGTKDdQIwrG\nsTBs205/U6RSZWXWsjVZcf9r/QSBtpSPhYTU3NRJPayPATfP6QAGG/OPO0JR\n7BV/v9/MStzXPGIWkGRXY0m+dnLgHzpe3hTNS2MC0eJaMHFvaOiNAtuwEZlv\nPnhwUSElZlkyUMPaKcJ4g2avXAybmLLUolGb6CEOa0HsyEUtLK7OXQRfpmY8\nRIH0QjMON1qqQhxH054KsCrL/k3peXvjLfPHVDIH5LGUIeihcdzAxnWCAqTb\nkrpDLBwLwhWLcJf7rwhtJ+t5NwhseLqVk6jFm3BHOgkfRlXpPLDovIGlZkBY\nFu6I+Luc1QuA0tRfeuEdsDqOIxQlBxSkRpXzh2xodw3gTubV1dooky2aEov8\nGyQA\r\n=8Hg5\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIADAaDdlCq0aioNpih6sErrmwPLvWqaZbwAcxbm2IJ9JAiEA08mOJgEDe+teWaK/Y/TUAs6/lIARt77jnrroJbIhj3g="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.7eef88a.0_1615398081174_0.6635288796138574"},"_hasShrinkwrap":false},"3.1.8":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"3.1.8","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.12.3","@babel/plugin-proposal-class-properties":"^7.12.1","@babel/plugin-transform-flow-strip-types":"^7.12.1","@babel/preset-env":"^7.12.1","@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.3","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"2.2.6","fusion-test-utils":"2.1.7","fusion-tokens":"2.1.7","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"2.2.6","fusion-tokens":"2.1.7"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-3.1.8.tgz","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@3.1.8","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-4j7LRXHWbKT13yqHnCF1VldHd2Mfew0cq2QC+Z72nABsUAFlNZ4tGxVbGgK2SMbmtAApR/YkggLIAJvlAKbTQA==","shasum":"e770150ae5ce33ea50dc8fa734424ef17cd5e672","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-3.1.8.tgz","fileCount":25,"unpackedSize":61035,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJgSru5CRA9TVsSAnZWagAAWwYP/1EDEgpMShuTYf1wfLqp\nc0JVj7bQ9ApZ7Tzaw8rfQgTu4q5NITaroiI+a3Dgo882Pua5cidgbCTrW4AK\nCLZucHnoGYBqrJhB/Kgxr6WXg1egF9HEMTftZaLjrJLFEWuIVKgST/Sry/mP\nX5tUGaaOBgWS58/ZV0lgsDogy0uzdsuCB/Nofa4P4RgbmqKR9loHqfOaiQTf\nOgsWHzJtJ79Q7yHqnopvD6U1PNKyXgRdU2mRU4XcKNKLiflmNU2YlgS6pZHt\nxgB/GE6BXxKYvuO2F5fpiKyNnwrjCmXx8o0s+mNTxvoODi3vk4nUL5beM3q5\nM/hVmgPb53+7nSIUUySComUXzpT4KG1KtgEwINqogfNWtHPxo7w07+uqwD81\nsmcKDgQGOn0flgcEs19s34tiYsxQrw5Brn1gzxX1HNAUlXKqiaCw8HxGXvkB\n3G9lJ350v/W8Hozmugsaa0SUalPHqrlEGfWG/pRStKIW0Cx8X1GVdDqtz1lX\nB72rEM1DpnL6o2fBK2mOzyuVTFSJgXwGBXxvcmeD6V8+TLYRs0WUTtbMWoAH\nozFIlaOU/CybNXxvIjRralw0MUDvZUauTs8otUVrIDKDPZaOjxiA7FrzHJP2\nk6F8LAKSiufoUoqIWs4E7V0XWuE4/c8kbE6BNuDFWNfEJ/sioPhWmJn6O9pa\nCM6p\r\n=ykc3\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIHtOkKm51vKG1pr2TpcR1p9LERKtHRG4pGCD9gzEZX9oAiEA3+2Y5aUDYac1edB40gl2R2zbLO1n1lScr90crkSmDX8="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_3.1.8_1615510456847_0.5299752259516461"},"_hasShrinkwrap":false},"0.0.0-canary.5086770.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.5086770.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.12.3","@babel/plugin-proposal-class-properties":"^7.12.1","@babel/plugin-transform-flow-strip-types":"^7.12.1","@babel/preset-env":"^7.12.1","@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.3","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.5086770.0","fusion-test-utils":"0.0.0-canary.5086770.0","fusion-tokens":"0.0.0-canary.5086770.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.5086770.0","fusion-tokens":"0.0.0-canary.5086770.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.5086770.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.5086770.0","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-qNCms+Nxy5thAgB+kbIR2WCSg5k9x4eryP8ES/OKUMXQDWl4UDNEsyPHV6kbRiYoEL0tmQHrd7qmTQadEC1v7w==","shasum":"47ba20c5f6bd2b14ba8eaad421f6ac8912ea1a1e","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.5086770.0.tgz","fileCount":25,"unpackedSize":61137,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJgSt+SCRA9TVsSAnZWagAARE0P/jPJIU8c+n/HvQWwKBMH\nsTVgayhuQtfjP85zVpceO5X1Gce2vjZrvXVIZLD106q2/zkT718uV2cb5Qro\nw+wtMGhvCCJdf4OD0uzqgWVdxoQ/75oHv37mlJ8By2z5Yj2KiBElXLmj/a/k\n0+1KnMpEg/hhlpRWmiKgsJv/85hHx3Diiqj2/9QCimvAun3ZI0XqWIdgkoSM\nmNsVC8JvbSeZ/HI/2YgzOZqREfeZdCG86zIJBkiiIKoyak/MP/hy3ONUpafr\n8dCoYJnMX49Y4x87vTIEYAz3dcbzE23CAgc38GWchQurSxgIOBTG+w7D7SVd\nAV7rGbTY9BzFkup8b7OcXXttqPvJlS+k5RxMeJes4YnHMfiJzX0o+G5Uapzm\n6vWpfFwrrO2ICp5juJuXjhd+Enlno1ao5BApwhZY/65Jt/tpYh0GUr3GGTIJ\nqwRggHkXVPx3hFSvhHrRhoYsjQkPr7Oe0RIObN5SHz2CFPK8NqLvecksjykN\nOndm1+6WPbbiu4SAoJsSkmPPbRYjUaksSDINZQjojkw/GexUI2NoP1V3ys7c\nNsOYM3mBi9KCMRb/ivFERJDBbfhfh9JQl3aG/2SmFyWIsAzIggJqrqA2qbbj\nDa8GEPmsvHs2GT3BB8QS7gN6bJWlpCA2HOTcDN+hm/ZSeBXmoY1318jIXVz/\nqNLF\r\n=w3ue\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQC1iHxtPSb55v2kVgMvtzG7VPBjmQqYxSMglc5fbRdzmAIhAMX06ZcxGg9RHUQOW3jHbCKk9p4+nfAp5eLoAH/mirdN"}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.5086770.0_1615519633936_0.5507626443536859"},"_hasShrinkwrap":false},"0.0.0-canary.243e09c.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.243e09c.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.12.3","@babel/plugin-proposal-class-properties":"^7.12.1","@babel/plugin-transform-flow-strip-types":"^7.12.1","@babel/preset-env":"^7.12.1","@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.3","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.243e09c.0","fusion-test-utils":"0.0.0-canary.243e09c.0","fusion-tokens":"0.0.0-canary.243e09c.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.243e09c.0","fusion-tokens":"0.0.0-canary.243e09c.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.243e09c.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.243e09c.0","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-x6inNI1KttRF7ggF8nK9rC8N+f/LrC7bHxmF3G6r4iU7XxB1AWW8V+DMsmAaOF5KjJ3nxAwdkbGr2+oJL76AUQ==","shasum":"a9856a6e876ef5e05ac80f04ea8de555d780d498","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.243e09c.0.tgz","fileCount":25,"unpackedSize":61137,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJgU+K7CRA9TVsSAnZWagAA6W8P/3Ao5R03u+XxrRR+XHlJ\nAf55oagb9kREAdlR8UK+sDurmbs91oqvngJF0TTKMCoiw8Y5DIFdKGsOwRJB\nLaeJQ2LhsyL1vDDEajUBwLbFt3ZLk6crnpD925NCZcHdu3tW6GOFFI4PK2v/\n6y9RSQg5+IqlPfKPRB1UZP2F5GbFln/7FEnSwv1+iHWdWxeGx4CQzWAlP1KI\nSkZgsY7uxqvRzqGuxiVE15MWjydTNpaxDGiqt/rOIo+j1sowGs4Ye3poNaMn\nroI4E2E/1IVC4LkPFT9t/NrjYOhjQyWqiFnuDPKGJp1CO7Pma/dbudV5aLdt\n4KrUnF0ABELakMSH3WAQMbOa8d+6ArF8p/JkBZ5eG5unqcV5NUKB4cEd+MbQ\nOCQXXEFvIj100SkeAgYmWWmog8oNsVi6PfQtA7B9+QEuWDr8BssGCuTk6LaZ\n2SxS4AnpNIzkeGjVwzh0mrSbWg90Wj8aKfikz2fwv3lnh5jA7vB5vMUrsRtu\n+ffDnbwqQ0kR1jdv5iqg/o/+bR4CttW6Jp4UF6/isswrTsOvzDD63y20KG4J\n6H3I5WQP6rZHTcu1zMjVso9Q8caPhQ7l4yV8whll6IBOnnWwlNWdKtPxamff\n9YJc7fSHZL0HlIakgOLQW3D4xy19VRZJg+JV9gpzhVM9C4kdnz96azcNnZJm\nqeqA\r\n=+4a9\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIBBhzUEyXg8DFl/R5j+ifsWovYM7H94qgkRBsbSC+v0hAiEAuDzxvjOq2Dpxg6LpTNv586WFVYU1Kwryk2X9r93lK5c="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.243e09c.0_1616110267084_0.6937395165540456"},"_hasShrinkwrap":false},"0.0.0-canary.156446a.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.156446a.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.12.3","@babel/plugin-proposal-class-properties":"^7.12.1","@babel/plugin-transform-flow-strip-types":"^7.12.1","@babel/preset-env":"^7.12.1","@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.3","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.156446a.0","fusion-test-utils":"0.0.0-canary.156446a.0","fusion-tokens":"0.0.0-canary.156446a.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.156446a.0","fusion-tokens":"0.0.0-canary.156446a.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.156446a.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.156446a.0","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-FTXiDjY37A79KiHv6ap7h5assPk+W9wTzFlELInDY0L2r+zXaSoksCaHv8gQhqiVvkwrIW4U2efZhBrLACxsNQ==","shasum":"2e4fdb80909d2468c8b0decec9fb90ff9ac0985f","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.156446a.0.tgz","fileCount":25,"unpackedSize":61137,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJgZ5zwCRA9TVsSAnZWagAAQi4QAI/1qLKDufIyIiXPniGw\nqc68+5uR79E9d+kVF5fEQ0p3W+woCtjgo8zZnvAY4/Y9KXBiMYjLcIkLVeya\nxrhey6g+oNIjlaq+SBb6kSMOakLoN//cCVclPNQwRQSuSmOPDkrELxZWyCSs\nidd54nLNLp0B4/3PE0wg4X/b7bt+q7o0iwjdmvQ4xUhiP2a0vWFUo6pph9M0\nlelLZgk/XjdlTcRQ1G+28mxmJS+tHLvZAoo4l910lMcbWAxSMuxrntwPxvPr\nO1LSuDBegUrD5beLP7FaG4DFvm1MI00G3TaC9Rlyvelz9ONHtmE6FrP7quiR\nqfEs8mYl/OYA8p1ubaqH7i4oToEEIsSQVQhiDQeQxhKXvW2bpabQIBf79NJ1\nqOsSgjNZH/LKhNu3dryeFAB/RbjYNGJSXuejaNBqWPjpp40JEqrIDHTNrUpF\nxBr90xtzhlC662g289po3r8uWhiKlY4eodM3lAjoU7xnAKAno10/vCjUxc7g\npAX4FwtCf2TsZPJHvd7pYfwyIWuDdFyS1WQ+l3T2atSenhGDolpnkjgDwmjd\nraK+PNdQf7iLNh1g/vmmkKrM5lwitCDHMNoRa7c3GxKjgD+9QF0k8LJuu5O+\nfUKZiRnCTMIwb2cKEu6g89Gx7Y0AecQirgVJBCb+mRXWSjKnhxn+ortALVoI\nGL3p\r\n=pSen\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDQUmIfx+uKk1FIJDVaiSR//YQedAfqOalG28Xx/VCh0AIhAMhcY8sUnUYg16ObHUt5xo2AEDGl/PkC2574etXMCbwK"}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.156446a.0_1617403120342_0.4944324712298105"},"_hasShrinkwrap":false},"0.0.0-canary.bda3eb5.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.bda3eb5.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.12.3","@babel/plugin-proposal-class-properties":"^7.12.1","@babel/plugin-transform-flow-strip-types":"^7.12.1","@babel/preset-env":"^7.12.1","@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.3","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.bda3eb5.0","fusion-test-utils":"0.0.0-canary.bda3eb5.0","fusion-tokens":"0.0.0-canary.bda3eb5.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.bda3eb5.0","fusion-tokens":"0.0.0-canary.bda3eb5.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.bda3eb5.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.bda3eb5.0","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-bhDTlDgXFMF2DykjDSqK8+aykpGg/autiPg91m8NwCOdNKxIZStSylTmAtZxR6J4CTr6Eqc9w1mnlmKy+gwYJg==","shasum":"8246215ffc97921733e1bd2501e5859cafaa0536","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.bda3eb5.0.tgz","fileCount":25,"unpackedSize":61137,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJgbhvZCRA9TVsSAnZWagAAAKMP/Ah3puyvGvP9IHWieosf\nMn6mriCY4kM1vUb6d6tGlXWK+K/4xany5XAmMmLoNREU8s8tarPyf2KLfFdF\n/puRJOXKBuPMRIYIJlzEolbyYk0EQHe0RMM0ldHh1mR5QKJBcVfgj93MPv8f\n9ugHTN/Gmk4qD8hOiC2Yy9T8qCsXscKk3hB84PBqPd3tPCVtTtdw59KdRGrB\nNHGOJNfUpOYC7uLWwzqy93IOZxBKa7jsMg0LK4fa5Tr0/XlBU4HQTIyj4Cm3\nU5gCJ9kS/S2you6V+inf0nX/BAYexEERDTtV40HiOkujQ6wnQdlbriSOI9s6\np8vTtyco6WEw6qDb81mHdiU5rNQtauYWU4mIpZI0kTcSUGGIvxLV/JsF9AKe\nzbv6y0BMcWbptnIUfrQ1ul5ir0dV15tExtotI8qEVgm58zBnp3YGG9MQS5da\n7ricMC6HYMSCcOTd+xba5fWLEbT9X2/NXvt/HpaO0fSB7IT9V6S/whUCdp66\nI8WSZkiWJ2A4RXr0AOqpejjmagrykpnnAeIbjtyEen4JHnSgEJetTIoEveWf\nI/PEJMOz10V5OXO02jfk/Mq6TFRTny+jkZyj2U5fqXjniVjg/4Ngb2daoK9n\nP8Pv9nv9R5xfx/qAahHXYbTg6vbsXtMDkkyuZFcvFd5xH73BYOsupZyyFFdq\n0ife\r\n=U/v5\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDJmqhNZ0gxNhMKEmtmUwqPTCGDUBf0yNnXRR5qI0h7owIhAOQuRL3DCZO7tCZ1GcLgWWE8xsW5OOx0Om0I2pBdHHAn"}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.bda3eb5.0_1617828825209_0.8648754542290538"},"_hasShrinkwrap":false},"0.0.0-canary.7852906.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.7852906.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.12.3","@babel/plugin-proposal-class-properties":"^7.12.1","@babel/plugin-transform-flow-strip-types":"^7.12.1","@babel/preset-env":"^7.12.1","@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.3","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.7852906.0","fusion-test-utils":"0.0.0-canary.7852906.0","fusion-tokens":"0.0.0-canary.7852906.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.7852906.0","fusion-tokens":"0.0.0-canary.7852906.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.7852906.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.7852906.0","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-oRk8Q52G48NDJ40lOp+Ft1jbEcIUqWGb/BpUDO3lSYZTdveuhA/qEYTPTrAwSiHgTPjcfzlATuu9YKj/MxEJFw==","shasum":"a18883fffe6fdf055e3894e1915f5a45a62dc85c","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.7852906.0.tgz","fileCount":25,"unpackedSize":61137,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJgb4C0CRA9TVsSAnZWagAAqZ4P/Aked1TBwGjOa7fWotdu\nWst5Yhc4Wq0B5YMP3T8jz0mvZ/p44VwigmZxA1benzBylYg+pxIhzadrmgI3\nMvjxavOVgFLikVqa+3otMMVI3HyPJM4fil9tvI8iBlXdqQ4A0deO0SUSbgKv\nZ/ryNFrBnm68Ef9zqDrSMlXlUnsH2JZ/tZa3v9S3XK3+EYoOaleLikWnNKnP\nUgc9yl/awrfW+SgP64lvAYmc7l9Rn2GJJPjT4aoIs/mcjY1XgCCBVIvXCNpV\nR/00f2TkNyUy28v9Ho87W8NiPRUwbslB01bGPxN3RBpWpZs4lbhC8orqqUPB\nTVCtDWwhMj4afwWHWW9xKLSd3s/6bdHd6KtokHicTTJbqDdz0IIlWvOxHGVg\nAwgvqkYb9kvDk/nWHJVX62N2ECpw4sHOpXrFfsQi+Y4PujLbXT4Js5Tv//u2\nwkWr6TTaWBtlkUVLw1++CeEzopRnsTF10f0RoxuCY5tQ5JkCRChyVj3VXwA4\nQXkL1hV6mlElmwGJisubO9mBtTAoRijfXIkqajdpRn5PGj8PZ/MyY58L8KU4\n9tAKNhGctgFco40A5tMHl+Ds+EJw0Ta7nG4JQp7G/bqxsydVt7KW1C2XnRDH\nmkNEgFDShf1Yzclk/YhFaz1GmubVGwSbi3hwpWeJKcW2WTQ+ty02R5vK11c1\n47hz\r\n=sdDi\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCOVfyqH2TYCOd/SA2p/vf+g5nD0lhfFolm7s+MtL7unQIgAOkB1da7+qWMsSmGIXARX8qBUYLUtZPU7FKCMaHYir4="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.7852906.0_1617920180217_0.8721798215479941"},"_hasShrinkwrap":false},"0.0.0-canary.36c1f93.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.36c1f93.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.12.3","@babel/plugin-proposal-class-properties":"^7.12.1","@babel/plugin-transform-flow-strip-types":"^7.12.1","@babel/preset-env":"^7.12.1","@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.3","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.36c1f93.0","fusion-test-utils":"0.0.0-canary.36c1f93.0","fusion-tokens":"0.0.0-canary.36c1f93.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.36c1f93.0","fusion-tokens":"0.0.0-canary.36c1f93.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.36c1f93.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.36c1f93.0","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-tmUvkcF++/IywDldLCGPo+LplwvC18vw1PwaQDn8FEhKt2OwATu7nNlgMo4jcd5zTmzH+qNB18ZZocKNeWWjrA==","shasum":"684a07227ee2db256e20bd5b68e40d29eade77b4","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.36c1f93.0.tgz","fileCount":25,"unpackedSize":61137,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJgdF7OCRA9TVsSAnZWagAAFDsP/RGvSpa/yXxQn3qtkRfP\nV4MXiKsEjHQxGfqQepwmSTyRkmuA8fNxLKondR890HFOaHAXB0t4y6sI3x6a\ng7D6BOQZpYCpBApRbUOUhOPiDqheY7vznm43RmCjAe0xz9GSfPyLOxODMoRg\naRoP+0buGQcXWsio/YIiwnuwdc91TXdtmJU5KMv1Cnw9NOqfo9ZkajpLNfce\n9ywHwnqVDj7/PHknm1fymR1VqRzM0eZ48nqRn6sUoRMVwwTERQAdjN/SJ/4J\nwlkmT3Sgb2huGUtgjMjbZgcckGOaPvlcoof7oNA0OGk12unXccmNCI2n5VR5\nuNtl2v1mFKg90LL+S++qPMVSmBNXd/eYllwBMrFVEaxh4rXs6QT9vTBUEEKA\nn+BOvmQOPA6RIHd/nvFk8K+W2wabCFoDptAUjJkbfAjK1puVotIcouRNEzxb\nFmB2ZFMFgUSBSf7G8l3G89t3j41LB2B5EWveUMQvZLgyineFUs0C0lXtNHxb\niLiry11IKHqgxuLnWfN4MRifZtiDqaUyb5zn1/cxUWmtEZL0K8QcyCWew/j8\nUfulCVIS/E7yvVUmUMLohYzJyx5pDpPyjRMtNDeGVq+7X5pcoR7Twy6BVuE5\nCSxZkZUq3HL2DLlbZB0GOXfI8OP24saz9G4nGuA8mkKeTKkakkZYh3WH8uag\nJLCb\r\n=juJC\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIGNdf+qry1FnK49NQG5cK3skED+rD84GtFNXEXkF4xgpAiEArd0XL+JyqCmJYQ6VZgDbtA5oXTGbOikWDyJVSzxeRRc="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.36c1f93.0_1618239181562_0.6482576126357875"},"_hasShrinkwrap":false},"0.0.0-canary.147decc.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.147decc.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.12.3","@babel/plugin-proposal-class-properties":"^7.12.1","@babel/plugin-transform-flow-strip-types":"^7.12.1","@babel/preset-env":"^7.12.1","@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.3","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.147decc.0","fusion-test-utils":"0.0.0-canary.147decc.0","fusion-tokens":"0.0.0-canary.147decc.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.147decc.0","fusion-tokens":"0.0.0-canary.147decc.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.147decc.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.147decc.0","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-R5cEQtWAezni02aMZCybtZeY+ojQ2/EFXozfXq+3aJGG7xAdJcFk0KcKf7IGG4qFSsPuiB9GRG2p0cK7wDA6VQ==","shasum":"d3f10209a81af5f288ade5bd68058a67711ccc3a","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.147decc.0.tgz","fileCount":25,"unpackedSize":61137,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJgddCkCRA9TVsSAnZWagAA5SUP/2oaoG7NTW1FDzsQ47rt\nceuEW9YFAqNSU/DD3LvnS0Ev6cOABuZtepx9jwo9SBbh0ptC2w+bU8XN5M1G\nymU/NoojORJsUAzSpCDGWLhQ+BwUBJLMfsIS8ij5ACFI2jz/KyoPmaRw+Drg\ntHE/9vroXnZ0D8vGbTs1rcPda866eo5xlwlRp1UZ7HSWHEPO5+wUDc9n6SeM\noRtct+P+HiojauHAAy17OgLO+pvRwysjC3w6MPZFkxI43YR+JM114rQghOkG\nVNXK4owBlmJc4xLmfhnMe/ZPGYewwNUfm5nEl6HtGv42QifgF31HpCELRsmH\n3Hv2mCBVyD2lsd4BG1vjOmM45/TnY3yXYttFhUtw5v0+JZOgBr2fNed8Wmga\nwhb30a2l6xwRA7UcOIdCjX1dfXpu+tk/OpQVUmjY8EwhcEWYTr4r/v6/giSR\ncxODVaVpBrvZgwNlxf5oxwIr6sRwnls5nnEl46aq9ynQLOrnBOJ/pnp+Ea3Y\n6K3XH4y8SO4npCL8a7Gje8x3q9ca1UlfFnUcqw66KCCGSpgy+caXya6eq01Q\nt9023OFb0rv97w9EO6hKRs+vIvzy9bs6Q1//Q28H/K2HxdorKhEIYXCm26gp\nqB+37k4GcdxdeoAss9ZEXTLa171wyBmNHsO71lcMDjkImqPfOdPeFpCuKzVG\n1ANn\r\n=xeur\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCID+pG5GSQ9rDe32DjHnPq6atA+kYa8eQAGzeg0ZlAMjyAiEA63YFQNXjdKnJ6GcuEVRMdP7V/6kWJ5tWNcTvuT31B8I="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.147decc.0_1618333860406_0.7078651961469351"},"_hasShrinkwrap":false},"0.0.0-canary.481456c.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.481456c.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.12.3","@babel/plugin-proposal-class-properties":"^7.12.1","@babel/plugin-transform-flow-strip-types":"^7.12.1","@babel/preset-env":"^7.12.1","@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.3","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.481456c.0","fusion-test-utils":"0.0.0-canary.481456c.0","fusion-tokens":"0.0.0-canary.481456c.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.481456c.0","fusion-tokens":"0.0.0-canary.481456c.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.481456c.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.481456c.0","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-9qsere2tagvTMxYxByMUZqxqcr41aspGI3WSOeatusOYshROkJBsRdeltSO/1jDi19id+oJBeTEKzTo+n0fkkw==","shasum":"6e001f41c330c4ee1ef0f20609693ca7894a518c","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.481456c.0.tgz","fileCount":25,"unpackedSize":61137,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJgdhQ+CRA9TVsSAnZWagAAvjgP+wWf1c71WvutHBgFSXfr\nJ5k3qTxzkoTi+VzBLwhUXrMkoHxh/vgz90bKKsi0bVbfVvgl8VUGFrlU7oOo\n9ApC4dP5lUeRvrCTujgt6HcnOJWxrJYptF89OHvMOC6QLmybTh4PNRkWzWgW\nsZoWGyRaWA6dcxwC76qQoNBb9k+Tmk+GKV/BxO2Bl++vKzbgdcQlD7mS25Ab\n6OEbPzJvszhCJeHK44+bu2gxwiz0ZlaP7GlVjFAECQLn8L+goxBww+hlxlPm\nCJIMp2EG6TvLPwYi5LEcm6FXUYZesSCqa5CFeZuGDYz+HxBGs6j4ZxkdAo8Y\nDcxuXtzaGmearIFVP3fu9+cJDMVrQsD/SWWq88kLSm7TZvwnxT++j+CkxhYD\nU72BXBniAsuhv/rDYM97pqqnpsWLo7ZcM1niXKwgaBIlWPFe6xLoEuDSj7J6\n/Euow5TB/DePkF5wBUJ0t9ujaU2AYFCpGenBU3DOMf54WTpE8REJgLlvior8\nYZ9dH+st4jH+QHwd1UZGFeIQe8JUREMh1T+lNx2RCRET8FagUTso9ds+oIBn\nYnR7NGuw0aVnzF8vfhC0Lcr50LNlsgPui519ENl2Kn0GwoIvNb61RwpmiUJR\nTpLBvrkWUs9QoFd+djSnvLoLs5RTWpDAYbr3kh2USclF1KrAkJo4J5eprU6a\nqaEe\r\n=wZ4a\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIBYBOwVHQTgXvVEbkSvbpUMJh8PJFcPtUgOBL84kfpqEAiADIWvJcReouhgzg1pSRD8DD1ovT7Em3u81Wz7bGCix2w=="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.481456c.0_1618351165866_0.2894654493136555"},"_hasShrinkwrap":false},"0.0.0-canary.4d2f7e5.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.4d2f7e5.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.12.3","@babel/plugin-proposal-class-properties":"^7.12.1","@babel/plugin-transform-flow-strip-types":"^7.12.1","@babel/preset-env":"^7.12.1","@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.3","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.4d2f7e5.0","fusion-test-utils":"0.0.0-canary.4d2f7e5.0","fusion-tokens":"0.0.0-canary.4d2f7e5.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.4d2f7e5.0","fusion-tokens":"0.0.0-canary.4d2f7e5.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.4d2f7e5.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.4d2f7e5.0","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-2cEWSu6yTUymCHns+NybdAZzpG2/G3K4sP3vYc2N7zavAgln7gsaxj5fDVBNYVYjPPXDw2Dd4kx01q943axQbg==","shasum":"7f84871e73aed9d4989d8089998ed6473993c1bc","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.4d2f7e5.0.tgz","fileCount":25,"unpackedSize":61137,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJgdiZhCRA9TVsSAnZWagAA4wsQAIW12hY9nSli1lGyW/wz\ng3P6df2JMG+1qEDoLyYWG/TatW0G5SJYJE0WT8OncruocEMisr9XJ5Cj7EHp\nOXNytu48QHu8T42PNOBrv79+4VYfK58/h0G6M/ermNR9HSTRuEeohoRLKsIO\nYdOkTiCED5Nck9T5LdKR3XEyn966ZigCVvYv/s38WXyAdCCTqMTlsofyOT3z\n0OCAnjV+sX3NYzL0CxLzMCSvsDQ/pQhspzxKlXtM0GO9jg3FMHIm/afeKiel\neEy61FOL0zEoj6wrhqI+iVdSeCw+njwUNkTRFxH/w93JyLiPg+YC4N5T9On5\noIa0Rj0jRmXK8pVWWpfyLq/eFLv4JPoS3eXjZEMi3Gyn9QHfaVuATOM55M/A\nLx3SyT6utHGTkjpb2coaDxlcp0abcGr3fn9rAQ2AnmNf0DYgFS1jD0G29g45\nV/Q/e4Cb2IDmQWCh+5FoPn9s/LnE7rcQ1MZ7KyDXuGWGXTPq5Cyx0Mycg5PI\nYBmgYWagxmKT37K3VYySTIwJw5tyd5vKbyYn49z4Gc37qrsQueNeviGib35l\nRQa0FSBvweDTsiZ5k766+tekFBcd1D4Fjc2yws/DGqCUN71d5ASA//wlxWb3\n82MMIdjbi/qAwZt4gpncxmUsWwI7MzYGLxJhAUKofsdCHhy3Mjh4DzfkIC9e\nhDLz\r\n=EUG1\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCICEjhmGA3J6/hWLNRktnGNDTEI12Qs3aCQFgFeLhkgxpAiEAzLWkxEEU2AoCStJ0kN7XhNx3IhO21Jf5gvPxGVmiMB4="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.4d2f7e5.0_1618355809453_0.5049332527871284"},"_hasShrinkwrap":false},"0.0.0-canary.9158df6.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.9158df6.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.12.3","@babel/plugin-proposal-class-properties":"^7.12.1","@babel/plugin-transform-flow-strip-types":"^7.12.1","@babel/preset-env":"^7.12.1","@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.3","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.9158df6.0","fusion-test-utils":"0.0.0-canary.9158df6.0","fusion-tokens":"0.0.0-canary.9158df6.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.9158df6.0","fusion-tokens":"0.0.0-canary.9158df6.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.9158df6.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.9158df6.0","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-AFdyTzCklhywiks73k2rz6ZTn0mBbPHDj4Q558wJm+23xzE0fskbShzf00Ii9oJwcrhl382As+pBms0ate/rOQ==","shasum":"0861765dcdcb5ae277b6d8f3ddcedfbf03e0f972","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.9158df6.0.tgz","fileCount":25,"unpackedSize":61137,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJgdvuzCRA9TVsSAnZWagAAogYP/3Hf6N587rwoXqB2n20N\nYjnTQSf6rdulcY3G9iGtKxzJBFW4g8SjMdgsEQkpD89C3WmnZK1cpEvgC/G/\nhRs7I8ud13wm+0s6JFo9XpQGEMBfQ/VEcb13PcCOQcQ3aNIq2p08v12rlHu/\nJe1s/FYIFxPE5Z+Ejlye6xpyiaIUxw/8+2fQYYM71KQCd1DQ3dZf1MnCgvGN\nP62AvIiJnO6OMHvEpZI5htF1h6qtKYtg1oyO72Xw13oiFqyD2xGpZnw9o4rs\noaqtoGQAODjAqDUO9d+s2qtOr1JbXs25gO0Qgd9HFbjACLsp9/grLXFgZQNY\n91rZCJKOl/J95gSk6bDNfY43isLy6ddc9AbxJq+tt/q32uCH20GeELIboJSh\ne9c2+0gL0wVy6U9OPyswM5W0MDZ61rPjJUygE1z0LyTPT+oQlDiuIYVq/ueS\nNfmsQuU8qDbi3hvO4iektn6fpS7M1ieyvtjR7sYHpaEigLtsvRRgb7L/tXPe\n9CK6AVmJk7oTp4BTO8HCdiXSj382S354YlPVZBdDrbbYotRVK7jYO8UMrgWz\npXxjt7ctTMJdyeyDXBsW7cDob/UMC5O0YQQcYkQtTWOtelT1KSGnF+YJ87fo\nmrh7+49f86AleyAoCEcq82oDM4eEIIdxV9KPC5UboEbK7BlgsbkKzu/XKBDl\nrZSE\r\n=D71C\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIFADQz3nb6BOpdU34APChPF9FA46mG4Zruz3GCckvD2XAiAuWxyjtZc4EuWtunckh1fGk6dhmqPsk+q6WbSC3WDLOw=="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.9158df6.0_1618410419072_0.21855947441965595"},"_hasShrinkwrap":false},"0.0.0-canary.c68f2d4.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.c68f2d4.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.12.3","@babel/plugin-proposal-class-properties":"^7.12.1","@babel/plugin-transform-flow-strip-types":"^7.12.1","@babel/preset-env":"^7.12.1","@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.3","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.c68f2d4.0","fusion-test-utils":"0.0.0-canary.c68f2d4.0","fusion-tokens":"0.0.0-canary.c68f2d4.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.c68f2d4.0","fusion-tokens":"0.0.0-canary.c68f2d4.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.c68f2d4.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.c68f2d4.0","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-3izAn1qAY/NGOdWeOCz4y3a3cz/lMpDE5q0Ls1g2evnr6g1hZAtzAS3apC5z2fQtaIj8lUWRzGj+KACeoj4vYg==","shasum":"91fcc9a9585bccc7829420b85cb1f2cfff1a9492","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.c68f2d4.0.tgz","fileCount":25,"unpackedSize":61137,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJgdzyuCRA9TVsSAnZWagAAObEP/RhO1d0Pe/eiFy5ZBW6i\nOgJyiTuPRkPcW2g6pfsqme5NSF81GmdHKa61AkM/r2L0nmqnf9nmpWuULEi6\ngnDhBADRxIT9/IL/2PU8dlVH542j7za/VEBOI14EI6x2gYCOHr09Jj8W+Udg\njHzzLn8Z6ORwP0N7PbwT9qTZHhPUubzc7VSNQ/seKqOF/aecXeBKKsVWrxiy\nFFnkeu4A5+THug5akJwriO6anGyv0y1/Kys2DxNbhCGk3/Z/k3+3fhbLYEiC\nwmdW1K69g0J94wbGwhg/SOnpBQmU6DdfPE6Oaaf5bigeCaPlXa6zq6zepyMV\nbkbzkOv+78fb1nI9IFoSllpln7tJpmrKrhR4n/3Yd6Ki40CpjYcAzZ+AKYKa\npj0W41etMrAKHeUBEXEGfK1gvfCqdisWZZKQmJ06n8rKAw3Q3MnEOCrUC2B5\n1mKpi1esZuwrdkmUqQlJzzKgqLbUIgRx+Z1wte1809TtbtSaP96H0kRckUkZ\nCgF4Jy6dr+w4vqkHI9QPTkmKHXwE9LeRYOVNsriCw6U+AN6ivXHmDxllLzMi\nopfgasfiK5Loz+DAeodUXYMS5ZR/KhGKhab1lavqmSMuu0amUaUYBDRgFWs2\nrlZY+VMpG8MtuCziPlWEzIeH/PMu58pYcesTf6trKNM3hV8RYjyATrQweqHH\n6cqn\r\n=hl04\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDVU6yICiIkiZsnPGZlKvFJkjqWhfx7LONNSsRgr2Xv4AIhAMrB5cxWJXHQ7D9tcXi1M6nqX1b4XfbbDVp4d6jsSJQr"}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.c68f2d4.0_1618427053831_0.8822610856573037"},"_hasShrinkwrap":false},"0.0.0-canary.fa4dd7d.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.fa4dd7d.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.12.3","@babel/plugin-proposal-class-properties":"^7.12.1","@babel/plugin-transform-flow-strip-types":"^7.12.1","@babel/preset-env":"^7.12.1","@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.3","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.fa4dd7d.0","fusion-test-utils":"0.0.0-canary.fa4dd7d.0","fusion-tokens":"0.0.0-canary.fa4dd7d.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.fa4dd7d.0","fusion-tokens":"0.0.0-canary.fa4dd7d.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.fa4dd7d.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.fa4dd7d.0","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-nR5ZC7c/BdoepO5th3JCEqOzCxx0aElgj3zDgsRcJIw4x5uotvrW+I3APdpawGpUcoip5n2x9mTc1qK1WPBxwQ==","shasum":"834049fdd5e192376b9646021144f73eed796f40","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.fa4dd7d.0.tgz","fileCount":25,"unpackedSize":61137,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJgd2ZICRA9TVsSAnZWagAABSgP/08Bx9D0u2hpR0Z+J71e\nqKn5ThbWVH3hvXtQKkgzYcALOppLpH8BTz4NiVGdKPqhOmmuLNAjxgg5a+57\nHhWSvpIS1Qag5TAlqHro34220vYTEhDrSLjaGJIL0GyeKVFkkOUqNs1Swa2u\nh25EF0jjQzzkLHGJb/Jux0mA/a4lfeERIMdbkAKKdWBBXE9EmmYKfiVHeNM6\nd/nhKAa4Gf3POHcQIuDglgm/X/5Vf8uTYoToM9eYipxzV1MmlvQkKmE/1Fg6\n2+mBzds+4cnCFf0EPn5+JDCPytVPejGl0Yx8Mwa24pQBnlBdP8P9Hnqv8qER\nULFzLzCvlkPGt9DmPAi7jcTy6GBsCH8kqhhrQ5UGdWyz4Q5h842+REchS5P3\nZvtrRZxZhBXB/g6c7Sh2Alm5xPLZYDZ6siTQZywA+Z3ZSu5VZMID11uudvK6\nDqIaG4FZw6e/ZSaGQCNcCqS1DT9VkOzzw6mutn7N1ZiTBUkssOAfZokD9UxS\nthFioww6R6tahksEExtatD3A0P3f4ORU6VoHX1Ss7NrfEQLmpajZq7Xa0/HT\nbk5I2eXNTHK/tFmGQ2VSBB5R/KBXKW0fBNJQ1PSz4FNAQ87G/nZew0ZzIYTS\n2gbSY+24r515O4yLWXA4GVdqlTWZ0rLfY23YPfAaGXzwKHZgau4NFKsumUKB\nXFc2\r\n=mViW\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDd0hStRcUyL4BxenCF0E/Ef9uAIJC6jd9AHmbOamXoigIhAOPfZejUM2A3Pye75HbF/sfogF2dTe29Ur2tUnQm0NkZ"}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.fa4dd7d.0_1618437703793_0.9389908152982025"},"_hasShrinkwrap":false},"3.1.9":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"3.1.9","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.12.3","@babel/plugin-proposal-class-properties":"^7.12.1","@babel/plugin-transform-flow-strip-types":"^7.12.1","@babel/preset-env":"^7.12.1","@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.3","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"2.3.0","fusion-test-utils":"2.1.8","fusion-tokens":"2.1.8","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"2.3.0","fusion-tokens":"2.1.8"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-3.1.9.tgz","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@3.1.9","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-AVJQ321waU3YLBxSMWRXyOSL8mpJ8VPt2pafpnyxY4I6MFiEK+BmfghdtuCaHchjUsn3Hq2zF1AO+ynI9CQ+fQ==","shasum":"427cd317fec6b3e5e279be79c2269f398cd35ad8","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-3.1.9.tgz","fileCount":25,"unpackedSize":61035,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJgegyyCRA9TVsSAnZWagAA2acP/j6O0RaJjl52fAbUXz2/\n/aNXS82Xnmpbjct1SrOJQTttWMatN575x2/PCcRFdDOQIDNh8Xzn5xhByr/I\nNBMnlNukZ7P61hCwllbKUHh6ZGbcNGWzmWKrtkEW5xZsyiexx1c83Lj8vdT5\naxcHqo67lbkuCtzWnQo6sxPK3zfQD75H40EEcEkiDi1EqWJNj71p7rD7IwWN\nlDJtTbGApTTW2czafgK1gBEc0b67F2ZsVMQUHGtsIKzecwVybjHXFEwDd7sg\nI5iQz5y6C2c4Z1k/lFWyz7zcuuSiiKju11geBeXD0bngnBTQ1JmrrC3j7/kk\nj0UKEYrxIlZgnJUNmSJm13UTOKSrPPox0dnMHNIs/y1wsnSZQjvhtAgV/pOu\n9xwCQ6SvdUca2vEjUfRb+VuyD6IQ6HVW1ySvHHlsuWpW5Gnh2oZUAj5OBOzZ\nFP9y0cRDcg0JTev2KxPRBAlTRZ8/uQT7r5aELgh5L5PFtUrwPpp7TasWLn0+\nT2pCmWSg6Vm5p46zxYkP21xZSaF+Cbl0iKUqMjMdl5oCYmhTzi2scWbjsFyO\n3CkPAiVIdA2oCSImTas7ebgWnF5awwLM5mHphWF6US2kpWOehtoWlarmJXMm\nOPwQgDYBEf7A08ubPEbd/KAJBulqS8/YxkudPYLWPfRe748dXwPoS9q+7lJm\nMC33\r\n=jEIp\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCICJggeTctMJGaJ4piE6nGi2+TgidXZ7LgTFm0qJ0qYo8AiBDvQ+aseRbJcsuZAoDj47KUd/004fxpdGxhdJcAQryIA=="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_3.1.9_1618611377577_0.09372233549075992"},"_hasShrinkwrap":false},"0.0.0-canary.60586e2.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.60586e2.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.12.3","@babel/plugin-proposal-class-properties":"^7.12.1","@babel/plugin-transform-flow-strip-types":"^7.12.1","@babel/preset-env":"^7.12.1","@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.3","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.60586e2.0","fusion-test-utils":"0.0.0-canary.60586e2.0","fusion-tokens":"0.0.0-canary.60586e2.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.60586e2.0","fusion-tokens":"0.0.0-canary.60586e2.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.60586e2.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.60586e2.0","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-Vap1I2Zq4J1cWd9TGhVDCFn6cuHXRMitYtKNlSZ1Rs6SQAuyNywQgIUvIXayolBoVprrZtbqP+K96lAmYUo22A==","shasum":"1ea636a54d57f8d81244f6d767829724eefe3031","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.60586e2.0.tgz","fileCount":25,"unpackedSize":61137,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJgooXwCRA9TVsSAnZWagAAdekP/2NzVnq9Cu/LlzXs6dPY\n4Enl85TnXHydNiSQM4c/lKCDsYxZ8PM6bi54k6Cxmlk+q3Yv6s19azmELSXn\n/t9W2FsJuVxoHp1TJIdc19Xzc1uEhEw2Q66hLPHoT/L13slYpgpeFkSlq7Nt\nSdbWX2FsVVOc+VnoCrdClQUmxMRbzA5nXYECEABNKaIA2FXRyrLVmKnnMr3r\nGFcvQIKjitNh5lbnJw31kizVmWI2UfTWU0IrF6+2AjLsSJwFoq8BKaAhMK8I\n10yXBDB6BAMt60YSlRYfweOj7p1ipvr/yuOBHy6QNI5ODvxknmkahZPe0Avs\nKG+HiQ4f6RQ+9A7mESD4HBsiEyfI/cNeSc2rJDJ3ZrZGG8BhNvL6I+ZteqBO\nuBAkmxM5v0T6hMXmlrOsBW5o/s3jTYraysrmCyfO+3/BSF39dYhRa08lDnPl\nZzGMHBfkfi/y9zcZsZaD7kO+NlWmy8+WxEi4NxtzQg6B7ZFF1wsMTrXNVtbu\nZ0M3/f1MCk9Lb18Etvj4nRX+lcO3iRKCJ1vkpleD+UsWIss70Y6yytwx4Pmf\neFoLCCKs0VMXqBL3Uh6cM7AAJLocCzbQZGPPZTK/xmfGcsf0Er9zaudYR4rH\nuDuyT/lhjM3O/hWEke9q4VOjLzw7p4NKygd/bR9JNR5V0G0kmjI1gDNWfR5/\nynMP\r\n=hwFa\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIDOwmPeagrClo3knpLE/ThFfO1nQ5C4a1z/Dhriw1llkAiEA0v4dVqBmt8i0hByt8V6etcBar4eLjSfiNX0YaBDMHbM="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.60586e2.0_1621263856215_0.9983915462047785"},"_hasShrinkwrap":false},"0.0.0-canary.b3081dd.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.b3081dd.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.12.3","@babel/plugin-proposal-class-properties":"^7.12.1","@babel/plugin-transform-flow-strip-types":"^7.12.1","@babel/preset-env":"^7.12.1","@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.3","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.b3081dd.0","fusion-test-utils":"0.0.0-canary.b3081dd.0","fusion-tokens":"0.0.0-canary.b3081dd.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.b3081dd.0","fusion-tokens":"0.0.0-canary.b3081dd.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.b3081dd.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.b3081dd.0","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-1o69hrocQ7S3qbQ4Y+CjE7gbJADQpXk5vsJD5CibvzTnPo/7F87FCeiGiznnyaCDjCDCx1psQXa+T+7jkAW/wg==","shasum":"c2e26d281e8b5cb7f7d1682f75dde5573096ac1c","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.b3081dd.0.tgz","fileCount":25,"unpackedSize":61137,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJgqC2UCRA9TVsSAnZWagAAsCcQAJJevj9vD0RlfiOEHIae\nMLxFkm42Gm9v05lnHcNoNvDbl3/kOiVhs3wCnsE+L3EJV8EDSnySs7tgLIfi\nLtQKQ6gTEh8HSbNwICovhT2zkRBtmvjCWqYHpFJ4r2UTfpMHR6il7QIRtfbh\nFZqqt/eoLESgkVBytAU+ARTk3cBa2roe2QVn123KKKlRyEZEtrtV8NSkpM3R\nioNWwm9y9aMme5ep2+oX0++FVbc9vL2IJ+KX8ANbcpQAtinxoJFuRkhRETvS\nPc1YLpUUbrNHMqTYqHEqLQWAO06Y4Kx5PzOXhdS7b5dAi3g7rd+4m0orHpcE\n4fa/UlNMaL5CEpcuzLCIrd/bfMBlE1Z9hMCpdYR+h0BFN1wuwKHHdUxcKBIL\nWr8N7zBL4xBtl4Cveq5WguUVDQLsylNlkt1n9gTiQkm+k9PghKhutHIU7GIr\nbZe50+3gx8gKDbya/clnl+GbdOQhowlOfKF1YSoitoHILZCqwnleGkxcrSac\nSBzRFJGqPtf/Hygy/I+FTB9/i8Z8OTzIfQQoEInd33o7tNeyyVqKiphkvfEP\nHK1YFjZTBuyIvCPoSo5ITDRwX/lcRuI/8INMPafwkuu6tJ2GedWpDcQGtIF2\nbo7mCLPJ2Jnj4p6V0p24BLyZK2q+JVvxfShAxDtN+dsbu5OD/H2JokCILlou\nDVxX\r\n=EcFd\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIAmpD1T1iKenOiWE6/2SYae3RqRLufitFCj5jJvTmEwmAiBHOqoROJ4SSx5aycjjTAlGYfqSYtVqbmlDgBF/cLFiXA=="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.b3081dd.0_1621634451782_0.6152051543974768"},"_hasShrinkwrap":false},"3.1.10":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"3.1.10","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.12.3","@babel/plugin-proposal-class-properties":"^7.12.1","@babel/plugin-transform-flow-strip-types":"^7.12.1","@babel/preset-env":"^7.12.1","@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.3","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"2.3.1","fusion-test-utils":"2.2.1","fusion-tokens":"2.1.9","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"2.3.1","fusion-tokens":"2.1.9"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-3.1.10.tgz","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@3.1.10","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-hFJHOGfW7qqqSvWPh5gtqe/vJmxFw3eC/oJxG+c5ygQ/LZK3XhpPa241zx7+PuRagyWZVlv8uYV/LC1k9TEuFQ==","shasum":"2fccbfc47b9bb047690bfad01619f559fd8bc71a","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-3.1.10.tgz","fileCount":25,"unpackedSize":61036,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJgrEZ7CRA9TVsSAnZWagAApswP/3VAR/8MEDBvkAQC0RkQ\nFLcCJUK9M0Au+lR+XHO08lm+5f+1NWrjxZwSmnat7U1aaJW9pQIcIQf7CG+i\nKtc1YP/E2U98IJv+lV7WIfio9stGvBhCUIgK0MaDh1egj0964FrOe+WtLc83\nV5v0pnw64CCou8iWFBJxFUpMKT8JT5uMYAD5zDaBPogtv8ZIYgqWD1CnEO+Q\n2b8jj/xgb+iU/I1sRZ5MSY9LzO6dEoSJ3l+40r4hfr8NUEJXd0q1WwuUFuY1\nUi8tYi+DFeXoYim1fzMmxRZ6WQCr4jFSEtH/Nyy38K8PE9vmrgaTIImtOpwH\nqRO3DiO59iPJVCMiBeV0418SiQ4jsWbbFLgGwI3UWwc9SYiRWhmwzeFmdTvZ\nHoszbzMsbCyGSUQe6KXmhfoP2gylOnnhA00533thW7NKCBIuLKCrSmZDILsJ\nQIorjyKIdXdowpIt3ryXuDFuSLtWS7sgAjC63YulmXs0whVZoxpJypWABIfS\nAll3l9kZcaUbo+wiOPkMTqYgLMizorfUwmzeg31F7+TMaI6geDT0VkcBNY7/\n/pk9XcwpZB/AU453SJ6I31HH0W/W+yZVKMzoToIwGVDIbmAXopEu2IS4F0yF\nq2GkArRd6a5PgyWvFAmFmCgkqIe8QC9T7hc+CPQ2mVlqq0yH2k2YDOXzwYFQ\nOy4z\r\n=8ghW\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIBmGYhD8FHWeN4sJoXS2Q/YBsgm1WlvgrvFEB+fFZKPgAiEA0UZdvra05w6CiKifIEsTCs5+Bg1HX6T+uRhyBr6o100="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_3.1.10_1621902971129_0.8904659302390758"},"_hasShrinkwrap":false},"0.0.0-canary.9b92a54.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.9b92a54.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.12.3","@babel/plugin-proposal-class-properties":"^7.12.1","@babel/plugin-transform-flow-strip-types":"^7.12.1","@babel/preset-env":"^7.12.1","@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.3","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"2.3.1","fusion-test-utils":"2.2.1","fusion-tokens":"2.1.9","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"2.3.1","fusion-tokens":"2.1.9"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.9b92a54.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.9b92a54.0","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-RgwhTyD/jY2nFLkKpUdxiTIgunawiVCztDnKMTmCsBTodx76jg5yH3caSN3t6bf7JLr6V5rSm5NFm+c8fEPKiQ==","shasum":"b3791fb4b349717cab26ac98052b0810708e1fc3","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.9b92a54.0.tgz","fileCount":25,"unpackedSize":61052,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJguWO/CRA9TVsSAnZWagAA89gP/RAhQFnnbHYSua2XUajy\noViPMNDKavC00NQMhAc437c2eIE/K869b0wwB2LKW0eGLJNbHgEM1Q5VOfH6\nhEp9+f7MdE7YTfwdp5dseDipFhLZ7F+ZNLxTq71w6695bl7bYFGLw4dxP5wu\ndfrOmjRinjsW4WcfCctPpRnEGOHCitVdyEWdMl5qa+CQgNneoo9X63cXEkDY\naXp2Dc9wC8O89S3KlgosNxjXqEcE+y8K1US3nNyU88nMUCJntQDQl6Bwo+5l\nXE3CZxvv0dd2StPjWUGEIE/kgtV7y3HdHPz1Yq4y4NiguGcs4fjKoJz2Q8fq\n8Am6aXKMxlCvhT/GmQtJeLWwtmKfFcS2YD9LwVMTkTQ6ht5U7u1mgLNkG89v\nDxllRTkzm8JaTMMXJ7wAGyoPG5JZftI1W6N52wZDzuJzJEgN5SiYv9gn2nRo\n4ixX5kR/TFami43lCURveGuqMoyoFpvZOfPhXrRx2iUPGjmBLpCJk0/RWV36\n/oe0jQtnf1fmS9R2qawpYtZ/zEyjMhLyRy/R+fTmTdpKEUS74+sWmBJXtx/U\nH/dd5db+FxB65cl+xb3TX4Ix1hWraHZjleIQG44HPoK3N1GVBEEgEbIJ5ZLg\nhG44UAaJ6dIdJvAqjHq7fZhVbSxjcIqTHpP4+L+Tw+Tojp4iR9DL5b8sjITX\nXQgu\r\n=wdot\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIBrdeP+0YAom6oj6XtV8iDuXqhypD+TIhGMMyEyzd15JAiBI1ySmscAbVNutgk4luf7lZQB9dZzwMUsWEnPn4NNEHQ=="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.9b92a54.0_1622762431504_0.7395120073989707"},"_hasShrinkwrap":false},"0.0.0-canary.d88c6ff.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.d88c6ff.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.12.3","@babel/plugin-proposal-class-properties":"^7.12.1","@babel/plugin-transform-flow-strip-types":"^7.12.1","@babel/preset-env":"^7.12.1","@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.3","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"2.3.1","fusion-test-utils":"2.2.1","fusion-tokens":"2.1.9","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"2.3.1","fusion-tokens":"2.1.9"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.d88c6ff.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.d88c6ff.0","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-Nof9bIXODsIwUtf7BAWcuwZqDgbunShSqchQszyQC5Z7bzpY7fPx0VhXEOnMR6XC3IXLZKtt+zpZmbhvRK8sSA==","shasum":"e7e7daee5be57cb34e2a3b6c8b31f74eeeccabc2","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.d88c6ff.0.tgz","fileCount":25,"unpackedSize":61052,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJguX2RCRA9TVsSAnZWagAAjv4P/R7b3u7ediJVC0SbQMlu\nvIjXpUP+UdvpkszXa4FPJwI4qAhGT24utqBvIrIEcwvn5ZQ5vSfBEMAoOUzC\nBQUXHma4wGc1Z+Ewqs2U6YbWqWvEgfRNAwWQ02yuFCBaOF/sYfZPAm8wpryI\nK+P1KO0YDHtzgGccnCheHrt9L7wNsCeLRU8rMprXMM3YWb+tU9YVmDthd+HZ\ne7Q7XunlOoqCaN2gITbu4rtEA91jM7nN0AFCxlAyQ+KZr1Qy3hlYJB01d+Ra\nwMKB6nhndpgZSxmI8tRqxSLmml5Zy/pDmQZ0XI01bQgJ9SYx2WsP8aUg8WHa\nlqddShquC3fm2mt4KzFOrP/GuKWMfY1IrYPkff46SeWKAhCsj+K+dd0Z+FU0\nwQZhS2sVsd4Sym9lKIAuvvn0/8F7xCPr49JxrrXKc2CCNrs71wwgUI50ZhlW\nBJ9uJS8Vj0qMtqx2sOGSOa8daiGM6pLUPLOX+QuWMvulksP8kX0Z0DrRaPNI\nKv2Xw2eQYOkFw1DDfz0+E7R26vsZ6iITi0FnJPniZRt2Xy4t1Xf+NdrCUY+H\n50tispsGSl6x07JlbsLTqZLp7xCEbFT+nm0AGNUGdzNAjp1BEWN1DStnvm0m\nb9ba15vkLES/H760Mm6yAnibVrkOeq8QWHoIuQ5/D+S8xTED+oOvI89vYzKm\nGtPe\r\n=ChHD\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIFTAEB0T1MRSyvnrXItjz4/9U7VQl9zd4zKCUbL/UQG4AiALmQy5fsnNETvNcVinLcSge7G5JP8019yOE1S2vZvpAQ=="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.d88c6ff.0_1622769041360_0.6448455494120608"},"_hasShrinkwrap":false},"0.0.0-canary.f50f438.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.f50f438.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.12.3","@babel/plugin-proposal-class-properties":"^7.12.1","@babel/plugin-transform-flow-strip-types":"^7.12.1","@babel/preset-env":"^7.12.1","@babel/preset-react":"^7.8.3","babel-eslint":"^10.0.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","eslint":"^6.8.0","eslint-config-fusion":"6.2.3","eslint-plugin-cup":"^2.0.2","eslint-plugin-flowtype":"^4.6.0","eslint-plugin-import":"^2.20.1","eslint-plugin-jest":"^23.20.0","eslint-plugin-prettier":"^3.1.2","eslint-plugin-react":"^7.18.3","eslint-plugin-react-hooks":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"2.3.1","fusion-test-utils":"2.2.1","fusion-tokens":"2.1.9","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^1.19.1","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"2.3.1","fusion-tokens":"2.1.9"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"eslint . --ignore-path .gitignore","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.f50f438.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.f50f438.0","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-LBBV/oEOXzZATDnmWxyU2fhE5ylJzQ7NEQxX0lWOJlI3iyGVmrN5AVeOjPMW2vXAN4KjDzoPHjA9amU2qhqkJQ==","shasum":"1791bf1b93661f04c9f55be96d33885d0849b314","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.f50f438.0.tgz","fileCount":25,"unpackedSize":61052,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJgw/p1CRA9TVsSAnZWagAAQHMP/2mnanNqAt7B+6lagSH2\n4YdEXfqytwOYF5RxW9bpLOaqtDJ87+w3P1WOyOIMkbDgRILhmdT4YBsJX8o6\nW7PuVI1gjF4Rhee750Meu6Eqo0UJ042WL1Z4PLI8cl7IeMsCjpNDesjvjSrI\n8oYebLKPku0eP6OTzEoiR0E+FlU2EFLmApB5zq6oC2ph+NlKXAzXqveOLxQD\nSAArqwrxhhIkkCdR5jGJo7XAdbohPtf0YaMtDMzS0EqLPT50th1s3lAWLZ0D\nx3+diW/l3YV6rLP//dpDIxdouEQ469oJKc2S3yId3sRaKc/HjbvaByEp+2Ec\nmdYFg8ipJgdxCkBV0oX/iDnhMrAzGyoF9o/E+4oiHzHkNbT+RoOxkgI3QYPv\n5FwqdfaBWD26m7pjD/fFWm2UMEGVhiwY4VM5ZIYK+7RKi2AO4cp50tXXr/zy\nMMTXzWgojHcBiGOKEDBROPve1K17GEo/VlVvqomxiFLJe6wwjertjZUDXJte\neFHncl6wlqHt/Sz6NoXvucnpE3TxHMMknY3+0qBqgoXCPpwkoxMuh/XM+rQv\nNNumiGqp1k6n/bDoPqgGjlwW2VdQvp/mcWpbYpe8tkOGGZiA7jgnBqcAtpal\nKanVxt1vKnO9D5ZEcxTvaAcfVb//yOzr0xqrJKlEjKphK1i9G+zmJx4m4vWh\nzZ2K\r\n=25XC\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQC/avfCCfyIabfTQpWbahivKrr1Fa59hbYxUhhmlARTTwIhAK/kRKBIINwsIiXcSUsX4YzxUhyfFdm1pNvWZ4ojAS4G"}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.f50f438.0_1623456372926_0.22033964469569178"},"_hasShrinkwrap":false},"0.0.0-canary.dc6dd20.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.dc6dd20.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.12.3","@babel/plugin-proposal-class-properties":"^7.12.1","@babel/plugin-transform-flow-strip-types":"^7.12.1","@babel/preset-env":"^7.12.1","@babel/preset-react":"^7.8.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.dc6dd20.0","fusion-test-utils":"0.0.0-canary.dc6dd20.0","fusion-tokens":"0.0.0-canary.dc6dd20.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.dc6dd20.0","fusion-tokens":"0.0.0-canary.dc6dd20.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.dc6dd20.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.dc6dd20.0","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-00hYSsnN44TK7x81gIQg1CuyWMkNtYR7NoMGbzmHOzeYyu8P3gtFoY2GZKoAsV0twPiG2AoLVk1ylucKmTlC2A==","shasum":"8a7a6e6ced6cb630fda102069ef44dd02238212e","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.dc6dd20.0.tgz","fileCount":24,"unpackedSize":60514,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJgx7H9CRA9TVsSAnZWagAA2/EP/28FokMqyh/TPhXkZkw5\nZtMuCVIb1mnuBVFjYo9WO27VYMNHyghNfasejRbqEfD5sLrY90ifM7DHTkOo\nDpdCz9ye48j/Jp0qaEl+SQf8MGiLA9ByZoqxcqMBasZNNzzzCG2AcBHsl+P7\naayOgIGRN13C19OJCgP3Sy0/NxPU8WLuebP18FOhPnTVBzHzq0kGQMDPQIwU\nWJg5cYV58YdYroxBEH6u0H19DQDtA1Iq4FSMYaaagYgJm5NFu6AzvTQagKWS\nQ1maTOb2SRziUrHR3xukikKzw+DfvDi1og2zo+hXEplK/POb6l0B1mwN2mLZ\nzhwjai3P1xXgcn7++3o7CI0ZwaQan4MIGZjMS6sUtnJPeFBDwXxiclVr7VXd\nRwlx8c+CFCrDGjE0RKtkC5cbOCLr0Yieqxw11mGbm+KVqQfNWsij3BXslVwm\nJylgKBT4XQ7cvPOt6csAnOn2ieFkBpC74vLopoT9pj3MC1B6OBs+G6o83pL7\ne9Gw9E376apbcpV0xYMJ946nR3GW+hKhz7OABODtdKVcpxUtk8CcV4teAPrC\nCY3GTxx34aDJTK0mwLz9yCat9oPdR5XFMzNUsRiP6Xcz1vM/FWSrV6POsMHD\n35FR6FUc2lVL1C0QY9dTttvO35JIJpF/UUZXxhOJ9Kc+3j6JLavyWK67IsWu\n4TlL\r\n=aqqO\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQC409epqJaVLP2FFrDaUngX3RwGjxhzZEd7kxIRaZPHPQIgGauoe5n8LwnXwromQ1RYikSy1fhv1GrMDPquDjJNLtI="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.dc6dd20.0_1623699965104_0.5865868575736128"},"_hasShrinkwrap":false},"0.0.0-canary.66de151.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.66de151.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.12.3","@babel/plugin-proposal-class-properties":"^7.12.1","@babel/plugin-transform-flow-strip-types":"^7.12.1","@babel/preset-env":"^7.12.1","@babel/preset-react":"^7.8.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.66de151.0","fusion-test-utils":"0.0.0-canary.66de151.0","fusion-tokens":"0.0.0-canary.66de151.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.66de151.0","fusion-tokens":"0.0.0-canary.66de151.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.66de151.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.66de151.0","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-JCnRVJeq95/wgR3xHnoPYPTFZCPNPO18xJmbAVpMdNMZxoCFXSDzMjcyHkuA1cuLd+O1sA84EB6WdPSp4ir2sA==","shasum":"6d866e78dea7941060be4f4849fbcf0267e49cec","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.66de151.0.tgz","fileCount":24,"unpackedSize":60514,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJgyA/3CRA9TVsSAnZWagAA9YcP/3wlSnTNqtTNaVSN+TiI\naU9vaKot3aA5KmLYYTzCSU7x5js/x63rWjwC04ZnBA6brBrGH6sTB4Uofq9c\nN41pH49Aq7FKxRwDOGtX2xZ1I0/jyNOE17a0ED3U4IX91TZYMioonvUX1yj5\njoCigFO37TEQEKtQNdaP7GYb5vxDSvKwRTeSFOEeoof2rJxBNrde0gfk9SWj\nv75/W/xwOvqh/2pnuDw1sTFp9y+pcSQGVEd6c+7IxRryGymwR/SwQtr1rptO\nD1Qc+CdOoeggVr0KufKrsrNhpXYEzFtcUsIwCZOLJ+QZq2S5bUZmneBInQP8\ncfNutc+BROZFJv/rgRbhh5EfS1BYrhLBjkNRdtor2EIQ5lTxrgAQa4bwwINW\nvnCzsSqvq1JHDpEVEwwP1zv/L1GZBpV+0qkvYhdA7ii+cS1arfjXDRUhIMmq\nRxcbcow0CdE584JIYz71+SbwH6YIJCo9yyyZT7+veI90ry4MVTfwJIMoFdUJ\nKVdC6MfxX5uCz8T4h75lD1GP0NXzKBSDOnh6v4SbCE9etEjHkTWJnywQ+89+\nZzJY5H1NqYj9hw5xYvsgrI20VajoZiTaMCdEBNP/HF8dzxHgrKjd2SdojzhD\n/nCpvTXKvqPN7s5BWQdjyxt044WRtdlvNOKQ4Vr9WHrIUrzsskc4OEg6iMcg\n3j73\r\n=pl5x\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIAOnwzPm58+HEYzbMf8ZCl/hFDfkFCqG2XAFZa6uMdgXAiEA/enHkH4dbNcBi5yiILKG9mtjcgOsVeoJW61wsvYFza4="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.66de151.0_1623724023823_0.628497424647539"},"_hasShrinkwrap":false},"3.1.11":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"3.1.11","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.12.3","@babel/plugin-proposal-class-properties":"^7.12.1","@babel/plugin-transform-flow-strip-types":"^7.12.1","@babel/preset-env":"^7.12.1","@babel/preset-react":"^7.8.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"2.3.2","fusion-test-utils":"2.2.2","fusion-tokens":"2.1.10","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"2.3.2","fusion-tokens":"2.1.10"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-3.1.11.tgz","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@3.1.11","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-0DnfVho1JieBkwRojc8E8S0iuuxufW4XWu5e6YToCw74e/KXZ6PChsctMWG0t3Kl73rXFv3kPjFjlPw5ZHCrlQ==","shasum":"fa6e46675e49e6dde60b809d4da76244b2ea7e15","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-3.1.11.tgz","fileCount":24,"unpackedSize":60415,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJgym89CRA9TVsSAnZWagAA4ZYQAI1hseD1LsX/wF7+Hdzn\nZ1aMsAehZ8tnBKT0hBpLN/gNIKph/qFeXj1PgXUVVmfj7fd9oxdSX3DR3G9z\ngc3b0EQRCP4Ze0zVdHCUcAj1mJhwcET+pChEL5Lk3lPC9yCtY/o+VSRx5w2Y\nLVI+hIKEd6LqgZlb4ezD7hANanxFZWGxv9/4ceZgy2C9UmNUWIQ/u31P8CFY\n18W90j+PVXnHs1efnLxBZi2xZyq+xqAGtUpCnB2+t3HvXxYTZaFg+zyHafDk\nUpr8PhlfP8bpmn4SqvD6zHo08bVnj1lKm2+jHGfHuNqhDVOVyYaNP6Ph9Qlt\n7KUYw5styxDcynLDGMqYhbEacvm76CO0rQyHoHqCB3RaGvdam5RAYRUZW0l9\nryI1WPlfWnmPnhdDVRoNu4EUbcCkVk1ywvx+zM6vLNHLlIZj2Bk2bHx+rMzQ\ne9bXn+InkOpUVou6CdiSWa82rb4ZyrKfOqa3ztafxHySHcDyoL812juOY/4c\n5wcnTAtSzMI9jpTa/dIkbBeQ17kOkrTVOTnOdtMLCL2Z5Lzelq/Byz17JM10\n60pl1WZsR0cx5fbIijjsD13xxkVNjO15kzwHd4qqI56G11Zmg5s8bif/B9nc\nLQu6IwPC7TwtHtT/8u3bC8JL7pxaZlJcmXO2fBFY9jOgm5kb/v1Fu03lSMrM\nJMAu\r\n=FCV8\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCYVy+zR6K1+qDF4Da0ASqgIK5C3BHqUuN3tKseFmrJ8gIhAMr1caMVPZ7wLtHzEogmUHHc9cur5vx48C75gEPSJNow"}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_3.1.11_1623879484667_0.4269277082197134"},"_hasShrinkwrap":false},"0.0.0-canary.cc30c9b.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.cc30c9b.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.12.3","@babel/plugin-proposal-class-properties":"^7.12.1","@babel/plugin-transform-flow-strip-types":"^7.12.1","@babel/preset-env":"^7.12.1","@babel/preset-react":"^7.8.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.cc30c9b.0","fusion-test-utils":"0.0.0-canary.cc30c9b.0","fusion-tokens":"0.0.0-canary.cc30c9b.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.cc30c9b.0","fusion-tokens":"0.0.0-canary.cc30c9b.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.cc30c9b.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.cc30c9b.0","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-/kAqRegw5O16P83Fdd/9Uh3QvB0Cw0vBa+kEcTQueYDiqsu9vNcVrJXmzMJosbl+iLfniXQO/MB40+5N1F9VCw==","shasum":"f69aecec7bb195efd20f197a546f5cb4f6a45d2d","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.cc30c9b.0.tgz","fileCount":24,"unpackedSize":60824,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJg/2RmCRA9TVsSAnZWagAA22AP/j8l3kopCBKaerepZbhL\nB3hzxbSYVM51oYcoHI+l7BqEbWFjSF4ZM8kquHQgKWJi+mXjRvkHOU53IMz5\nHRSVN1Nc3BJf8c6Zk4t8n/WgO0aT2ELW1hYnpGVF1d3ymuGS91AfquGnHevB\nmM5x+qIvGDNkw4M0UNgMSLk60Jk8cdUYfUauYbGpz3XRzafvJK2ur9KE/gV3\n2foNPqASiex6AKGVFnsoKYkqqyqFVFaPC+VZfr9AUamo59s3ygw7gr3zlshe\nPhGi131nsNLBMRrkywmi7PsB3U/KMGWVtNAKiDAQtz8ZgsX1Nnv7YNmmlKv3\nBmumSsKQkHeW65VSBkMgPkjmCCWlzFJhBxtUyhAugMERISm/TB6g/yLJHUKA\nphitHcLLxqY1Fm2Ulp11/eNlvp1xiY97X26Gugqw7gNOuJj5JZixueTvrA3P\nIlZQpvPq30PFugRB7/RcOXdhwUm9QMg06R7xfVp9ecVfkq+i6NMbMEf5YL9Z\nnlZeuXOq1n+MBIde9ZPNrmFIgVqFOVYYic7Bc61HHjoYvBMcjy1dbwmuSuAp\nDUggK7kB+j0IMG6lUTCsD07oFD0JPrQiu5/9k30SA1WhyXrlxgHhblqiEm0O\nSLYDz41MnlIn1d5keQs1YKGs4XzDfywu+BD8wQDbmDA7zW5RHXSM1B52PBuJ\nAiQW\r\n=OsQK\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQC2YlLQSLsYPWBEia8cxzhJAXPPw/TWpkdNQdg/pahZ7gIhAOsD92K2dMTMxYNOLOY+lBKFni8l26M9AUxj0eF93AgA"}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.cc30c9b.0_1627350118147_0.6747839773559401"},"_hasShrinkwrap":false},"0.0.0-canary.e5a3019.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.e5a3019.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.12.3","@babel/plugin-proposal-class-properties":"^7.12.1","@babel/plugin-transform-flow-strip-types":"^7.12.1","@babel/preset-env":"^7.12.1","@babel/preset-react":"^7.8.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.e5a3019.0","fusion-test-utils":"0.0.0-canary.e5a3019.0","fusion-tokens":"0.0.0-canary.e5a3019.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.e5a3019.0","fusion-tokens":"0.0.0-canary.e5a3019.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.e5a3019.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.e5a3019.0","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-x8B/2sJQCyr7Of4MyjveXG5cOANI11bV0AdWVqotAIMWQfh65lToBbRTZJePKQF6RDC5oE+UfQYLdUUCpgLJtQ==","shasum":"eccc2282e297980e4f7bdfca5f0de223455b3973","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.e5a3019.0.tgz","fileCount":24,"unpackedSize":60824,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhAJkOCRA9TVsSAnZWagAAJPAQAJqO8AunKaIQAgtTaTEs\nL1ci6CajvNHgO4F8GYj3P/rrZGMLrEr2D0m1wXFpfz/8bVB7/6INSbNcKnkw\nhBXkADVYzr/z9I2zalQktQ0nhOu467ChXL2VpYUk7RYdnTZXFOUqfxvCTvH8\nNPT9WXgHdA0ZYwgt1BxAQEG1GfpkDGlukGwDQRwkSpk0Gjt0fOZRLgMVmLmO\nB/3y7Gzd0bCICWWY1gg3FqvzDxFYWV95tDtfEX8Up+/01Hi/jzHhUab4S8NO\nVIpmIBfaC3KSn4q8M3Eujvp5d1h+GnpUBjMY5e92dJz0vc1nhHn1PW28v5ke\n7J098Tv1PZrmdsticZwUTNHbtzEWDGrDZ63cUiFiVwbb016dMHRxoht1VXyQ\ny8iWvCDNohEUTjH8mUHeyp0jshMQ5NbMG+npVr7urTEAQY/eCAlqYiSAYSgb\nTtlQmcNMgGzTpaAk7bDJcU+ZjEf7IBY1F7XsfMvi9xTmda2OCI3roYY75dLs\n4E7hoY/QIlKDnA6/FMGLYPjWPjfkYiVL6nDOk3T28E87UuR+vLclGns154iJ\niGAgMSbxjxDEAAGZg+rPjvOiABEF98W1qxV5HcNOKkIUuaLpcSGExgPlKfwo\nz27o51IkAUwkWJf4uqom9BDA2xMvxVx0taX7y7acIN9X+dTysPILVDNLnqGY\n8x5r\r\n=fNhu\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIDC5JHAbcGrEC7VIfSkzte2h3wuBd47Ioa9OhTPlC2JnAiEAp2Nqk/yzF/ThfOAoSwehCDB69gMEcFq69iwce7lgu4Y="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.e5a3019.0_1627429134061_0.19112202146719182"},"_hasShrinkwrap":false},"0.0.0-canary.74b8151.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.74b8151.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.12.3","@babel/plugin-proposal-class-properties":"^7.12.1","@babel/plugin-transform-flow-strip-types":"^7.12.1","@babel/preset-env":"^7.12.1","@babel/preset-react":"^7.8.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.74b8151.0","fusion-test-utils":"0.0.0-canary.74b8151.0","fusion-tokens":"0.0.0-canary.74b8151.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.74b8151.0","fusion-tokens":"0.0.0-canary.74b8151.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.74b8151.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.74b8151.0","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-LO8zizC2immt+XhVtCWv0RY3srX+Lz4w1FAf3NxJudrCAiTkOJnEbCZ6WeTM+0gWqFralaNV/h7N5mlzW0I76g==","shasum":"aa634a46e72d9a07022f5b9848d4989c2086c1f1","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.74b8151.0.tgz","fileCount":24,"unpackedSize":60824,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhALSOCRA9TVsSAnZWagAAJtcP/1wpAs00e7NWxZN6TfHY\n8Jk/YNlVMJAALLdE0HFzcErZvm9HVPNobWaePQ9BISuJ0U9W9+udrgXNbNV4\nc51LeawwVSvJGtYpu4WU9Icof5nbHgnJo9M/+StjO2RAufW10cfDnD4LLumq\nc1p3Ep74YMzAx9lJSDXhIIW8wwK9t8+FnDo1sJBs4PlMjzyhvxEtnkKbMi7b\ndNYpRmdf1dKdiuV1DLGl+IibWLhuZX56vsIn8d177+36YtH5HVO3QSR6/nja\nmEF/A+cOKNgbEDDv9VBck0qD46JkFzz+BGvqk8pi8mJV7S7JTkN0+lVC43Of\n7MGtulJ9lvxOWenV7p/0EiL1CMISrL9+DmsmhlRmVBNbejUqWc5Y0atAYBuh\nXq4RhPv/peViaq6XLwh1zzRq5jLGeHU1ZZMofSx9YKxiL2UX67HHL6eUMMCM\nrs0l36RmjV3vUuRP74g/yd7f8srAhmHQQw5HjVoPHbet4GnVybV46NOAoT2g\nDEbs9AArl7K1xz0ysjF+0mx2tqVcmHQTtjjp+fL7OJW6AO5YhflQRo02RfwK\nkCc03vsxaNlxFbCx8ECrp1IqolNgC5GFD7RB29s+HIlcT7Qind+N93gU80sO\n2KojNmwVWm8nGHpmQscOARQyLB4LEdo2l1Jl9Cmv2QCTz/r/NaYlKzoY5BON\no6HY\r\n=NL+w\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDKzGjnrMUyFhVizqAhW/0WsK64qE2Xron0a0Whe4/UBgIhAP40AVt536tpjrR5CFO81ewGJrQwnXvjExdxTyVoO+qj"}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.74b8151.0_1627436174737_0.8540803781458388"},"_hasShrinkwrap":false},"0.0.0-canary.53b58e6.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.53b58e6.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.12.3","@babel/plugin-proposal-class-properties":"^7.12.1","@babel/plugin-transform-flow-strip-types":"^7.12.1","@babel/preset-env":"^7.12.1","@babel/preset-react":"^7.8.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"2.3.2","fusion-test-utils":"2.2.2","fusion-tokens":"2.1.10","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"2.3.2","fusion-tokens":"2.1.10"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.53b58e6.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.53b58e6.0","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-TbteXhTuZGoBIYC4VwYdSx493DenQk7rYrDAvVynOfMlBkIh+Jvqdc+mAuurk6GF4F3HBeE4sfiXYhQ9LpUgUQ==","shasum":"362f24405b85b739fb20c68db3d3dfce4f2f2a06","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.53b58e6.0.tgz","fileCount":24,"unpackedSize":60741,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhAaFZCRA9TVsSAnZWagAAlgUQAI9U5dZRUX+Qrjd7lGbJ\nNAt5X3nPMu+FMzq+56FxCUI+HZRbLNGRoWJW4i2+JS2kUuV2aLV1qJUgbcIN\n6HloOCiWljkVO5T4lDQs2WLRLDVzmp84geA6J/H12dq/R+ZTEbWxWS91Bfoy\n6gcjLQTsF9f51GVq2C+XryC4/cQZL8Nb7koMmw5sUJpSYTmSyswFB02HS5pQ\nJU4e/vWk1Eq0QvSrM5oLezYl6LE+VliGFKbHeZQBNP2pn94ecB0XjNga2Y72\n4LiV3nYAY2w6f/kgZtGUVCFgLRdg3BlUs1F+YPkIvnuF9mJP2UxCxRK60Vw5\nMBQ90xP4022vpCUgesocNgzgasWkLydO+QHux28dg3gj6ePtImglfifMxSYR\nvdOb6hMVNLiYM/2lFyjxUmcVWNvc3zE3CBnkuwAS0tWxvdiXJah0fGSIhF2i\nz1GD9sUg7vVhEBbNYuAVlgVTR1eXDxmea7O+vIhL6u6kH29cC9kOI4AxLszz\nlI36/vR3Jq/EIyKPgtZV3lexunxwHK0VoCFaalxaqDggQknef5/vWstf4eaq\n/M3f9EXajrcRdTtsEeaIdGP3bGAoezC77hwlSm1KPy9XQyZfY63gPrpxR+Zb\n6QpxLZKUaeQF93k9mOo1CBjoNH/0aL42hhzaoGal9eLcpHI2mzmTEU14vW2Z\n/HZh\r\n=5ngx\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDLuCIbG6/N9sQOPi4eclztSZkWLaczaTOjIgN7krhrAwIhANzWAQKK8/Vcqx5XM9/RJ6q+utAff7acUw+/3GUq05fy"}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.53b58e6.0_1627496793232_0.4844394905856957"},"_hasShrinkwrap":false},"0.0.0-canary.53b58e6.1":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.53b58e6.1","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.12.3","@babel/plugin-proposal-class-properties":"^7.12.1","@babel/plugin-transform-flow-strip-types":"^7.12.1","@babel/preset-env":"^7.12.1","@babel/preset-react":"^7.8.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"2.3.2","fusion-test-utils":"2.2.2","fusion-tokens":"2.1.10","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"2.3.2","fusion-tokens":"2.1.10"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.53b58e6.1.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.53b58e6.1","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-VF8WZfPtc80Aagwuk7lgxlODjv6HLqo3A+ge735RpF0OOUgWAv5MEHzFs9sp7XSVa/0ZrGbUKmEv+uyaboVFww==","shasum":"1065f9528372fcb12493fdd79eac270f974253e3","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.53b58e6.1.tgz","fileCount":24,"unpackedSize":60741,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhAjYbCRA9TVsSAnZWagAAe9oP/RpbE/JjKFBBgc2yjmSG\n3aaFxabLlBqQFa70AF9y4esH75GqOsWeGn8X1OO450H9Mmyw3pVW7CavswSp\nERSM6lXuZVCScGHPIj70yLJcm1O7P6mUCCl6ZGXM9ivuKI+GQhuJy+Yd4Ofi\nNe6iyHTBylxlTZ8VGDkGw413lVoEJU3gqYsiYN0xaUH488ADaVioOPZRqSNr\n9Cld2Mkgw8vHVMZlUrdE8mPD7EPuc6eYu3GXTGTjSXSDSUpuS3SRcLwChjmx\nmQeM3hhuLp2L46/HrMyUxmcJc/qp1dUsG134HUYgqbesfjjnWjoeU1T2SNyQ\ngf6KnJrUwl5T9WsZZ1KKASpeNy4/BUEuI3O82cujTAtem7I+ntla0tt5pGr5\nrtuwJ2JklPVSzjL04/q2f68M22zK2vK7d1OYEZs+ouvoUpd4kCARgBhSUyhK\niarA8Pdz4wFL7f16Obtum+er89i/6LvLKBKX9K5lxOrzaIweGLI1GoOouZHp\nuKrxappGQmLqcYRIhbrYFX0crs+McgiOGVt0VOYaAcVGRB6yZaS3nnDDVi6K\nIwy/OhwDqS3mYi3YEGt+hPZ0wREnCPWaqmFiE03mQf8mnPeR1LMTOL5YgmTE\nV2bYh5Em5Pi0OZJKHnSOcMt5ftb0Idd8geLrzKJpQ7+zq/NlqMcoSMvi1Z09\nKfY+\r\n=95Th\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCwQAVIY7dhy3LWduKFkd7AOXgZVv814ha/y4w+JBfoAQIgJSD2ogh3Msjcx9U3nZEWUR/saR7TTBIaMawDEv2DcWc="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.53b58e6.1_1627534875483_0.08264377027738878"},"_hasShrinkwrap":false},"0.0.0-canary.d9ecd19.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.d9ecd19.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.12.3","@babel/plugin-proposal-class-properties":"^7.12.1","@babel/plugin-transform-flow-strip-types":"^7.12.1","@babel/preset-env":"^7.12.1","@babel/preset-react":"^7.8.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.d9ecd19.0","fusion-test-utils":"0.0.0-canary.d9ecd19.0","fusion-tokens":"0.0.0-canary.d9ecd19.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.d9ecd19.0","fusion-tokens":"0.0.0-canary.d9ecd19.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.d9ecd19.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.d9ecd19.0","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-An7JtC0WJh2JwMLXp58wL6kCsRLNJEgpENRcFT84jBEuRV+Yc14pbYtk1/26infXrnDU68mxKjl+XZZK+7C2YQ==","shasum":"21ece4ae62d4a2e7ef8c7fc9999f283d569ba410","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.d9ecd19.0.tgz","fileCount":24,"unpackedSize":60824,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhBExFCRA9TVsSAnZWagAA//MP/izD6LmD2IBBXE4RHB1Z\nXH5SjkCjs4UN0G1Zq5JEzZBY8Fab8sty4Ad37hojzD9p8uqRgyICrRSwpfPK\nRGx5aqMgjSBOzOKPDovcJ1kIrPfU6S9LKUt2Ft1XYvAyxX6n+ncZY2q2u7Mf\nuxQmg+TUG44zuKJGOeE2pYx81QLaJhDdCE/UUqBsBpElp6CI/4MRy5RjzSnB\nOKrINzhpfH85fMSOLDM4Q68spZSeoWlYKMU4hagl/movdZLCnMBz8v7D/HQ+\nf3PDMBxv8oiVJ4MIuBf//cZsRF4A2wPuow7A4yvXbC8HsXZC8ovc7HvpKyD0\nOpgK5nOUGLWRYUWdZtXTr950su89SrxoWPtPdGWa/WEM53bJAAn1znhDusAU\ne71dYfaIhZABkeuhg3lhJXf3CJTbBCNDBE9ABcDyXym9XjBbvbg+XvN6rrU1\n1It08cVl7gPx6sy2Mx/I2kynepnbjtgbScoHsyKQs3iT+Fp2yymKYyKcksco\nLQvj5+UTxJu4TwRR9mPPCqIm39r3UUEh0ccpe15Oq3oWV9+aG/3PYyaRXH9P\n7WTnJUdsJASAKfsZUqHdNf+ODbzbSqxMWkTbhAUba9OPSTK5xvA/8lkrsxio\n3bbEmkcJS82chwixP1PJWId3TYhsUhoKFmatDlM1iwlNUscnGfu6mtjCohAp\nFXrZ\r\n=woC+\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDnRh53MaxUQjPtZC+2F+Pdg3f2TH4A8/VRvMVDgWd/mgIgRDHi31z/uAUxTpbJX9W4Plg8i/WLc/0HPnap7Ho9Y+s="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.d9ecd19.0_1627671620918_0.573662614670426"},"_hasShrinkwrap":false},"0.0.0-canary.f0b60b1.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.f0b60b1.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.12.3","@babel/plugin-proposal-class-properties":"^7.12.1","@babel/plugin-transform-flow-strip-types":"^7.12.1","@babel/preset-env":"^7.12.1","@babel/preset-react":"^7.8.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.f0b60b1.0","fusion-test-utils":"0.0.0-canary.f0b60b1.0","fusion-tokens":"0.0.0-canary.f0b60b1.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.f0b60b1.0","fusion-tokens":"0.0.0-canary.f0b60b1.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.f0b60b1.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.f0b60b1.0","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-92rHEHGnzB9TgXsEA1aab+9WtEf67oIAHXqYTZ42uX3AXL47pHgMoMOPPQ9+6xnA27LdhE94BxIVAqLjP6uMQA==","shasum":"cb90068cc37d3ede325033088b28d5e82a42c577","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.f0b60b1.0.tgz","fileCount":24,"unpackedSize":60824,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhFZ9jCRA9TVsSAnZWagAArOwP/1ijiWhyoGAZ2o/LrLGk\n5EXJsH25eDepTrZ6a7pOe5wSMMfZUnNAqM1igV3MhN5NPde6A2zyvTRgz4oI\ng/x/ABPRgpdXVJKE5lXy5asGYukF7yJgRWTNBdJbGniZp+brEHFDTEjxCuOR\nWvAw5TGFW8hHryZCkDE70VobIex4p9Dkw3Khgcb6ur9VrTfLwlc4M75RPswX\nYRAZTVJbFe2nTPS9I1oIDUPxGH4DU48Zp34lE0bwO20MPZTn0FLO7/tIIId5\nELu0r02wGGqDXjkyzJy94SosKLbfLmdrPv72TcHoCEKSHd+FVQcx/LsTDQjZ\n587MKkdOLSAeIR4wMclRWz9cILleebLNtfxJVLkHmu6yC1CB0QDgLHq/PS+r\nsnM54aA8yMDwHLRj1BUe5fpyozbt5r23AeuetgCyJ0yGhJplWZznKoNoGVuF\nCSgelM8Mfk1a831YDaM8kPHhmRuOyzJqx1w869rx32k5iHs0wGlNhci4OKr6\nLWhlX2wK3gkyjqzkdCmrrIHF5ToTxgRLAJTrQtBrB7gPz48fN6ieUZIXOxis\nBvG1Y3J5PPJ3fx7uUw7XlDaSD5ziHkAaMrU98plyOrwimZ/0qIueXiglzNNv\naNyDOWxSCIUIv83dPnB29nNZE4eS8QUIIdpr2M/N1QkaH8w6aPdppQuGKoF1\nCWIU\r\n=xUq5\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQClqtK44WsdgA/Ms0AudtCBlRfEtACwM95Q6L5/hezsZgIgUx+TI1ZZy8eNqJbFAqXYwyVrxNWP6QmgujzO+HsOXiQ="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.f0b60b1.0_1628807011238_0.5525756588043684"},"_hasShrinkwrap":false},"3.1.12":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"3.1.12","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.12.3","@babel/plugin-proposal-class-properties":"^7.12.1","@babel/plugin-transform-flow-strip-types":"^7.12.1","@babel/preset-env":"^7.12.1","@babel/preset-react":"^7.8.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"2.4.0","fusion-test-utils":"2.2.3","fusion-tokens":"2.1.11","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"2.4.0","fusion-tokens":"2.1.11"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-3.1.12.tgz","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@3.1.12","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-OfGdOHh7Y2bCJLHp+vxkZ+5WzaZxJiWtxjR2Uk1ugqY6whIT4iouyEPwkZSf/9ETedBpDI7Jg01OsyW3plf/Ow==","shasum":"d68a124f387005e56dced6054063cbce485ab2ae","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-3.1.12.tgz","fileCount":24,"unpackedSize":60725,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhG/Q/CRA9TVsSAnZWagAA5KMP/33m4gT/A0OGx/rWUkR5\nduarXuZCiQGAnecQ2VfDnWYROD1HAKBRtsDUjSZ+TTdigsYdM2lRARyOTg5j\noRdG16vAY15yHWOKnVxPzZ77xnnsEIcXJT8y5uCWsTeboddfhqIXXjb0A40a\nQW+sutYlzPQpNPCMEIg5pskvsa/neghCrrLm3vNCBYsZ8bDFTmEk+tmDi953\nVZN64vCIn+dy9H7kqIN7v4YFhK0KPBqiT5XnduZzCcq1FnDyiiVNHrJW0tZE\nJZIleCu6zB9BLwx2HLSOyOki4sArFrOFiuqBi+aZetCXEw4X4EwRAHzmaLaF\nuid97jiuzYSdzl2m/W9EtTehRVafeDEhUREX99yPONr6/nmh5j4ihgZLd/vG\n4sf3IazAUMBODFqttMP5cgr4uQn/ZkTx/a0/rDto5DBVgbFmxA3cBiae1PD5\nPLOo1oor+Bx3kj3NM5hvy63JE9LXs6QKgpO3k2xpuCglJJAQFDILyjMOjnbD\nrXHRy2eeJ8rbsvjlKy+fyMQx1GxcKykOJz7NkxsGda2VktPw3+fNp8KEua30\n+vO1LDyEpFzzcSanHXhwytwf/ztN+SYweDfbu0ieVAYEhKP5sfEy01Amwc61\nwfV45WZFh+N+NBAYNvuS26VdV1bgCdLbncX6j0xJnMfc+Mri3HB4nPMr33xZ\nM90w\r\n=/3lT\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDMPy7QTLySQEPhC3CJfR9CLkW9REkgD9IJgTzaYvWsAwIgfK3vi86enCIsG5vFS+F+RWN21PDsIJ3ypDY2c40KmpU="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_3.1.12_1629221951069_0.3123016116368069"},"_hasShrinkwrap":false},"0.0.0-canary.0833d86.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.0833d86.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.12.3","@babel/plugin-proposal-class-properties":"^7.12.1","@babel/plugin-transform-flow-strip-types":"^7.12.1","@babel/preset-env":"^7.12.1","@babel/preset-react":"^7.8.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.0833d86.0","fusion-test-utils":"0.0.0-canary.0833d86.0","fusion-tokens":"0.0.0-canary.0833d86.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.0833d86.0","fusion-tokens":"0.0.0-canary.0833d86.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.0833d86.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.0833d86.0","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-qpjrdm+zrWggBO/i421BdP0CLubA875rI1PMs9Y2lWe7sUsQAySQwR97p/LhKNMWnk/TjUjawQZ/QGvJRViFLw==","shasum":"28db69fb334c4ef65c9db2bcdd799ab021168248","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.0833d86.0.tgz","fileCount":24,"unpackedSize":60851,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhLm2VCRA9TVsSAnZWagAAET0P/1Mgt8Kj1Kgbmni+X06m\nSXdC5VdVVkIMthcx9ppOmzLoGPueJn3kp5IL/EiEFctDABtDNotQ/fFhylB2\nAlt4GoGFlukNcalW4LA9xlrQKmREJU4JzU5NeNcMs5MM/RAzNayu2aHNwKuw\nIGeaf8TFCEI9L31kmERiwebJZEbCPtEv/iFPP31MDXliIfOt9Qoq8oNv56Wi\nEtvznDTksn2r8RzPvIW+I+PKx5DNF2My3SJqR59txc2rLUIQnvEP2RQOPVtK\nT8dOjDxsvf+aKjlK7RAzJhyhFpu7KI5Raf9h7f1GjWxUywkddtk2+iSqyXOK\nvAJ8Wn9opayWTo81gg9stDNUDnK4WmdOqBxznvONUdiP+gJj8IjRkhPeeBwe\n9djqkoIQKYPJ5l9CeC4VH/KACAYo7d6yC68EAWZhp+eCnIO+uEB1aEsX233f\ndZ0kL7kHR5kBWRA+iB2O+UX4YuKJqvyxEzbsP1DaN+e9q7a/Y5HhwyObU00l\nDlEO9kdF5lt8jGd2ghMRanJXwx1kMc72Ad6/5BZMNVjqDDPv/Y/5lAxw5RTW\nFFoA6rHzzZctYrUEPRFMcwSOWty3jQyWVTF3SstfpRwsuSaxxZ5ACGXGUm15\nMtfr7Rd1UQzVlrwJ571M3PIYEBn0VX7hgTjPYkuqXhcOUA7UiuZ6QG41YH4e\n4uxO\r\n=0RHm\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCBdrJUadDvygNwSRAJk+tz1oj5wBncDuAdkx0eGObiQAIhALZ/VWKuPe8C+oW2NXOzd+K/ErirCP9qvd+wQxBMsDNO"}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.0833d86.0_1630432660948_0.9097890623319396"},"_hasShrinkwrap":false},"0.0.0-canary.009cb5f.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.009cb5f.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.12.3","@babel/plugin-proposal-class-properties":"^7.12.1","@babel/plugin-transform-flow-strip-types":"^7.12.1","@babel/preset-env":"^7.12.1","@babel/preset-react":"^7.8.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.009cb5f.0","fusion-test-utils":"0.0.0-canary.009cb5f.0","fusion-tokens":"0.0.0-canary.009cb5f.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.009cb5f.0","fusion-tokens":"0.0.0-canary.009cb5f.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.009cb5f.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.009cb5f.0","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-gzBKtFokm53u38gO+amPfJUVROYFZuQIak9zi3AF/muLYlyWILeeAnvV5jofuNTB4jShF6HWmb+q7FTww8SsLg==","shasum":"019f644deb7abace206b46c0869beda4c3d850d0","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.009cb5f.0.tgz","fileCount":24,"unpackedSize":60851,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhLtXaCRA9TVsSAnZWagAAmkMP/ig4MrRvVgacX/4XBwZl\n3LYVtXBHq07Z1DZKbjLTjtpzVShCSxgVsvuDAJUODFVlE+WlsCMW/ZO5/QqL\ndBCdcIcvqAuTYy353A2wYBntA/TTbG8q2ZzUQaXElMeCalAGQcJkXE25ezzg\nIxBlRLq9zi9K9VRRFxRUpvhKAIDLKxtR48LRfNfrH8nZ5P04WHYkbIB7vzh4\no2LxZi4xkWwcJaLbQk2JcAz36oER2BX8bvdD/n5HqsgKz1QRPeOzaJQUtehP\n1NW7KQ4Hmnu0Ut6DYLqWIVNqP0IeMaqSbEkc31RuVZk62zWNhHsO/bbp3hKp\nd1qelmIfeYdsojypFAhYhpyWVIdkQ8muU1Vnn8umLojdpPOQU4c3pWYhwoZg\npra5OAylcD49bZdofjXW+LOxS5uZDpAIbIq+57s6RUfbmWMgZv3H5sTfTXCM\nAZoL68WBVc6kXdh6eg551M+3yUbsWQShL8us/BKbPiN+VaiiLlUviKckCHJ3\nIqso3IF+QPrG/ZOPMYL2Gfh+/dQnjQ5JrdGqggVtLufisgL+urooqUdaB6Yr\neyBB14fMUWiYu0T/I87hwE6s0zWp1imQVqx55T3n79bzWZJE3QPvO9ZvjEnF\nJPkzPnyogLCb2LXMyZkCeGnq0mm2P1SI6y7jyhd1FJb5T2IlgtUAcZsHyXt5\nzsCm\r\n=HbNU\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQClF2o+IG56Yiz2RIyXd1vLgn2aOckmX+kUlb2PvDfJLwIgUqJZUMAJK5V3YgENeyVXnA7IwxPrZP6NQMbc8k8YEyw="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.009cb5f.0_1630459354782_0.15349854886392156"},"_hasShrinkwrap":false},"0.0.0-canary.34f1f86.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.34f1f86.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.34f1f86.0","fusion-test-utils":"0.0.0-canary.34f1f86.0","fusion-tokens":"0.0.0-canary.34f1f86.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.34f1f86.0","fusion-tokens":"0.0.0-canary.34f1f86.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.34f1f86.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.34f1f86.0","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-FxKetby9CL1LMrEVv6B/v5TKg5c96Lo38kF5Z7F1afWQ1ROBHXyyQbNNZg9iy9G1JA31KShzJPZg6kymSe+Xfg==","shasum":"9efe32bd0bb0dae898e51ddca5d16c0bc2eccf1a","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.34f1f86.0.tgz","fileCount":24,"unpackedSize":60920,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhL+uhCRA9TVsSAnZWagAARp4QAKRCwy9wDtRoqUGyAABc\nofS+MnArH8j5z0POFCB8X+xKmluCTI4ab9cowhlF3g01+RT85INSVw+TQ8l+\n/sYZgUY0QyoTOd9ZOejq5Bjy4CpzbkOH16eN4y6QIuDCT5w1Gp1/XUTWUK09\nZL1BXt6Ibo2TtR762z4vrsLu1p57pmOrcRIO8yIZDQKz4vgXlph4mHTmVckk\nKnVeC0U3JILe+7FllcdiOCDQvtIWTPoEEOxltIkCmUa7unQMRsKYPm11EIXm\nWncRtaQKM+Ly4D7pZ9XXx+W6ldIGCCodLezlMpSFPvR8LMpOkfQhYFdNxiT1\nmPScoAPF4jVSc04x2RNMCisnTxWDKWwm1joYWHegCKd3aeQnuvnvlVJOj4Hk\nZ4+KE1oUZqGxOVehBeJHJiS8Bx6XYK/Tqk7p4P3dhqI3Uw72MPjblPO2sTr6\nELG2Pf7ctp+UhLEQVbc/vURBTruOOM0RS28nz9xanrNuBPJpzvW+jd1CJ5rr\nfEa7kLPLsUnWJqf/x9rGFQAZWrwbiEHDidKQvzmCnaQVuetuXfRvWOg8/aOQ\nj9IDpZyzz97pIS9oyxqy39K/iRItsFcwI7RK70BNoDswo5CH2GuSU46iV/bp\n+JYyC0w428NAlDnHPvkRh5e782DxSQrxyAAJy5VyRvpeFkCZgycH8rJsm7yj\nkMlU\r\n=feYZ\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIGPBWG1NIcBpjL6U75bSh3ioJU9qM1Eki/P94pu3cQ/nAiEAo12pNXHOnajjlNNcrPdTusbQI23giW61iBY7Ivp/BVg="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.34f1f86.0_1630530465308_0.42143865255539237"},"_hasShrinkwrap":false},"0.0.0-canary.0f75d56.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.0f75d56.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.12.3","@babel/plugin-proposal-class-properties":"^7.12.1","@babel/plugin-transform-flow-strip-types":"^7.12.1","@babel/preset-env":"^7.12.1","@babel/preset-react":"^7.8.3","body-parser":"^1.18.3","create-universal-package":"^4.1.0","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.0f75d56.0","fusion-test-utils":"0.0.0-canary.0f75d56.0","fusion-tokens":"0.0.0-canary.0f75d56.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.0f75d56.0","fusion-tokens":"0.0.0-canary.0f75d56.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.0f75d56.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.0f75d56.0","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-cEE2hAyZceztaAhXPjJg8+OHeADBJAWzJJwZBLvrqE1yJX6M6lfDBm6kY/qI3rT86zqkJXgPrpFKENPKRCWLEQ==","shasum":"e94ff489376532f7558ef328b6667dea754084f8","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.0f75d56.0.tgz","fileCount":24,"unpackedSize":60851,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhL/woCRA9TVsSAnZWagAAzI0P/3dX2PoJ6Cpr9JcL1bIy\nHyHm3fyx4tYTt8F2NhdaWkA2UNkj64HG5vd8kV8XC3kJ3UAL58qErKYVGorn\nfqNEOZ1V/DcbrQXjx2/VyDrqCUaz7KRVIygUNYOFK0DPX05HeHeqZ21xyFt2\nP7tygQfH10KDjn3cF46z3PmMBeeA+CrBx1OlBupRYJIokl3Mhacsfmft5Wft\nvH2vHTm1njQwuMeOyZM0Z+T6cjsp/rubYJd+KrpRzKRvhYVb2eaBHcw2RQKG\nR2k3pD8E6v5HOkpby+3vWfDCSPDBlxBBP4Srg0LUoe8TrEUQf02AF6Mbwl2m\nLFHgII2b9Q+g/RkGfFdPvNBB6pTDXwvFEAcpjSL1G4+C473inT+mc5Ge6RSD\nIBZ3TziRTDJhDJ/RWkvhz/GNCeF453MoFJTieLk2A6nVFBfCx/fpjqivqdNZ\nVhwlZTkFjPf83pCEscsDfC2BXNqHhvw8iA9fCpbQbgoG2tf0oYguUq0aGGtC\npJmTbEIeO5TPW1TCOQjFlA5Pzm/vENYEhFcjzppwNQdxtgGZ2Cm9YO4dwcuZ\ncmJt9AQrDALfhVk8Vcw2wi3hDlhD8Ok0lesCe+DgaJ1ZvkUgu5ItkBfh2WsA\n8Pisd5yFR4VmPAIOX3JDhNqMacjDgVIaUWfpFc8i7G1FuAQYOkRPmBn8ijzF\nmc98\r\n=A3wP\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCJwYoeAoUunAIcWzMViQ7EfpO5cgY8T7AEvEoVf66aqAIhANgwV3SCMmdGupX40vU3aXQ0AAnCB2ov7AOg4ctuRCym"}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.0f75d56.0_1630534696070_0.8694554842849427"},"_hasShrinkwrap":false},"0.0.0-canary.addd6fb.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.addd6fb.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.addd6fb.0","fusion-test-utils":"0.0.0-canary.addd6fb.0","fusion-tokens":"0.0.0-canary.addd6fb.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.addd6fb.0","fusion-tokens":"0.0.0-canary.addd6fb.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.addd6fb.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.addd6fb.0","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-rvEiW8RBax+4SZWyQNaI+z8bFq1GhJaDPf++eYfH9o72tIEKs0L1bYRhEZoDxsPqVghcsOsMVLzIregxlaMVIQ==","shasum":"e6f1c3a0395be3102fb3b15b7041263f5fe133e0","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.addd6fb.0.tgz","fileCount":24,"unpackedSize":60920,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhMCEJCRA9TVsSAnZWagAAlQkP/1SRKtubU3cQq7PtcGbO\n/YdxRZj+CvlkYWhHJUHhYlVIhxGeT5b+4P7zFaKoPz1w9JxPb0rKAbfJY65M\nxt+pCWCVM75jZStSRsiCic5Bb4+ZtOd8yYYCxbg6v0tavAz3z66wMPxYKKjz\nv4de9Smf1MYiZG3xDnqz7CPKMy2DwVOq0kcAYH/S6tCS6F1JZ241S3ZrSBFs\n7RJ+5jJ1exteSQ2eJj0emXovkbk7J+6q5n1jIYJRcZQkXVAWwdgy5bND9vU9\nUNyKu260XIl/BwaTs53+Fta1dNPQc5k6vUyoqtOZYqmHytZh6zW3yeYnOtA3\naurFGHWt56nwk1ErJse2XK7nUJzAyRHX+eGRbbra1rn17xIO4OmM5HjFGwxz\nQo/llQ6cpsHoL9Cxv6xSpbJmylI9qZapDzfJaT28ohD6zuJJncVVs7nMDj3s\ngEmF09PlhoVXpYzMSNwDknXeGrHPeMGGWXqmOMDufDpqx1CwkZgdTrqPWMsk\nkOzOPh/mAN/vMaktEOwufvqHGP5c+FzP2IG1S1nI9YLYccGEg9bhfF587wlp\n37KZ4TnSPLszL0RwZD6VsstNdY0L4j6xfg8Ctzx5LaMqx8VYrIBqXfEGsg/s\n3gkXfJSwb7mU2PoelHDr9HhrvJCZN+CfTbdg1i65vcVMxbA49BWwY091N2/E\nnAz7\r\n=J8zv\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIC34+fEC8QwsPpzF3tYUe03OCcimje44UkGQDgASUDHcAiEA2gBxPY2bC3DsFp+fWbcg6CbVZzrEa5bMEyHlsUCaBc0="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.addd6fb.0_1630544136934_0.6472012137143399"},"_hasShrinkwrap":false},"0.0.0-canary.e938140.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.e938140.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.e938140.0","fusion-test-utils":"0.0.0-canary.e938140.0","fusion-tokens":"0.0.0-canary.e938140.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.e938140.0","fusion-tokens":"0.0.0-canary.e938140.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.e938140.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.e938140.0","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-iO7y6DmgiWfmjgtfbt2gvx5vvIyCAVqWIIjpRSgUoHBLD7/LWADAsDp0dllbmOrbbbYLXmmRv/oQMU52N49m8w==","shasum":"f2249471bc65d444ecb3557b5bee2e58415da773","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.e938140.0.tgz","fileCount":24,"unpackedSize":60920,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhOPGcCRA9TVsSAnZWagAAv44P+wYj7Js2jXCh2KxOwR2p\nfPVXvt+KlMuMEM2uKok2bPASBqmjMLI57hnm+Hk6Yw/08HkI7FYFl298OulJ\nUnddYvJ1IWsTnlUtZ8Y0AvVanMPwontgYhbFi+9CVb/qmKex57tjFb2BTzHV\nh0Pz5CKyMt5SahF4RdMd7NDXqLpxYTfohkDrSQTJAMens2D6pKXN/dLEsVbR\n4N0peRd9ESQ+kOcho7D41vaSSQE3fAeAh8zuKFab769OQhq78cGQdqVdGrDV\nOGsm8OAQRToFtCufsUgOSB6XH5IVlTXXs08IjBef+Pr+tD0BW927WJil825S\nDSkK2e32WhRVeY7Wz4hXqzfZovv5H6Ab//PyipmN0PJ/0nn9cN+Zz7uWoh5s\nXF+ejP/EDiHAWf9QUVpzOcwemPp0v7URq3qiuy0YTHcfFYn5ionE03AJznkX\nVl8nnVjW6JkM0oDhUmwJjnlGRChXfxOG4Xo8yAKGKsYCG+kwmllz1SJjpBqt\nsVUklNfQhRkMiOcKsa1j5yCXE2HYOn1zGhdq1pn6MJPE74vS/8NWRPvJRZvm\nBkoJdu63LNTeYBD83PYuC6zaCCm98zclSl+JP0jCH5B6uEj1EWYRgL7Af0cz\nzTq3qLzBSZspRXO6yQvkyM6ny9/cSQjnTH7NubaPGsmF7PFu2VLALwnK1teI\nucrY\r\n=HSFM\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDdcZxAX1Ca0j27RrlEJlhhMGJhpbCVfmAMIcyxhNIRQgIgKgKKj+PqD0Tb4WFJRv3MZKCVRvgs6R9EWd4d/u5Eec4="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.e938140.0_1631121820077_0.8451849946246215"},"_hasShrinkwrap":false},"0.0.0-canary.04ebbff.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.04ebbff.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.04ebbff.0","fusion-test-utils":"0.0.0-canary.04ebbff.0","fusion-tokens":"0.0.0-canary.04ebbff.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.04ebbff.0","fusion-tokens":"0.0.0-canary.04ebbff.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.04ebbff.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.04ebbff.0","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-AVWU2pBEWM5OokdJrjBMshBJhjsqn3V/nZD1DOqBOcyAlqN1s7h18O3lbcRF269qG2f/cEj4cEYvRqDHRyO2rg==","shasum":"d14fd12698990bfbb47b7ac328be45341c9a61a3","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.04ebbff.0.tgz","fileCount":24,"unpackedSize":60920,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhO5I1CRA9TVsSAnZWagAA0c8P/jRoBgd7yyVRDGcFqkqd\ntxlYLSbMmCpmLn7CeoWL4+DGcIVxEzczhdLviIhwLnmO6tzCjmsci28+aMV9\n5+/Z7wHvBxqrkUrhADtzijycWhcXTLa4vtIHXTz60IPim44Nfmq11G4TD8AH\nGdLBnD8dZFBob1AqnqYIIFMxQm3Vwa+EhisCHJ0bt1ghWfNvY2FO1qt2UO24\nRqT7TnfK8JFli8Y05cMwguFtkkMO5Tvi7DM/40xAZrrNLLVnAw10qjkfV7P6\nf+f3bNSoiIJqIauA/ebVu2obrX8ik6cSJQKO/4Qn+Wx364Lpg71pMxa9taMM\nHhF6ouCN90hGwF/FNeOKywJHtXuRR515J7nmz/BUQh5LhfB9iWNquoCf+hqy\nmgT7sllMrXNUPZcsEKgcGLi+8fGtt/JknF2EKTiu8BE612/nXkncqi0FEMq7\ndzm2BFIwzS034mJJOf8alMZhYN/X8gRXU6ioJbKmFrfxPQ6HfW2tHkJLZVUq\n8RD+fX/mbZ016mMGC7ioYiry8L8daq5WPEVEct5TDemk95pTAalcO+MJbVkP\npeLaeGhH2KLoEnhZa2TKQrXBR3HU2DRnpLbEG1v+ipkJ/mMxDbxrqvzx1eIM\nDo8Y6TAJFdWE1ZAb5sN+nBHgeS/FFjD7iRg4dGf9YH1SH55qxt5e1uC4D94e\nNxMd\r\n=Wdxx\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIFpc1wZBiHGANfyas6K6cXX+OikYU8vw66fumqRrN3RrAiA82STbWrS3XY9wtyQjku6v26t45eRt0vYusDfXrprHdg=="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.04ebbff.0_1631294005346_0.6408183909910838"},"_hasShrinkwrap":false},"0.0.0-canary.77d64ce.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.77d64ce.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.77d64ce.0","fusion-test-utils":"0.0.0-canary.77d64ce.0","fusion-tokens":"0.0.0-canary.77d64ce.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.77d64ce.0","fusion-tokens":"0.0.0-canary.77d64ce.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.77d64ce.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.77d64ce.0","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-GyQlD2N1ivhaWX/LUn24i4Pg3K7xOPSVssZhpPMi+EE+mnHBKUYRiwflFiCr2NOLpi7NQYErTSk6pAAsrsVKzg==","shasum":"35febdb1a9009a1729994654f2d59b88382779d8","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.77d64ce.0.tgz","fileCount":25,"unpackedSize":61609,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhQ77sCRA9TVsSAnZWagAAW4gP/2p2ZjkiE7DCy9dCDiFF\nOYF1O+5wRRDD0lxId5BmjPNevo+Jq6pae3HM5KMd2Cm06Q3dsfJHRXO8xbK2\n7Cf5PLLUqld51Qo1QhGy5Odx8f9k1hRICGCflruh0x/Wg7jw9wJugN4Eiqtf\nYYIx5DjdgkrE/Drvf3gKXDeR0dq9OBR9cJO1mooFbEzPB/lCS5cWpCF26FS6\njvTWRD1Foa7RDmzu4RJYzDmolEy8f30Jj5zA2gBPVCBYnPCd3lPP9WvdrBLl\nTZnTX6EeU0Eu+1eiY+9i85IlX0x+XdSKJGmix6bvNcIo6PT+nUyxQcN6nhLQ\nKAeraL6UyTtutuQ/ms5zL4L90VaEhf2OurPuOMfc4eDHOjesawhMa2kqYkol\nzHRfUiBaH2YfI5ZqAv1L3hhnDbO107r9aI47EIPDUCnVFNkBLu4BfaIjAI+r\nsH89JuMTiv/Le2dqYDU6crqsyw8PxnmRCL8clee84xXsaynHQqwFnVQeYe6z\nqHp8R1XzgEn+m57A/NV0nV5ijD6PjUJ6HLBY7buRdgEj+5SDnwpZJBWpjZjW\nAIgBG1wBDwm+b7ylMYQww9fmfwDXkSNCnZzRkT547BF4u1Ro0aJqqVUsFPWx\n+0BKHVoAKeavjGSXQ1E23XJWswtlG07TNP1nCW3HMU9FwWvUfI/jqrviocsv\n+dex\r\n=9Ntr\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQC+6mMg8rI3D76sc7QqNQE7HB1QeGRfHI8Q6UKnoEcVpAIgWXmy6Sq+35jgbRPGgDu2ZaiTmouTlGGL1aKVEGOkjPg="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.77d64ce.0_1631829740734_0.32737627700835104"},"_hasShrinkwrap":false},"3.2.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"3.2.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"2.5.0","fusion-test-utils":"2.3.0","fusion-tokens":"2.2.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"2.5.0","fusion-tokens":"2.2.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-3.2.0.tgz","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@3.2.0","_nodeVersion":"14.15.1","_npmVersion":"6.14.8","dist":{"integrity":"sha512-wDgBitqUBcl+Lh9N0HSp/MUpUKbmgto3q2rnZ6wCWmj/P7bBMB6jc1kXrnA1GlsnoVa9IO8mkNca2my/jsgyeQ==","shasum":"aaa63ed40e4e617e6a68af4521e8fe002e811148","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-3.2.0.tgz","fileCount":25,"unpackedSize":61507,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQC2RQ1649btB6nro/LKa/ipnEuuK07lcNyCWbHwlEk4FQIhAMBLgW/XEY/NjJ0cl6HXIrGV2diL+LIptZZntlRAEQzk"}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_3.2.0_1631897901171_0.3949675083931474"},"_hasShrinkwrap":false},"0.0.0-canary.a5335ef.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.a5335ef.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.a5335ef.0","fusion-test-utils":"0.0.0-canary.a5335ef.0","fusion-tokens":"0.0.0-canary.a5335ef.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.a5335ef.0","fusion-tokens":"0.0.0-canary.a5335ef.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.a5335ef.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.a5335ef.0","_nodeVersion":"14.18.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-eOHiO610YnQQbXGstgBuat+JassGkVLncsZU+w5Bbu4cRZisq6n1cHzssMlzB6LdKlFnzIV5Tb92oVxbPlk1zA==","shasum":"0efea58baf5ac507712e537edb12fc5832489ebf","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.a5335ef.0.tgz","fileCount":25,"unpackedSize":61609,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDnHxyCS2JknbcriM1BNoj1vXjLYoDyIERDZQolsoCLHwIgCk8QrWsyQJMHfH5n0vlTSiwGBB58uXiwENGM771mWt8="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.a5335ef.0_1636408566718_0.42999076969008687"},"_hasShrinkwrap":false},"0.0.0-canary.99bcfaa.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.99bcfaa.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.99bcfaa.0","fusion-test-utils":"0.0.0-canary.99bcfaa.0","fusion-tokens":"0.0.0-canary.99bcfaa.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.99bcfaa.0","fusion-tokens":"0.0.0-canary.99bcfaa.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.99bcfaa.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.99bcfaa.0","_nodeVersion":"14.18.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-L4qyeBgdoQ0yPcd/igEvha6e4KTb09Y+rOOxRx1j/iSESbgAJeRIofHCBq7MuEgeACqPTXt1G0qnB9pkKjIc8Q==","shasum":"a42379f46af2792378da110c6d9f5a909f9420ba","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.99bcfaa.0.tgz","fileCount":25,"unpackedSize":61609,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhkuFOCRA9TVsSAnZWagAAqjgP/1CYPj1mNkfWZTFXn3HM\nTt2b2h5IispKVavDHOWNzKQh/4EseLqxKG69W2KUHzBnGU3xhzfhMpMf91Lb\nzSvTRiAu+nAeGitSPGnovZI81W6657l4ltkU5hl3juwNt2Ls0npg72vshXuR\nJdlUZj7X3p/iIoGJuv8s+UtWYiu3TWnJROKwl2B02BL9xoim8uDXOThar8nU\nWCKDXzOjPaOAThgf+yV3LgNWDEVi2NXa8/mowuss86gYX1/btHslleEniG61\nkvWrS0juXHw/NDTOjSVmHqo+wY7Bj7ShfX9xSKvVsYaS0z8dRDb7KNG66YYz\neqLsHAesPB73cKQv6Yu7gvnCssFOV2xmw5/IOtbWdSAPHhuBWzNdg+MUeBPo\nEGAkoajXgn77zD9BTDpWIHY2aolqU2hZ/IaIg9lKoWP6fX7cEgueOQ5bsomx\n/yY8/R4V6fY8aMpWt9arWhljSJmt6DKwhTzEuwNL+x07XjJhjQ/rPg5H8V0v\nMdlxG1qFqOX/9WDiN0CfIVmx/v9Vif/RMNWx4ashf1j1sYZWuAysk4I2YmON\nmXZlo08LcFeL18i7X3Wk09Df/wGwxZt7nJKsfQiSV9MP72C7myVxsvWfzsB7\nmgJ9Q29gT4oQ/PznpyRM8qsqIYHM1JFjWA5B/KvTlTLrQiz+7OcdIs/nWtU3\nx9W+\r\n=LdFU\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDcLulk/x3pBtiEldbTxoYguqoovZ+yC+cdMTBgHmE7eQIhALtO3kXNykn4uNxxU0/VPqPv9BvxteoVHLxuf8OCjap/"}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.99bcfaa.0_1637015886291_0.06629259180907066"},"_hasShrinkwrap":false},"0.0.0-canary.858e9e0.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.858e9e0.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.858e9e0.0","fusion-test-utils":"0.0.0-canary.858e9e0.0","fusion-tokens":"0.0.0-canary.858e9e0.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.858e9e0.0","fusion-tokens":"0.0.0-canary.858e9e0.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.858e9e0.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.858e9e0.0","_nodeVersion":"14.18.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-OXFGRwCrwWiZwyf2mVqUr62LWHzAdSj8xlbPAea+akCppzvaUP8mVriymJNq/y6loAEl7exlk9lI1ds1JJgqSA==","shasum":"3d8b47b743e049cb1bcf13efe1f23e692935d1b9","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.858e9e0.0.tgz","fileCount":25,"unpackedSize":61609,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhkv8aCRA9TVsSAnZWagAAZXwP/RweoE9U238WT4sipom1\nrwt+uKbtJeLRfDw7LZenciy7NkEuNA6osuyOzBIk8gzd+rDZWcoF24XqGgTt\nbhswG0zFvXm/idn9KGdiqpUKqCxmidGqvJCgOQvUSNpKIZws+37D/51tJL0M\nXXh1Ytx3crPq80emUh++h6ozT/feNXUrdENcbjEm0E9n8rp1zPtMTpACZVnH\nFEmQ26beJnQx5W7OAFpYKnbZEySAysIBnHYaSN9UwwY9AUiy8Y2/V9zb28XM\niSwZremOjiUx0dCzT7RUoJ3/8mf1kuqElrcP8s31CPcbcqk97cIuiPHkO7Wz\nnm8zh95GROLhO1JxrJtoDvIy8OpE52h9n3nskzbIKoyNenGrCfk6WTq8DVwX\nbIF/5NrmZn9Sa/TIA3NW2LRPvVe6L/M7Lt3oAQ6CwP0JMYwfffctHcV9bjvQ\nYYJss7Ql/4G4z5nVpzw6g9lvy6i6itdPaxUy+up3sCYvQNeIHEjRrYRJtJ2z\nRm16gFwZ2L0qFAV8Da8aQwpeu6ghI1HIHBO4uJ2kQgYnzAaJkx2muj0+39Ma\nlJaRmB62n6aJngaEaXPjS5MQfhjUASeOJk8vv93ZyRDbO6kQEDSGy6GsYEry\noOe6ZzYw3m3FdGoE1HguUq3bv4/AnsCvs/rhBUXujT7KEuUAGayfeTmxq+BH\nofw5\r\n=UWQH\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQC7aF9cWScOfYDBG/r4GHWec53Yn/xyIxDRDyPQ/RVOxQIgdKyWRc0DH9uK6NHaSt0bZCZGqN7U8JZvnXQyiyEs3NE="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.858e9e0.0_1637023514034_0.7150654807833396"},"_hasShrinkwrap":false},"0.0.0-canary.940ae04.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.940ae04.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.940ae04.0","fusion-test-utils":"0.0.0-canary.940ae04.0","fusion-tokens":"0.0.0-canary.940ae04.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.940ae04.0","fusion-tokens":"0.0.0-canary.940ae04.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.940ae04.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.940ae04.0","_nodeVersion":"14.18.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-uuu4U+45pcjJOYPblgyOkK9r4MCbRbPoeEavz2FK1VaWJK8DjVDGC+V+tqJkc+UzwvYrz4j7aQzpj4kcJfpvnQ==","shasum":"4279c031a47fe89598b87a70a2bd0dc2de8de069","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.940ae04.0.tgz","fileCount":25,"unpackedSize":61609,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhlEn9CRA9TVsSAnZWagAA+7cP/ROK+dVMTIjIXvOXjYZt\nIO3tbafHANFRMaTyX9NFWTgfTloSyM/ryO2YcOsmjaWUanEwTK1d0Qt9kE7Z\nx1jxeviOej7fSyb5JytRWDVxtkGRKbu4cSNTlCz5vAUT328z38nTi4nEPDmm\nfe3b6xB788HnuowifLtaYU4NdPZ1LetxFJV184fVSHhwAiY+IdF01jKHDct5\nQhpGcvpNsEnkNVyXXR+uVKN18FC9gZA/rXGrmuhpm2sLl2NMtcbzV0Ja4MNC\nuWQ4lRsrEpy+Se/wVNf0Ie+wixv41cbGjc0fIQwjP15bISKb8/jHy9FAp/y3\n+VzIbhJiTSBzE8I79N8Ol5HPZ1GpPaKtjwif45Le2/iU6Ua6517u04+0eEBU\nL9wpZSeeR5IEvIdkhGt0vNgO7YLA2rhAv2g1p1O7gYM1Zadlfr5uff2ylXCS\njsWxov5TC3jrThG40grd4KcSRTEuCBo2VGylNcaiAAhcubesOObSLlpOLbfR\nJc/7atL2omqN9Srcp2469+c57F6GiHTuezjYhXdjlc1VFHKYocxqkQZJRFHV\nYPPaZUoJpVm5eMDjsZdzlXn94vhjpkF7Aoj3nKjiFktWPBK7M87h75rxG/bw\n72ar03BBrydgPd5dvGRhqnz+VqB9FyC3M7GxDcTtAe36Z3Xj+Gf5+5wYHq5j\n7NqO\r\n=6DTl\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIBrVwyZxKRpSnFvjj/YZFivv2uBvawWdzWQrJtam3XhuAiEAqV6HQ6V62ADWUohjYniI4AXiX6U8nAuq7DSvM1LGrw0="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.940ae04.0_1637108221530_0.1354493916648989"},"_hasShrinkwrap":false},"0.0.0-canary.61befa0.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.61befa0.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.61befa0.0","fusion-test-utils":"0.0.0-canary.61befa0.0","fusion-tokens":"0.0.0-canary.61befa0.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.61befa0.0","fusion-tokens":"0.0.0-canary.61befa0.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.61befa0.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.61befa0.0","_nodeVersion":"14.18.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-BhKCvVJKSnAaUAeazK7H+ofsWHehaQVu23QDUO5A5mPqpNJR8l5VANuQgiHBMizzmPE6lGjjMyqenZkOIuZffg==","shasum":"5cb393b2f7299a513224a66eed25c7406899c72f","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.61befa0.0.tgz","fileCount":25,"unpackedSize":61609,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhlXkOCRA9TVsSAnZWagAALZ0P/At6biyclXqXBr/bKoQY\nKuL2CSM72rHkaDPSNa2BQa+zWY0rz9vF5j4x0WIx5Z6J5uAnZ5ZYZ5PmYIut\n6bJuMwLWEmYQ6BpHXPq5aKLuBRVE+A+GJncb/9Xzfi4eG62KdJwK7fb9z0jg\nsXzLFkRI64GZBx2+mPs4mSAk7wTjUjgF/l9TNFk/tivAmVKC+5eKLZAtV77T\nNBdJ5+zN4n7Y3VLH4lI6Q/ksJSi/PbemVfJzaXl0nHK55RL+oZF4xDExrsRh\n7hCraWDIDP/QLZw1MopHWxroCP4BKl++MluzjD1bcNvbCf7IP8kGXwtQxOOi\nr6lbJ9w9OylKlMipTaDRi469gZ1kFH7Ezlrte9SIh/wkJ8mqTJiIqiWbQYkt\n+OjH2OPwvDqLzunw7EyYzm53kjdKEKPYavH2kQZvJhp0xnLpIXGvMH+pfzEc\nizoM3Y48VVI04j5gGLTGHc56QRsMwCazX2Gnwjd7S/MDrA2L+HWW/iMfPy5I\nKjfYSVuJE/3V6DeXiAzyX/UgPkxxLQieztISJCYKzb4aDrFsvG9avA7/C7SF\nIARJXRUS9/ziMc3jquXebUwwH3D4Px43wIGfQ26uEOrhJFgixO2gFuaecDkK\nKXRppZ1nlREelEIkOSe/dxiA5kIufXWKoMnYOQOgqUXFrQnz4UWYQWZtFE+6\n9c9a\r\n=jpMC\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCID3kX8fUqNNDHPAWZGP/donlA3Eev4/K5js0w42P/gIHAiAp3WDoP2m1K1jHVLCY+48352afpKlRMYQ8pZMwl6tZrQ=="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.61befa0.0_1637185806587_0.7540057069489661"},"_hasShrinkwrap":false},"0.0.0-canary.358ea34.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.358ea34.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.358ea34.0","fusion-test-utils":"0.0.0-canary.358ea34.0","fusion-tokens":"0.0.0-canary.358ea34.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.358ea34.0","fusion-tokens":"0.0.0-canary.358ea34.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.358ea34.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.358ea34.0","_nodeVersion":"14.18.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-90qtMLmGLZ7/e1LTYa8VN58fJXndf9lLJky45yyzcGQUL8dzzC7AMoAYm0Y9IPNBM7arC7Cvk70UnF/fL5W61A==","shasum":"c0873adea47b59d34cfff12a143d17fbd5e04b39","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.358ea34.0.tgz","fileCount":25,"unpackedSize":61609,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhnPnpCRA9TVsSAnZWagAAM8UQAJtS3fbC0tu4jowPddDt\n0aPJ/v4sR/qzaY76q/wtdLb2iTyW2+rjQboYUxHNKelcujesCma9/vs7k7i/\niRuXiX8gLS8+aFJkSz3khHPWRamWrImHmP5gqMuW5tTlCeim0L+aVcDMq8Xz\n8vHygDgijzon4qpGa4FaApJpK+/RTvbllxVXJICCzBL/WsUVW4834uaSA9vB\nJlBM+GE8NNfEuTRuK+ZYP9KiC1zAfL74MTHm2loPq5mLBBe3+CcaUXn/9slh\ndUuX2LDhEc4iPWHOFP5Ev4TAEXP6b+jaPWTmqS5WaX21v6SlV0eM1sHSokJk\nUKvrLod+dwMiryPN8QWTB+Ej1auTMc6Yn21UDWfdn+k2xx09huyfffRqI0EN\nSW/Hc9FXLpYiBWF7WTL3dpmKx93CGrhJe2PP6a1A1DSfQhWm7FARNxDRazPS\nNZzMicsFcpunFzsq+cmnD9ReV+xRn8P+hWLUDdV58kNqaPXvKZB1Yy+I5rqO\n9p8Xkpygy8d6xaAyFmzBFGlkOW6bzEaCg8oG1aI9KrQ86gKVUYjXcJf50bUr\nf95pNL6l5tJZwd7M9do1ctS43U9ZWHBm5VLnNjDVKICZzaE3NS9YN3Wt2vOr\nZtPJNmh7qLpLy20Wgq+su92wGNvlA9ASKzQdePHCITj5iVdX01/9hbksyhBN\nZPAk\r\n=QYyU\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDXy9B2HYSAEMvHETmLiMI1jZa8+myjdX/mUecXPrtdWwIgOu+Dbix7oSr50Z/1JQYsML7he/B2krC2G2ZP3Pt1Ldg="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.358ea34.0_1637677544910_0.5222071569619937"},"_hasShrinkwrap":false},"0.0.0-canary.0585b99.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.0585b99.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.0585b99.0","fusion-test-utils":"0.0.0-canary.0585b99.0","fusion-tokens":"0.0.0-canary.0585b99.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.0585b99.0","fusion-tokens":"0.0.0-canary.0585b99.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.0585b99.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.0585b99.0","_nodeVersion":"14.18.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-+cTCoXuHYbvuVB102nNatfF61678XClze8sW6oeSQ+ugyHor6Z7kpZqMtrjwJLHwSQ1nJlsPX/hMd+eYotH/Kw==","shasum":"dfde584046ced3933a5baae20ca7877eb3b1f5a5","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.0585b99.0.tgz","fileCount":25,"unpackedSize":61609,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhnUX9CRA9TVsSAnZWagAAMcwP/07A6GxGXHL6iU5tNsLm\nhz3o5t0qfc+/No3p4ZYrSSm8vQoPgBsFcTQ/9tgvj00wzSEKXi90WlfzX41g\neHBvoHl2hpqZZdoIO3UJR88lSBiHsRN06ih3GtwRLqAnEe8iQv2//4n71f5i\n5L8M8Pu8bxMH83JLUCcDNBUSv0sw7k7vtdKdfuLPgr//C7cbxwT7P9hP+oW+\nbt6dwTp0KhmdZJc3h3WsRHoPresLOwD1aoa7hbAjN6xQ7HqLL7yI3ZhLYaV/\nfz5KhxoaRnSrQTh2GsihLwdD/QUPh7jDzChoOCKXWnY6oCCBoa0omZnxV3da\nzVyx1p7SDZQ8jO/+0oXENwgWKEGrGpbHkMP+6QZoGk4RHYHFfg4znJ5cP6Y7\nO3EARGH4llHCqcAQtd81Os7ZrFeL01w8bcZ3+LUzbPNW/kwL6jLu11CGpcZF\nnAjfCVazQWdKir3t5BFBLMVwmewnDVxlASN16Io2yNkWVHlxMPwMUQs8zW79\naPTtQcI6AeDpKVo6a65XgxpcJwVCyNRHfP1NKl8mER/n4s/QJ0TtyWQ056Yn\nHa+bFmqA/dQb1cbQ+MEOcGLpg3JRVLZRm3u9ecbwKxcmcilYttYe14wLMnoV\nGaJgADlS61NVFQjecDSGxigeb+d+2+q9rDnTZUoVN5neCI1YYCQIyNfz/jax\noZtE\r\n=2ctI\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCizGRcdrkdhsfgJVYi4FqQDcl0wl26YZfAAqJCE824OAIhAIOOIGKEM4/LHUV1VRWBZI8ZOiBY1UG+m2GDc7scGYrv"}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.0585b99.0_1637697020999_0.07784053547220582"},"_hasShrinkwrap":false},"0.0.0-canary.4d4635d.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.4d4635d.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.4d4635d.0","fusion-test-utils":"0.0.0-canary.4d4635d.0","fusion-tokens":"0.0.0-canary.4d4635d.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.4d4635d.0","fusion-tokens":"0.0.0-canary.4d4635d.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.4d4635d.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.4d4635d.0","_nodeVersion":"14.18.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-IxSLvEl0/CRjSCzeWcMTq2UVl0adTWlEjYCdM7Q5qLz32EoDLpC7jNYK3IlHI9Iwye3HijQTrL7JI/yOMLSWoA==","shasum":"cbe84d4994f67636ab8c249161e4e23d85b09538","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.4d4635d.0.tgz","fileCount":25,"unpackedSize":61609,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhnVa0CRA9TVsSAnZWagAAsCwQAJovEPIs8ZYTSp9z0Bfa\nineJpis/0D/shomf0McrYNupQUQ8JgWXrfgx1uGMBRHzzTz9IwQIPE+bbaVh\n8smaKfDeMteeBdB/oIz64E4BpNrY6Bo7KRb2Vmgpy+mFLuy/kSFPoHX40Z+P\n5cbV5C/AKg599CGDuRajDwbxdNNEM1nKv3aCUxENDpCY5H8o0c+p7XGbRJfE\n2Zd8ItrKJhgKqhiarpLJg5GxTnsrkN/Prk9ksMXAFZ4EfgFSwd46q/Sa01Zz\nZ928M1rLYWZrapbaJnQulGIotPAREg9MrVEqWoiostIN4KQ/NZdfq8YedN17\nOoOQ3XJ2xmj/wemOM7Xnu+yWBFR316i0pxufE0bBy6z5mApak0PzEOrmKfnA\n2vFHw6qUYMEEoocOCNtV3PkrcZOy+obh/DNPfV5MyAYfZnTUKJG0tVMYB6ZN\nfBUFvfYh2Oh4KNuu1E2kyea0ThjfOwtOFbzZGRrQNssIE7nOukCno7zFx+5/\n3xOmLiL03LtMTnp1LF+w+a1afCDGX+o/4ZfPCKrB0gjhtBSvUQgrfu6gPA1h\noDgpGEYoDLQvFHGY9tJTy4XKJxHc4SslqlXTxXzJG10D8iF4F2TQh1xjkjbo\nZIVmRMgpeKd2R7QiK8MudmE8zOFBVbZRmjUq1oIODHoskiTj2EV7er+41Iyw\nKscj\r\n=7QVH\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQD6yqOF20/HA0c3tKn4Hj/92AoGc8zVZckwGRmjeEEmJwIgP4M25u7ZQPbYycWv4p7Tsw4UqBQgRxEATZOHyIAHw8U="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.4d4635d.0_1637701300325_0.30035033650235565"},"_hasShrinkwrap":false},"0.0.0-canary.4457a44.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.4457a44.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.4457a44.0","fusion-test-utils":"0.0.0-canary.4457a44.0","fusion-tokens":"0.0.0-canary.4457a44.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.4457a44.0","fusion-tokens":"0.0.0-canary.4457a44.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.4457a44.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.4457a44.0","_nodeVersion":"14.18.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-HGB+3kkVXOP8aw3BuQMTAsGH/5dRp0qU//vsX1wKbn/ZuQBE00wehOGuuiNZvzo05L4ydTnnytPwJ3YGwMvHtQ==","shasum":"bfb0d6c14657373b767a8fc548b39f9db5ecd440","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.4457a44.0.tgz","fileCount":25,"unpackedSize":61609,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhnVwhCRA9TVsSAnZWagAAWDUQAIEjl80nIQ87KDlEmIN3\npZGhY67UJdpk2yeGyNb+S+pkGgcZDPUOfddlKQ4M69xS313bS97rW8+vDimP\nlSMwxTMvWwSiEHej+RF8G45J4/a8o/QrFA913GmQIrYMG3ER3ZTNh6suZkbM\ns89mcGHAJX8mZ8E1CAraZXL3hCU0fNuGruKLYtG/HLNJKPpAPy/PyY/EEc5D\n6daxZcv2oNyazfFQWplL4uZvDHu6EWA2Cdg+LrF2BPiKmhc4KvlIHnrtIpQK\nk2wQLFYUXRpkpDivZzShI6zTLpL0nBVs8V5HrA1Tw94qIBMh3c/DGwZ+0gzm\noFshOKj5QjLjE6bDdzIpxNf9kXj5RsMJeOOmX9PyFjnkD3Ml5l0+P8pmNCh2\nZNcet+UjlQFcfcdg/fyG3EGieSD+E1pLUOzK7yqVwNK8t77EBrDS8vLoNSL+\nKaDxeTdH4J38gJ8Hs09jGwHV//tSGH/FpAq5xyfcW81X++d3pKZKUmYzijee\nHpugbWPE0TCvDgidlDFraktog+sK1wT8n90/wCkdcaWdZAWCNxUQ1GHY8R8o\nngwMV6VzvzE1zI02PxMHQfEd1iq6Wy6wpETurF0fOZamcEzZatPqjngHwgUb\nQkX9D76QQRI1iRXuEFcJBqIwdoBOIguavdDL7rRfOAQ+17/lLA2owaRWng/3\n3fVB\r\n=gsyz\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDorbQyNJFd3rk5SEUd+tn8qxGTk7AuUvfBhtLa4a0NkAIhAMiXIwQEIWCqe2IUUMx23FKGPS0nbNJ4tQAprQACvB+s"}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.4457a44.0_1637702689197_0.4652987694643256"},"_hasShrinkwrap":false},"3.2.1":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"3.2.1","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"2.5.1","fusion-test-utils":"2.3.1","fusion-tokens":"2.2.1","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"2.5.1","fusion-tokens":"2.2.1"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-3.2.1.tgz","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@3.2.1","_nodeVersion":"14.18.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-dLQ1xbQ8ZfgxCuvXyb3BaTXoZawKuFn/zmfmdvgIgQVGXel2jMM/GWjUFYrWJZd5qYy7YM4ZX6vN3JRVYd6+rg==","shasum":"d084cf249858582425d55f62c4ba082720648331","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-3.2.1.tgz","fileCount":25,"unpackedSize":61507,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhnr4KCRA9TVsSAnZWagAAXw4P/jPYo3NnhEQgw09seazT\n89dY9S1AJWI/9G5cjwf1/2IV3kdvFh6sa67nKen3Eu3WAaxjqWDlcZE0/5Dw\ncKm5Anw0pDgDChFab5ULK3KZxK6fhpGV57/nzmkRbFFd+FQ+p+l/3//aMOQL\nMMEaoTbsvbDQ9AzrSEhhkP0UEdlBFqgU8btCqFgqeGqiltcI95MNEK6LPT1e\na5Zk1/zUz1LxiOvRxL1Ks+KfPUkds0jNGCpP6shhmGS7uYXkMgXENqzGQtXR\n5ZN2UKqDUDZjw5Ce/w/d8ngBynzJIxmpZemQ1tTzVFb+3CNegDrBnxKQU0Bb\nX6fgJ4zZi/C8GkEvTz6OqiRNEoBItbm+KDRR9sdkc0BNec8emnQlEWevEhum\nu7L36DW9r89vvWXIhvhH/MsVr4FSPePXzLcVRBtFd9WbCQRjtP9rIspRxdYs\n2W7De/sb4bQPnqsfk0foB/wNSU8vZhynFzQ32/frvtRHGbWl7FYbvG4YlK1a\n8zl4Vf7rqa1VT9eaipQLJTWVFBqHlvV3R1v7YddA4xmtfpnFnuX/pPRywysO\nztvOy9xLxzSYVN5pLv7wRxIfu4/XSDszxNSav5oDDZvrlT6IYrAIhHzb7gYW\nFputfAMN+oHDy9yvJUz9ptEvSZiJBWwbjLXv4r3FwTe/0OHRoB15WwJcjYI6\npT3z\r\n=vS1l\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDCiLvKsfhzPs97VNXNqJVD/7ulM+eYcE/7954XPI9DsQIgLYipWq5t6qZd2MF76u8+0dDdqxIm/w6GEsFctpTPAU0="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_3.2.1_1637793290397_0.5399295470243621"},"_hasShrinkwrap":false},"0.0.0-canary.69a107c.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.69a107c.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.69a107c.0","fusion-test-utils":"0.0.0-canary.69a107c.0","fusion-tokens":"0.0.0-canary.69a107c.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.69a107c.0","fusion-tokens":"0.0.0-canary.69a107c.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.69a107c.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.69a107c.0","_nodeVersion":"14.18.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-AkfXC71NvMk3TNAgwfjuOsjRa4aLBDD3J8I7aPNorBsWOevE1Ck0L6pwcLSEKe2MaZx/mhMcsTelP0b+LdMIUA==","shasum":"5576c8d607c1cf2529acee2dfd302d70b5f4a57a","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.69a107c.0.tgz","fileCount":25,"unpackedSize":61609,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhrqAxCRA9TVsSAnZWagAAxzEP+gI3X0H0tRVAEeYRe1Rf\nIiOofBLJk870iD/DP3ciEtvsLeLF3b9UmxgMV2vHOykY7QamYpD9hKEcXo+t\nUnVFbXbETHsUIehJKFO0J26gfnU6sqy1kGble+5706lBBebk3seYJMPQ+4Kk\nFLsRhAyUcsSOOoiuSw4CSM/n70LBdoJbD0ZuRRyZywzrer0LwZNRhHcra6wJ\nwFs6yONLzWEMltaeQbK2V9CPScsw5kZwcLPSBpIWcCaRLlgJXxsWzwRQ1d8E\nc+67VBo8XnaWoppdnIP2gJkSW5WTqaIC4ip1KpChbuVfGQUUaeSlRV79zbGH\n+y0Jy4qnVpR1SjXbUmbEqZYYAxwQOOR1mgj8ixcBj3npzJ7lcmrxaCBaIMGi\n9mzulGVO8p4J5OfDZDVNYFfK8/SsrQyS514V69/aCcQFjAHe1vsnHh0Udcob\n37vA2hul0Eth3YK6i7c+10DTzI+xh5l3NhuqZ8ai+ATh2PEgVC+MyT6DXr7S\nSn/mQtojauNvBAd2purc1PKPpHV4yTNJqTciTGEE8yHdpYDl5mQJtSWhvo7g\n+jsYuBlOm2f/q5Bz6nCHuiZCQMufAuSzLmzhD+41V8nyjkTbTNZky31FQqZx\nxnU+3mTEPStyKD+QprmNt1pLCGCEYsDkd7x/S8rn2jTl42UaQ4xgtTRKsYnp\nUhl5\r\n=TB65\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIGyYV+QHnCKxbvWnvdMCv0iZWBP6DAyoJclb5n3YGW0JAiB/7xDBXK6AF1hgx4ib+RgPHjYJQywyzdQN/JYf4z+tjQ=="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.69a107c.0_1638834225151_0.5897409465621093"},"_hasShrinkwrap":false},"0.0.0-canary.c638cb0.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.c638cb0.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.c638cb0.0","fusion-test-utils":"0.0.0-canary.c638cb0.0","fusion-tokens":"0.0.0-canary.c638cb0.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.c638cb0.0","fusion-tokens":"0.0.0-canary.c638cb0.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.c638cb0.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.c638cb0.0","_nodeVersion":"14.18.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-uTLyuCw9nMa2aIQRF2SkWQR+0hBJ0/nbsd33ULGztLrGEh0c44G+x+YDOEC+Tgfhx8UQmFGlcsQWTs3POLojGQ==","shasum":"8c8e39263faa676141ce1fdb0deb4d80e4366ca8","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.c638cb0.0.tgz","fileCount":25,"unpackedSize":61609,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhr9dGCRA9TVsSAnZWagAA/ykP/jNNxiiyeDma/DpPdOz1\n3NdXTzV6Vk44Dk6rhM4LTiOCArT0cLfk8hDmXYUaq5Rp32IZGPqRRhtCX+8J\nxBehuwWJhFuSXfbeAziyObJ5Nvt2FzJZw1fpD301WAMOCR1cFq471JtbD4kw\n7LWvGgs43hB5HIXJ8Brqmvfgf0c+Hhq4ljJOrSQrx2c+qE6JHVnoUyqrRKJR\naube/mnUOlQqZiFEBbsfiFnwJ6DPAdiTVC2hiXrm4MM5quPNa2Ss+fiTx/EC\nzZPaLcEqVMjsJabsixwh0S7Gssj/9puPuWGJ+HZbzfiwphGGEe9reoEweaLi\najk/ubJZW7/6i6QYpwf9tRYNFEuUU7sZnPr7+oW5jTYxUb8FM2llkgS1F0ux\nsMfTKL0+XabVJ6XwiLsBhSZFjM7SsvFrzaqk3rL2JZTXIdX7pxtTqQFx207W\nDO1LqRb7EU1LeK77x6GrmvJ+vIzfqdUX12G76Gz/9rdc4a8tA21v8CgSFHWA\nKIDBMbmS+0+Z8qzVPVjDwYFPspofPHr6Nld7zY4pMbjVZZeu2xlbRoUuGBhx\nKETaMkZ1Ie9tRCiPiKXyXDWm4FpC9pi6IPEZK9FSU6hN86Ubbk9HqKRL/l0G\nOrL8RhuuFSJXoPE3yjflB4yCD7kX5m87ATQQoElWD06SuqO9hp7JqmnxZChf\nZHwy\r\n=Ze20\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCX5+cNqBJfdIA/E8+36SEhuFTUVn6kR9lKMvtnjUUQuAIgHURrbBFuhwoSQ/vR94d7PWF2bpKlF43tBUdLZwft2LQ="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.c638cb0.0_1638913862057_0.6089406803560762"},"_hasShrinkwrap":false},"3.2.2":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"3.2.2","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"2.5.2","fusion-test-utils":"2.3.2","fusion-tokens":"2.2.2","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"2.5.2","fusion-tokens":"2.2.2"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-3.2.2.tgz","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@3.2.2","_nodeVersion":"14.18.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-hxexNXPOnkfRSFI35s1JGXZYosQsRV5T2dFJAMvlP1SkKS2hdgJXDXlKQE4OClWgEb7Y6dTo7EaGrG/W8HBr1A==","shasum":"20e12ed9adb5531dcf93bc4cc77b438c0a591922","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-3.2.2.tgz","fileCount":25,"unpackedSize":61507,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhsmsfCRA9TVsSAnZWagAAcLAP/18Za/H5BdYe9F38sZTr\n8HWf5zVah7dLeTUuxNF6epFql6zv4CTwYSMbPEnD2yyyWb47S5slHLm63sYv\nUXn+ZoyHPMUBu3//oUDpQZ86sm3XNX6rjQxsdQvdB9tiUqmQI7yZThd2gtr1\niYTa4rKNoB/J8XEw3f6t2OecJElWtVrOrnAgumj3G1PZRnstuxOQ+druXq1h\nO7joyUOZBX6AFJIBEVgPir8KmxFYaJIj7KI56sx6N39KG6qkb0I6HmXGy51p\n4kICv/OuepJ/ha2gNp3nLgJFMexPq+Vr5IhqetdSfG+kQDKQ8OkvDa8riZ5U\no63abiyreQyVHz/ZO4iDXeZZMbwKNbuNiV0jjMYCmGHsQzQiVsdObHRQ9wqd\nHJudRXRCVZNWwaKZiK+U0cWGGbi0VZ4JgSCywawjFDQfIQyoAYLElsI+1fB/\naq3SppADF0/6R4wlNq3dan4GpE/EgWcV6u2t9sJbrC3SnnO/4t1KBJihhB6c\nvQ6cJVQF3+rM9NIxK/SjQUVBquAnfdwKNC+LBnkGACxMd1ecNmbp1FjfmZUt\nV9tpvqnN8mVDGHvp9v3YcngNrBVSvkcQH4JYvM0a/duxSoucMsdtNYPzX8sd\n9n3406DF75DtltgHs750s/ShZiDZT2cctsBdxJ85m1ipLJt8QdsWB/saB6yL\nyEAA\r\n=XEJ/\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIDylFydBb3F9HFDHGbCQXlwYmuPAf8aEzufmDNS9vNSLAiEA50RnMwd/bRWAFau9Wu8Ob6Hpn+2arZFFySmda2kAZcc="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_3.2.2_1639082783202_0.9689477425547623"},"_hasShrinkwrap":false},"0.0.0-canary.6c63a07.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.6c63a07.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.6c63a07.0","fusion-test-utils":"0.0.0-canary.6c63a07.0","fusion-tokens":"0.0.0-canary.6c63a07.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.6c63a07.0","fusion-tokens":"0.0.0-canary.6c63a07.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.6c63a07.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.6c63a07.0","_nodeVersion":"14.18.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-C0yyY/9sgOyXiHv2QtLoPzD1CEovXrcnXa9gUZSr7UeoSWsrEYVxPxgmGE1oWd+u3jU4BC8X/fgCaiDbtcsVYQ==","shasum":"2bc6eecc278e65ae5710c7da2fea1897067d5207","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.6c63a07.0.tgz","fileCount":25,"unpackedSize":61609,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJh03AZCRA9TVsSAnZWagAAr10P/2v8Wa7pQmE6ltDvtPtD\nWzNW6fjPmMLaEHJUc6MB8E6PDY0R73GEHefThdRDLP/k/4rSOuQ6PxzayGwH\nK2sOSBycevW6m2ss6c5pQ1Def05Tra4k+OblStce+msy/kp60PvGlNta0Qxo\n+ke10Q2oO8uvuWs5Eg/G1DkWo1GkTaQu5wqvVGIwqcFgkX7Mf+XTlg8B3z07\nk2CIfx8sNy8luGyZZOPMt8VSKfMMC/krFT1bwj+oRWEoqx3E3+Sbt1LJQY9M\ngxcheTc6+ybJdf6VnJl9RuGUdFVM4ZNxB5uZvJyZcBH2KlBZcygpAKvGYDBs\n+DVOEXehO3H8RLOzIky2HnvW1Ru0mq8+MCypjnnXwG4M+XYMuZB6Vsof873B\nvI5WMyB1KDaoM9k0YmbfqnT81ZrKHOIv5O/RJRLStbzGa1vUxyFnjJW+CBL6\nO3FHnMB06X+ex55BfmhICuV6sXA21+raV8k0QIBAAWsSeUF56EfMGXNn8+sS\nn0TtgJ1W9Xy+RyVE/ELtJ876nBMyqTyZ86/y7L8TbhOmA86hQsTsg5/TK0JE\nRJFBP3cM2WopfigOilwQ8Nm2Leejzic5Ym2XkaaNS8F5UpYwBf/9a7Hx0wAT\n5mTpQD1wGu4rKSMJm1OI5kNRfOiftmTmQ9/1bc0uz5rKZMHEW9N3FJMuzVsU\n/6dI\r\n=yume\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIFlMexjh31Spj8anNZcWwWx2kPQhdgNh3gYQ6bnAOfVjAiAeN9miM+MvxAosnRY9QaBvpvKh3NnE2+o4TciVaWnQtQ=="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.6c63a07.0_1641246744557_0.19423126375608168"},"_hasShrinkwrap":false},"0.0.0-canary.2fa3949.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.2fa3949.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.2fa3949.0","fusion-test-utils":"0.0.0-canary.2fa3949.0","fusion-tokens":"0.0.0-canary.2fa3949.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.2fa3949.0","fusion-tokens":"0.0.0-canary.2fa3949.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.2fa3949.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.2fa3949.0","_nodeVersion":"14.18.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-zc+Odxe1O8pIbnd5qnNXD5IrcIgD09k6bWYa9EtcA1/cO9dJXamT948epBMVPNMnMf3EsoEn/8R1RdpkD6Q02Q==","shasum":"76e72e891fd920b5272546a2b1ff7a6a37bb765f","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.2fa3949.0.tgz","fileCount":25,"unpackedSize":61609,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJh1MVdCRA9TVsSAnZWagAAwbUP/1tEZYkIuNB91TAMguz8\nr2Jc6rnyjgYp7S0jS9KsM0Pugs2bz/PkHMtrp3X/pWt13PvyKggFaVciRM4F\n4/JrJ2Ad4nfVrNZILuSaXmy/ckI/4LEIb5fWsgf0TNBPuZWWaYOXv8NxAigl\ngtzZyGhvZgiLx02jxnldCrzLaOq2bOVi9WptL6AINOViY55S47b8asKS0XzU\nRvtZ0cusmcybu166XyvXcMk64n3pKnHklo3EtG4wzSN2frrbni8SyNsrJBIF\n/liN2g1oMT6HRuYR6b0qaKJnjX5nqmfhh4UcWWuG29hfN4Exe1S+7Gwx1yDQ\niViALZE3ubYCmsk+ecAorU7ktXHqIB47FqbSrEEwXxso6lKiJf88XIEs9S4v\ndi1HVoXHAmlftGyX5vJi40s9LfSgfUgMSZ2BTMUBX+COzSzdF07ZFkby5des\nd1BVB89JlFtGYXbNwWudUjU2H12ugahuwmG3mTqcZ1L9+K86xGl2nNcxzmAg\nthrdkpjfsXrP0gpUrILY/gtJyhE+f1srFMHDGnUVmnDhmV5FOY3cKH5xmVdr\nQ1J9vb+TS6WAQ2LJD0KwKOwuhxp0uTrLNFytRb9Yv6b+AMrxFReM/QukQZq4\n1hPjXkegT6ZmT1hEPe2zANYphi0JYRxf1ReAyBwTxVKpfraLeJ1cCfRxPtFC\ni4IZ\r\n=V+3V\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIFg7YyD0yHhwwI4hoZ1KYt6Gv8d4iRx9KJp9vG/IJ+S8AiArmA6/0NkfaqxclUr93GeWKsdK7oLzKHsEQ9YsBgsX7g=="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.2fa3949.0_1641334109640_0.21358560326007403"},"_hasShrinkwrap":false},"3.2.3":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"3.2.3","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"2.5.3","fusion-test-utils":"2.3.3","fusion-tokens":"2.2.3","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"2.5.3","fusion-tokens":"2.2.3"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-3.2.3.tgz","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@3.2.3","_nodeVersion":"14.18.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-o+V8SXZqDnf0z3xF0K2ysvGQQB4i7bJUDFqM+XKHOW0VrUtTQDg49/oM+Bih5AIpwd//kwQjfl/WG8eaA+ydlg==","shasum":"9caf4c21842852e3cb3eb215f2769e99bb5e2afa","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-3.2.3.tgz","fileCount":25,"unpackedSize":61507,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJh9ESzCRA9TVsSAnZWagAA6mkP/1MgQEpEGbwK8S96hUIR\nR9dTVBEgkWBdI96AlLi/cYRwToJLp1SW+ZK3hxkhv2n70T67FqRqdmaFl4iO\nnb8VQF9kzExgVQ01Xw5IHMIeIswi71O5cjiwb5tA01mOw2ZgARpHteTCDl/9\no+zh0Sjrk5PoLrf+VOD8Bb80TyXpMDITmKaMp6UNQ8oe9cmLui39sMD9Fyau\n9IxQnD92A6Ly+cgTpmRQtBBcKA8CiIuS7eeFeTmGnEwKOEBVfWK9VDre9+6E\nxD2st55v2i1I+V2eAolPRqcR9/sO+ES5vNdgpx0DY/TEDEMKWyGn5cIBY6XU\njY2cLE2Weu2XFZ5mN7/HAEbEfFhPMiq85oXLY+G097cqnKpyoEWd7TbEwv4i\nYd5BE7QGH0CQ8R8Kz7AIXmfyB/ITR08H1HRinsTP+589Wa2W76wG7Cp31yJX\nLixa3yFRb2MK3zQRBFaSDl49CTKB5iHMa8wzL1/I2yi2Y1sBYe3wsMsSHntD\navwvaGX91bZwiW1K+2a6bkHNJlBAZ4+l0i7ngBlD48Jf0LPU17dFzwWHaN++\nXuHuCV323StuOy2KcuKtXXAwtJdtXB7owxPHUgCNNSG1UYh+6UsjD+kiOAtW\n2JEVwhiB91b2feoyii4QhXP3ITflwVRR3CD35ZtUs6JKctXZPw0CuTHgWKiX\n1Or0\r\n=PjZk\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIEN1RnGNZyuCDmfqS4bxQVWr1tD1fXqEgzt+gWbXh75UAiBIACePT0lsTH9jxlx+jdYRqOsWmBBr1Aznqkcea38TvQ=="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_3.2.3_1643398323320_0.5716935696424714"},"_hasShrinkwrap":false},"0.0.0-canary.2961969.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.2961969.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.2961969.0","fusion-test-utils":"0.0.0-canary.2961969.0","fusion-tokens":"0.0.0-canary.2961969.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.2961969.0","fusion-tokens":"0.0.0-canary.2961969.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.2961969.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.2961969.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-ylkkXKQQqPmcfRQl3RDtJ6tkAZPGo/5xA2iYrvzIFK6E4an0lz7szH2+EGHW5E/MsrImhubwayLlyFSUo9ZPZw==","shasum":"4323a7ecb8f9562983a7e2ec5d525ce34e36cee4","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.2961969.0.tgz","fileCount":25,"unpackedSize":61609,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiOhBJACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrX7A//Q0bWFAtVEzzd7eXaPQ0r3ybMXHtmEckS0hwx2Xcmy2cxkO76\r\ngemVgE6r4byImN6Rc0Ur5UxbdGBOYb8XfYcDiMSsrrc8ZYer8TWCOk0KHdyH\r\nM4bJvTpgFnd1nFK2erTLRgG9y7ycxBljn/NCOVFDb03RIwS1DzCodZ0FlFYJ\r\npRltyXpuLZsIUyh/gtjENlVCxuEo9tzlMsms4ugB9uqkG7JbF8Xx7y4zYjWH\r\nCDLcHkhe2vff1McQOW85OKJVuQPGEDchXnKhCw0EXzHSi4V6/ldE4V8YD1RD\r\nCcM0hnVmwpQAcRfjaTt6BnvZIrSNuJdEIBM9Ed++Wk1M5lEa6QYhb0Itu4yS\r\nLOnku5a05dq9iCypsAgDovFxByowYW/cJ2EXTTgM9yC9VepZ6JzAeylINa5/\r\nRLoE28yzdmDTKR/NoaqQ3aBrsY5yE1uxVRdE3xmyNVvwEXkP1jiWEzrXfGUO\r\noID2FiRH3Vcv/jD1Wy8MtR0NVeAZ/JN6j4VKlukiO3HSZQR9hnZk/2+zknTZ\r\nLG/3PHsP496EaByjakag5imWR+QoSElAhOXtMjJyccNy2eu9fcK5W60NGSqM\r\nltwSc7KojtjgV67Z8k+vl2HN6e1Whad6pTdceLyux6tuCSh2JCkhVDczwZ+D\r\n9NrzJkDtT6pXVCZSAmVI8rk3jDni2SXfzCg=\r\n=++D+\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIHcyZO+gEaAUuVsWiKXxYe4aiG6gBntmqDiIl6kR7UjLAiEAjBW+PxIQIXoi+WUe6NlzaHeF0igJ38hQCKYYfULl2eg="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.2961969.0_1647972425434_0.5955983979355763"},"_hasShrinkwrap":false},"0.0.0-canary.5dafecb.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.5dafecb.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.5dafecb.0","fusion-test-utils":"0.0.0-canary.5dafecb.0","fusion-tokens":"0.0.0-canary.5dafecb.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.5dafecb.0","fusion-tokens":"0.0.0-canary.5dafecb.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.5dafecb.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.5dafecb.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-BePrc1dEGO1WB5vByiVZMdpmDNF1QDfJNrkIu867T5pKTyk9hCA7RkORMzH9fnGe7QKD+cO1a+zi9uH7TFrSCg==","shasum":"ce83c03b5383cdec95fe4eb260c27a12d50d2b2e","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.5dafecb.0.tgz","fileCount":25,"unpackedSize":61609,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiO6YRACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqqNQ//SrCy9hhNeQwSXDqjWAOBRhw2nSvE1mNWXQdY1DayovXssKwl\r\n6WSo6O2v8FWRn/rUKc/EI6E0mUTar3QZzmhqTFr1gbXPIBMHGalcw97GZskg\r\nCHnQgenH7285w1zv4PkJ4ovcMXTK1GdJSYK4X0QDL6Pwce9GxhJHsMjETSs4\r\nA4ce3r3VA9UtXhKA7bI9ju5GlUvXvsC+4W2WK3e1x6nvbSeZ9ZJcUt9xfGXQ\r\nTA2kCrw3vpN1m2ADUV8tz8JbhnTGRPXrGsGccXj1KOZEihMNko/wR67jkSzc\r\nTi4RfmsULS1qA7HXgIhMAg3Zjaba5PLdgqNnzPkR8rqS+jaHjxFmXHpH3p2M\r\nN1JV8yEpGio0VD2qWC7Buww+1edBmJ8AvbElsBrOQzHFmTcs7p9yF5PH5LBo\r\nmDq3tCDHnt8LV6LLzjynr5xM6BSosM/SEHyRsQo6JOpcXyg/GbEfcip0DpqB\r\nKm2Z2eioCsD8h+2thRzpGO2ntCeUlh5iMSbKNvaLm+2JJOCJ0vkZEkZhcG8p\r\ni2IaahIJill+dyeLsC9qulhtlok9q6D2fkItC0F7qugvcMBLCDr+DTBgnkxA\r\nzmZpN4+MMsyRnx3MUECv/x6STPA2J2fYU+SBqyhVGiljjk9VPPjLppLG2xxj\r\n3oopkm6Ae6hSn12AXQqOtP9zdI1MJ3DzU7k=\r\n=F0B3\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDH7TUbxnvCzOIqQx5QCu6ZTpZ+QG/mUIvzW4U5fFb4XAIhAO61LxTdOdjSkEuJrK+BCLhP1sDvXqVGsoLClkEx3Znm"}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.5dafecb.0_1648076305003_0.36332994845832656"},"_hasShrinkwrap":false},"0.0.0-canary.f10290c.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.f10290c.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.109.0","fusion-core":"0.0.0-canary.f10290c.0","fusion-test-utils":"0.0.0-canary.f10290c.0","fusion-tokens":"0.0.0-canary.f10290c.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.f10290c.0","fusion-tokens":"0.0.0-canary.f10290c.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.f10290c.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.f10290c.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-15gJHInrfTZxF6IuxoVkmen+9UUA82cAy/yy6T0S6sjeVmu4W/UfE9fHn9YS7QSM8uT0J9bTR2p9DbRjujxqdQ==","shasum":"4ef14ba8b37567de89d8d2930f9977984cf9cb0f","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.f10290c.0.tgz","fileCount":25,"unpackedSize":61609,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiO+BzACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrAkA/5AQAypO7ZPiki3H8ai7dzjbVwIESAsO9OxhBCHNZLt9ABT1Yl\r\nPLTb8PYvju+orsP8ZOIWstoCjLA5WVrCJILtX48b4Vy03C3lnbRgKGBhyh/k\r\nsRtn+zuEmdYoUjvlwPzxCiAotiLqw+SEDfJkBn3VawDuoruZNem2QmD1TFUO\r\nrPOHkRr7huwSNb7T93doNY6h7CoiV3B9tvva4LpFHuYp4zXezOFbTw9VTbpk\r\n5KfZAa+EiQTsaBka4UwA6npamVb3aVY1d4pvq+D8eT8AV792Xqd6seUOwgrW\r\noGLHeFTcRDZ/klKKcBfRyTG0sr226V8V1pZ5WGEF+gLrCaf3UOgFkx+L7lps\r\nimor7D0eupfLTgHpqgGcnFM5mdqiI20edSrVlrhhzLCPmYylqDAUurhWh786\r\n1Q7wRQ82i8dj7pHNb1YAuPo1ZnF4AZPDr0jzEs/ExFy6t4/bvL4IjYtX+Uhv\r\nSaNUApECgzQZt3Rk/Tip/RTLjk204L5/bfv+SfQB59EA8/6a63UlbSnvM1za\r\nvJJIBBLIKgHxmlwNcjGhZo7IQxIPQxNZcWJC/ikIk9qQnUAQrRXHyQQwuNZe\r\nRl6AjkuJZE2s8QlDyNePKH8gTDRGeB1hyGT6wJ6EBfL1clwxXs3I/SicVPeW\r\nkqsyCMtbXBLX/pPInE/Pc94t70nki6IFJDU=\r\n=5oqO\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIEC3dDaSbdR+tgcuAbRKP0fr5nk1p5v8lncg3MQhAJASAiBVfC1pT/x4S8KHEYlz7FRq2W+bq9KEpLGj3cOdttFGSw=="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.f10290c.0_1648091250981_0.6409984900593233"},"_hasShrinkwrap":false},"0.0.0-canary.4b95c4d.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.4b95c4d.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"0.0.0-canary.4b95c4d.0","fusion-test-utils":"0.0.0-canary.4b95c4d.0","fusion-tokens":"0.0.0-canary.4b95c4d.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.4b95c4d.0","fusion-tokens":"0.0.0-canary.4b95c4d.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.4b95c4d.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.4b95c4d.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-vpOmH/A/f0x7IPtD+SnTJvgY2mNsagcnd3uFN4nesflvnjqFB2CswrfeQKCtq6LcXfNRbnb7DbVhUvrJ+PBthA==","shasum":"10947ebc501ecf9b49863309e0faae396ae21b56","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.4b95c4d.0.tgz","fileCount":25,"unpackedSize":61879,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiQB3PACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmq+CQ//bC0FwQZ69M7N5/YK2uszwpJytIXNU9ZbE0uLlesI+uonVRxF\r\nCUQax6xxx40E7hVsOqZ+aIf6C+lUV05IhQsljTJSC7UFJ5P8+/w+yWWkKL3G\r\nwVrUeh9wE5w5ddG9NDOdbhH82MRyDGwyjzGx/CxFBBXMPCE8gz5/vsK8wWEG\r\naQOLHXRtNdT5Q8iI/oDlyLTGdWFOno4q8+fIvN7PDtidjS7Y3xusis5nuzcx\r\ncBR/+jGfZysX4VFFKxrZ4MZAIuB9twGz4+BEUtRRwaaMlAYv2FQulNRT68He\r\nZ/aVjZ3qNaFpJGUAzbSvhD6M0ZPI29SWPVK8DfreRL4rC3TDS4zuARHIXeSq\r\noHjSkgCrOUDifpReavfyIVTobLTVYpj3eGX9rjY4V7cLRuE+fAV+qCB4Z0EA\r\newslH8FHCvhPX83nxWcqpV3qQYoayCk7rusDIPo+NhDW7izocMkLC7cc89gT\r\nokikU/gowoELnABmQZoXyvYJzRZ773dfR2dm7X013RmMPGXS9pk95SZY92tY\r\nsuD2vH8kiyPORTBg830B4vjSzhpOiOZrXWFmwfN+lsX1rvMlTHV9Sib1aPFf\r\n2sbszfaTc6OH1z7367uipvLM0os8+zCDWAAvWdxXoimfSQb+AlJ31FYaOMtQ\r\n1bOvbNLiBW1mIy8nAIZQX9A8iNEuYnPwI4I=\r\n=1t+W\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIG53u3pKRYGsj+rcToKhGMOfoQE+qfQ2UlOye3sjljdmAiEAo20uGPrCpm2Xjdtm6Fwa5Optp+94X4Qlxv3D41HfEAM="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.4b95c4d.0_1648369103466_0.08000111457270176"},"_hasShrinkwrap":false},"0.0.0-canary.ba7901a.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.ba7901a.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"0.0.0-canary.ba7901a.0","fusion-test-utils":"0.0.0-canary.ba7901a.0","fusion-tokens":"0.0.0-canary.ba7901a.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.ba7901a.0","fusion-tokens":"0.0.0-canary.ba7901a.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.ba7901a.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.ba7901a.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-X0PnNY4PgzoCMRkO8OofMK7lMU5ra1y4Fvp+wz5zs7rVOj/etTv3n/lrxs+gu9JvTLlAs8jcajcPKgdOcMAS7Q==","shasum":"2ba563846d2cb7be334a61cb33145181faef0b0e","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.ba7901a.0.tgz","fileCount":25,"unpackedSize":61879,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiQT0NACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmqctg//RIWofhhjSoLRA266PPhixkK2elA88pGk2y8mtg2ZmTPsHEW4\r\n59zXjaGsQUXO9Es28dzUi234+7xz89vIyxtjurincfKBR5GAl60YXBy+91Lg\r\n/dK2fvUTZFK9fFruSNUxbnYmjYVpC8CQJ6TFFhH397jtaFwQXILZCKqtPwQC\r\nc8VfY8ugN6W1Doi/oADiiJE+m3NJVvH0BX7zIf7A9ozzJ1a5XqMHD351L5ce\r\nkd4UYGoST9ASyftRVu6XAsAtb06TCJMcUmRT7Kydw/WxiPiCtnJtXAxyNQxN\r\nBVC4x3127jkZtv0VemIXgRe0aD10ysJQ6WiSNtGBUrDUXxdEOMTKsYN5V+pX\r\nHPQ1GmSYs804B6jXRLLXlgG3xjE7GmH8ndTwfPuBc7LBmkPwInb+LaRBIHWu\r\niw04jFbmFfG5zBB52M+lq5RQZQH8ytq6uqfyebWHmLW3FUgJNEaseSknhhJs\r\nhlj76qy2nQcdRKuEpZyenb8t4zfxqeXLztCrGCyniH5PKhAAn7Bp3VM1yGmC\r\nt5tL7RdMBIWOJCwAQydU7oXhqsTg/3NlpI5BK12GBAZT3+XsxJudMY/CgAm5\r\nkk/R/2qVdmLQIkjae51q4olA6FDaShH3m5W1fv9YpkD8KJqoWawnf90Lyv58\r\ntRhJAxPaZznqGbsjeYtfgJf/IwvYse/bvuk=\r\n=dQtD\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIE+/AmUdo5TdsdtjyL4da15WVjcLJvE+aIOyMUjANU3+AiA8ZF5ezHtn+ym0MXdq5GkeVKKt9PBJjnwzHx/zMeEWZQ=="}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.ba7901a.0_1648442636903_0.4207488974027309"},"_hasShrinkwrap":false},"0.0.0-canary.53e71c9.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.53e71c9.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"0.0.0-canary.53e71c9.0","fusion-test-utils":"0.0.0-canary.53e71c9.0","fusion-tokens":"0.0.0-canary.53e71c9.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.53e71c9.0","fusion-tokens":"0.0.0-canary.53e71c9.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.53e71c9.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.53e71c9.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-bS+P5u8G7TchI2HKbChjLKDLJH65cDRiAtGQxGybLPJlCwHBtihiW8oiaFSNNdV6z7RtWjTG0Yo0ybSDG9IumQ==","shasum":"0297fcdc129833839ed73231add2f17771cc2a83","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.53e71c9.0.tgz","fileCount":25,"unpackedSize":61879,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiQUm9ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrKOg/+OzPRRMq5NmtJNDOI0PT9wTmzLvJB67Q3IrsM0f28vlHawnfE\r\n5LPrlI0r9poSlrgi4mnx6/w66fst9IX62qWS2YNl3HttEeoPryfU9HvjQMxT\r\n6vkiw+lqu+5bCoMD+K9F4F2Q9K9E5PxFNJaUeiLv+ABZC3NOsQyYcpMnGySM\r\n5Wlb5AWYIJZTrsH4E9C+rU7t6KBzNC/FCKdznPqGq9jyZmpV3tKR/k6rBHRw\r\nuxAQZIM2XDg672W698OKgdTsUBj5psHHjKwy+uwbGRwVs0/ecQSHsGIuuUxB\r\nzZwIwJ5y2O33EkJfbYhbtmEJPEV6ikmSc4VhizS8fsFVEDYZE902R4pvsC7Q\r\nsMEabJbmPaHXjVTtN+tkqjymiRwNJswMrX2x93VRnVqANcRZisL+cW8TEUQ3\r\nkdqnC0YWrvqKN4SmJbnQMnDrAggShX8zGVlRGMF2ZxBb+iaYsOqVBp/EqI+2\r\nnJUkMlCmGnVLmmpTCQP/6ONHvYMcvd4zwR9LCB5ff0nkOfWrP1YvQI2YGXLr\r\nymSsyuEjEQAtuog3ZPnnNASHXGe3X/yqyfgIhhgfoSNUEsHXzEOegHeJiBXn\r\nXIlxGk885tR2N2v0ocBxXi7mN6cVwV/0SZwb276jOTYOA+7zAAE8Z4sJl92O\r\nivtdg/eSJ3n/zfsDfcT/eE+Bgijrqrxr574=\r\n=jaR7\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQChl0Qqp9j5zXPK3PSV2S4KcIdWnfPNP20NAWqhDHH1XQIhAMGM88gODgBGph0TSpKaa6+Qsce2GIt2ZMJpLgFhwjL3"}]},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.53e71c9.0_1648445884981_0.9209123503324268"},"_hasShrinkwrap":false},"3.2.4":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"3.2.4","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"2.5.4","fusion-test-utils":"2.3.5","fusion-tokens":"2.2.4","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"2.5.4","fusion-tokens":"2.2.4"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-3.2.4.tgz","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@3.2.4","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-7tDaOo5ED0UZgL9+XNFIXZ11Qgshuz4H5HlV8NlOnSRCm95aFxUrcOr9nggG7qGufSeGJsRbsf6DnrIaUOZO7g==","shasum":"c253761a9d9e2e0e8690541c6d93f7f9031d0b86","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-3.2.4.tgz","fileCount":25,"unpackedSize":61777,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIAOG7+Ngmc3qd+v+RyTgmN1zokQD89ffN5LOuR3nO4GtAiEA7+XKbRQM52unaEX9ppFxspVkk7LfSurqtVRii7j6JOc="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiRPGzACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqExg//Uh211ra516BI2CuMvNVh6cKYu88afGbYPsiLAntDz4FJlqyY\r\nbvf3YZekghOrEqZarO7GE/t1rGcIRdttMLnXvbysE1nhuoye2vd7c748bR0O\r\nPVnAuiHaOQvtSbBgwlfpAmaER2lB4c6uRnsVJAG9qHzpw+sYGvW5HrFSKTRp\r\n76llouheg88mpi8x4aJEDAmvX7f98HH/3FgCNI7JuiM6P3cnjZ+DZwUNL78I\r\nTXyVC1Rgt0vcj43n7IkYB1PpuSqR5oLHMOrR4HkZHoehp36X09+vfkGfDm2C\r\nzjERmV12c+YBi3w/gFHVEd6BkqhJkxmvhkRUt2rLeSv+CVr5FCnf3i65I6vZ\r\nxpAURq/maxKBJ4FHCg00AcM3xZnvJflxwzPXCxZ/n8jR0y/qcLGdzYsGKZbP\r\nAJoGmVVRpH05SEnqoW3gYf5tvKdRD/pU2XwfFHmNCWBPmX/DOVPYTmk3XS+h\r\nUvneFHu+EI+06YPrr2FaKOWBUWQZOIOQP5A6ruZx+b1kdebmsFWiK8pB7UAw\r\nw/xUcuBtLHfzrU5Xi1hOZ9gzlyjBrFlYOew/rvjKaFq8JsvaK3cGtcbwCloR\r\n/wB6SijtIlmY00j7Gb7tCuZUuPS8uysLzQbxhDVB/6STKFUIb5PeBnSse2CK\r\n09oYrRjKwVJcSYvaVoFEx+1JXoDWEYj2BFE=\r\n=CoH2\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_3.2.4_1648685490984_0.6046829376883689"},"_hasShrinkwrap":false},"0.0.0-canary.04f01d4.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.04f01d4.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"0.0.0-canary.04f01d4.0","fusion-test-utils":"0.0.0-canary.04f01d4.0","fusion-tokens":"0.0.0-canary.04f01d4.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.04f01d4.0","fusion-tokens":"0.0.0-canary.04f01d4.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.04f01d4.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.04f01d4.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-+c3hQ6G6yOOJuHQ+GGRNasELY5qjtQjcDwTVWi/iMHpbaCRoGIrACNjAgoFURCkcn7IsHHTB2jIMzpzmdkDBbw==","shasum":"e8a1bba3e72068db44fb45d6191e71eaf4775fec","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.04f01d4.0.tgz","fileCount":25,"unpackedSize":61821,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDVr+ij5V8NfTDRzAOuI5JHThpfjaJbr3qaokn9mDzDuQIgXIUAtiMOZispnTnm5t6Kxm8H3b1hMe+4P74EjKT9vx0="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiRdXEACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpEsQ/7BHSHtOyQzVOHO5oC85h3I1ZAzWsw77aqkeCx8wzbteH1xcrB\r\nq1HR+7iss9lPHOTe4zHJMf0bsSiWu6piOm0gOREDM8DIREjhFvWwO5N2TI+k\r\nog74yRA4AgSb9imliWAxBjYySEqAOElGur51qtDoxJWPSdSpnQU2UkuCRas4\r\nmncjovKel+ih3/gmft8OH9z7ZLHeLnTYbmSN3OXQkt6XRYf2SNrluQ43iXk6\r\nxpIxH8sLdmmTgmdQIBtXbqtXeT8emSXM8jb5Y22rAVPq80NVhP32Bq6QxWTm\r\nw+67PytbejwrjpiXMbCQNsQipUs3K4pPEV73ii5BOKY23+kJFZDK5S1bsIlz\r\ntftfsWoJTT4oypEo1O+3ia/uyig8ybqimrj3phwFoUGs3gYLHvezVrFBZa1l\r\ntXy6IC/YBoh4UrURaGZW4WaXZ6GikWzCNze7yBgHao0Dtb9BJ5YeAM/ujy43\r\nv1Ztvuo2aGlbxvBP7DKaVviIO+ahdjezJ7+/iRxTOfWbe9Yb6m+txK3Hcy7j\r\nx/pXxWRdPn7H/SXiyzFBqz5eGUVtzLG+ouxTi1jmxYj02mUhWA0leF+NIowR\r\nvI/1BSDxCo9Zy66xL5h22bQTHPICrxsIEmAG9drZfBrnX/cuXJQrbKlgO8lH\r\nGq6Aq0tdJ2Hoyskva4X/uJq0JFu1R212gas=\r\n=gK1B\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.04f01d4.0_1648743875836_0.6477984038491142"},"_hasShrinkwrap":false},"0.0.0-canary.0115aaa.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.0115aaa.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"0.0.0-canary.0115aaa.0","fusion-test-utils":"0.0.0-canary.0115aaa.0","fusion-tokens":"0.0.0-canary.0115aaa.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.0115aaa.0","fusion-tokens":"0.0.0-canary.0115aaa.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.0115aaa.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.0115aaa.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-tlWz4eiNCIKODAKGzT09qRFnnxkKfw7wq+BXwIVx14tW5jkCGhJ2q7Ls4/nk81vOLuPErwy1Z2Z0Rthwf7tttA==","shasum":"d3c488b0901024a957479c397aa4383d6f51251a","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.0115aaa.0.tgz","fileCount":25,"unpackedSize":61821,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDn3ZcyuibwjO6wSjRoSJSDdaq3enfvSqlt0c727m5hIQIgEY95x2wp97n7+XPLEnxnMDSuD3clv8elzs6ikdWSbAE="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiRiK/ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmr5Dw/+NpU5Rva0bE/iX20HBYjcKo0xbjbLjBbLzM5/hf5fOX+7BNM8\r\nDMxMZL+podmS6LY8poX5QeLcW9ZjpHRyyx03uqxlL1y/zYUuEQ9D50Cs2RwT\r\nliuzXeWNdGQnUVrXGkFnLNRbua0vBRf+khx0nrJO6nbS0HGQYynoiAEcAztO\r\ns/aExzhkgyLK+XT84/PvZe3sSsxzflcg51WbYXWl2sdhxO3QIIppI9KaJ0aa\r\nNN9ZszTJJ90vKojDM5PRf9dmJrpa80IjqZb8hhUNMC0c44TrwJp5GaVpfDzH\r\n9mU8BlBgYbNUJ3+9jP1MqULHUr57Gj1oOrTr5DtQUE4MWsmcUDd/7iKYGQA8\r\nfHCAkSUP+z8WREXl38qVswoBYJ6F0VPh6qpVGj9SEJnsw/xu+n+MnmPTwlLN\r\nmfvTHcz0t9Oe5lm94hXy+tfvjtYf0YXxDWJCZ3WtglnKdwTyhWAtydK4uflV\r\n08my4Sc8uyUEY32wRyoqPDmva0iWFzhpTutQxThK13hEeBEQiQF+/GykKFO6\r\ntdr1WfGI3JQLxcyqMo9ye8SMAmIbefVuSt//SF90muXYSDcs+SN6zcpjVTvj\r\n3gELgj995xRQ6EnSJBOD/Aax3vM5m99e4646AoJer0JzXMMajw5/maPe7hvu\r\nyO4EhIC9YVrXCYtOzBHGqSMKWICYaRwh+gE=\r\n=D3+t\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.0115aaa.0_1648763583344_0.8086380026814675"},"_hasShrinkwrap":false},"0.0.0-canary.3fd760c.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.3fd760c.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"0.0.0-canary.3fd760c.0","fusion-test-utils":"0.0.0-canary.3fd760c.0","fusion-tokens":"0.0.0-canary.3fd760c.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.3fd760c.0","fusion-tokens":"0.0.0-canary.3fd760c.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.3fd760c.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.3fd760c.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-jX/ciAlgWZinAd12gifuL0SDiF26jk2qDepTssw0LJlKqDSP9SxcxGJGLc59mzVrpuI5On8WBWtJxssLcKS+kA==","shasum":"021ccf8456fe2af464f123f63f821673255c41b4","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.3fd760c.0.tgz","fileCount":25,"unpackedSize":61879,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIHS9Gh7IapOMpxoulc+2Qnanm3Y9f2lw5RAFgEo/+fDLAiBmlQbP9FyjN+e5Og4mi6WpzY5u+7NzcH6oZAasWAMJLA=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiRy6NACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpVQQ//Uk0g3JH3F68cWF52ExdEwmazwVeFapznaFSz7B2fvw8FrbPt\r\n/A27ntU/PO8FsbeY3zlQR/Kl/aYqczqS0g+qf4ZcUZvTDc7K7FBy2nVjUSX7\r\njGhbE8zV6vvzOfugushMF4EtN3BUiyIU49jqebdqM4/t66xAwVCqRv8X5Wg4\r\nAZQIiyVCXUczBn0U1bVO7UmCpomjrQZfPCHFBFqER+wCDcatZpvjcOGBKvjc\r\n3U00bF75IwEnSbxeKMNEdEc8i7znkefdpaHnZbuiWX7BYSMsH0qa7KoxdgHJ\r\n6LrLGs5wMw0c6z8dGEfA4F5UVmfbhs7oBYLs5HA6sJlEnjA8sMMLlyJgcLBf\r\n0V1jzIGZR8CIfByjiom6PQcEgGynMRZPPMmZB0jQP254WjOQG5T6FhMdrDYP\r\nzs3beDhhDGxKdPSCVfuvLQ48zy4bMzhnx2ObStgUrdUEsgpheUYdZlxdFItr\r\nrD3lnGbkXhZrm0nUAI5j41Fec6m1puewiwjTPmCXYOZCz1SSk5ZwmLFaKElX\r\nLti/UiWPGiGNZXgHveunmsRHLtvsHmXqOx7KdeNnxf+OzMr1YqVf5wLP1GfS\r\nOsfc+v3qq1BPdGxYDsUqlvNBZL3wSb2mghqQ7Q8Qo9edJdF4HfjTHioMJrFo\r\nQuiI5qGnSkYZy0G6z6cSHB87x+a/m9TC1b8=\r\n=zrim\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.3fd760c.0_1648832141633_0.7832011090664193"},"_hasShrinkwrap":false},"0.0.0-canary.d90d4e6.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.d90d4e6.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"0.0.0-canary.d90d4e6.0","fusion-test-utils":"0.0.0-canary.d90d4e6.0","fusion-tokens":"0.0.0-canary.d90d4e6.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.d90d4e6.0","fusion-tokens":"0.0.0-canary.d90d4e6.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.d90d4e6.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.d90d4e6.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-4f3VsEt+T6XWmVL6GJTIEwNrm8YHML9yrXP8T+Ob3PquWEtPcXjcgseOmE42Ubnb8IegkiqDxMCqAxJmLH9yYQ==","shasum":"7ab73e77d805df0cac045704c065455bd02b1ca0","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.d90d4e6.0.tgz","fileCount":25,"unpackedSize":61879,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCyATyYc3xLroerIkB5vVQd/3NMCJ62DkVqavYM8x/MXwIgR9Nm5mir1VcDiiO4mXsuXYIQI9L71+mODT3r0e0zbHY="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiR0TyACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrXCw/9EpL2146nC4DvEJbvwFJxdh9csNcO6E207Vo6TaS/Jzs+CfKP\r\nYZB7pH88v9NznR4LK6A1fPW/S9/L/gmwvNu42oArf/5QzSvgQ2Uwl0iyF7O/\r\nMJDVWS2GNtD97j7e5tCFKUMGecjoNyCVfrgNnbvGL8/5LZ20ygH48jXuK/Sd\r\npzr/A0Zq4eRC1oyLAOcTsV7tUIpllXjGx+fergVj3FoHNfZg30QHE1yjAf1Y\r\nKB4I4YMOUbUPqiRHqDqf2EttxXI+WIp9LiH7v3SXWr0pBV39kxwKdSHRN108\r\nxsOanG9uwTy51TSnWv56ITfGb4CrbgqWiZxpkng5vZxlP7zGvwSnZAfVInAR\r\nlSuB+mlZOWNU7O5+Nq3VQZgW0i7tCoXLt4Ry79FY1P8pU1lBD3Pn8Xn5D3W0\r\nhHAN1kqbrYGJSKHTXKJgm5acAHZXr9PGD5pYv2rwCIfWC6422hVNv4+jfUiP\r\nBVPA/oTeQ8qjKixW9PUN72X4+NhWve4Qthb4ejOHpuTVUZWSkiAixJokvi85\r\nGJ8YZS1hDWEiJZocfP/I95bfkh0uC+C/Z/jG+9gRU0Q7/43fnGcn7PrgqipJ\r\naAyznVhwE8Yy3Jx6Xfxy1fJUPDV7jIFVQY2OIiURIV1IhUuYKxxG4tqPmrpo\r\n4WnZ0PJVKVN9YwYy0EST0RowrFqIZiIdAnU=\r\n=sj32\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.d90d4e6.0_1648837874616_0.40810740548702573"},"_hasShrinkwrap":false},"0.0.0-canary.0c6b102.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.0c6b102.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"0.0.0-canary.0c6b102.0","fusion-test-utils":"0.0.0-canary.0c6b102.0","fusion-tokens":"0.0.0-canary.0c6b102.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.0c6b102.0","fusion-tokens":"0.0.0-canary.0c6b102.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.0c6b102.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.0c6b102.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-SSaAefPpahywIiiJnHo+bhNYxKx4q8GwvOVG/qM+yikaOWk2vqgHlV+AbbG83pXiXA9ig7UEuc2J6e5SeNuh9Q==","shasum":"d5e9b95056a134a4bf548b4e9dbbf1417dc3cb7f","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.0c6b102.0.tgz","fileCount":25,"unpackedSize":61821,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDAwnxicda0bYuDdN2SfzMrBQn0o4j+VmhezDNkhg6t5QIgdiLTNv2LAXA41FwT2Tf9gTDLst35A8pMWvhH/sqxTPo="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiS6JjACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoiLQ/9GAm5Pk48mTAwmla/8fh6mYIUI+V3gqBLds7E5KRgOHAKEzMM\r\nybe4exwjBZRIFVaRTwEz0ukjKamlxl7HFi8zY2zk9UqxM1AcZ0IM1TBAyUop\r\nBbcQa9/WxF58+ocjanPr8wx8U4AAWh6T8NckH9PgUaJIpCIiB6h+fHhz3M6t\r\nX9wA/+uI+dY/ij1j6wgOEhRncnyeb5R2DqTWsTmKUiIOm7TGSwpt7C/tjJcx\r\nO7EbXssT3hIhR9NEDqk0oKUcPAJ++iLVrTHlRF59U9by1MQAoYqva7ugTC6e\r\n1KAvU4DSHRo6BJuNDzWHmCzKFbvObrL9b7Fz6giLyIpjAN6SCSUkciTsL1RD\r\nhEbz/2Nwa4H3IXp1q45xaDLxS+RL4ZK8CRTB33bCQpK4cPjlup9giQ0wLipk\r\nE1w09TO82f7iiKyPc36/B05LFz5urlJ8H/D8ivFq8otLLmhrvdE9t2Fx7EyY\r\nApmnBcym4HXlYOAiLDLu5xMpPdD5yiYJ2pq6B3HcrYaMETuEubYg0eFglHBA\r\nDof+GTMS6WlKageH5zUU2+wBlMEdR4KviFaJnSwVoOE3Gws9ywzRmovUKSxj\r\ntDdd9RZF8zXaQTSxKv8PWfIy9VHaAGnDGrVPF18lOwre2LNkq3hdEQuKlwzg\r\nviRfMXgacbCaM/BUW1h5snsLliqKQ+n67YA=\r\n=mAHP\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.0c6b102.0_1649123939641_0.5029299048501312"},"_hasShrinkwrap":false},"0.0.0-canary.a48714f.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.a48714f.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"0.0.0-canary.a48714f.0","fusion-test-utils":"0.0.0-canary.a48714f.0","fusion-tokens":"0.0.0-canary.a48714f.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.a48714f.0","fusion-tokens":"0.0.0-canary.a48714f.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.a48714f.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.a48714f.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-W9SAewmCCLGsP0oPBayPO/rtExgoW4fhmZz6QxmOvrvBF75Hre/v2O4iPXPPUpI2tB2JYVcoO7RA4J3Gd4hR9A==","shasum":"0196617aee6d79274f3bb96b3e50fe37256bd9cd","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.a48714f.0.tgz","fileCount":25,"unpackedSize":61879,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCPEJwHbtS+4PX7V45ho2s2/ZrY33G57NwRWAxlybleEwIhANaM+egma45Cjh7BrvCnHmIQH3LqNN2GBFhQ8nLIXFxj"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiTKLaACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpT8w/8C8wtOOeuQIjMnQAhUH28aDrqq6ICnXKWD7qpI7fq2fPsv8Sv\r\n1tgaGMeYwxkLAeIosTuzqO5reEFHSx0Ckpgif8PCXS+upZOioRoJXrRZzpbU\r\nWPoZzfO4jcygCnHcOtrMiSvt6vRR/aJtrXvBJSb10WzYg+UfiShebLPrdP6B\r\ncZwDsErgAAJHMEa51dl9EN23x/I92I2Ad6iBbYM43VhLa2hCr1reeU6EqJw5\r\ngXp5zlnxne6j61iAljg1hMFm1LMWi0OkmDIbD5M8oNs4yjo0fRDLVJKrShSH\r\n1GoFdPtxMmMmyhNz0HCabsSgzT5CHxQG/g9NX+DnmYEVZ4rItkV0OTQ1/YJo\r\nIjFIj8Pvfy6dC5/4w2EnJlZwzOsCV5QcZsilGm8G2oU4rnZfFIFEKLGNoBAp\r\nfzvHNk82/7B30qj5v48dqKU1OKsztqPBzQY7z5dWSnXfXt1PsQ3YI/H3f65O\r\na+QUs8LZGx5PgAVSC+Ll6jEbwkzcZd5m+AWRea7tmwNz2Y+TkvD7+MyJDHQS\r\nwTQQudQRJmCPgwRaHcXxDTfbenB+0oLo/YBsrFC3Z3fRIKg9s/C3oeLOlMDI\r\n+U410zjJjm696CnNELftBSCAmg75wHw/p4NrZmV/DkQ07dqyI8uJYabNLBXP\r\nayt/ItORmN82G8I1ZoyzlBMYIbiqgZn8nHA=\r\n=Tni/\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.a48714f.0_1649189594255_0.1332507409314041"},"_hasShrinkwrap":false},"0.0.0-canary.48261a2.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.48261a2.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"0.0.0-canary.48261a2.0","fusion-test-utils":"0.0.0-canary.48261a2.0","fusion-tokens":"0.0.0-canary.48261a2.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.48261a2.0","fusion-tokens":"0.0.0-canary.48261a2.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.48261a2.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.48261a2.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-FrxIz3pNg78nC2OgsaFwMG1+Xu7sNoDDbNf3KW2O1vBmO8VMwROEsIU5nlCkrhIcRyv/+Bvpy0ckuszgNUCtyA==","shasum":"1ca618f0b0430ff00aa66de82497ed390dd7fe85","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.48261a2.0.tgz","fileCount":25,"unpackedSize":61879,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIC2chbYqaasEs00bs25mC0rvvPv8smfUFVrHc29w58XsAiAHgeqypICBGp38d+gyLvZExBMr7GxGhPmkTwKt7rE9Pg=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiTLnJACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqRsg//WSvZDuyfIflai69nO/fZhznU+dfU8sy3hgQbrCxu9ZRgLS0r\r\n8wG7VkfwNjJgebJtT+NzKlHwdf3O+fMgQVKzhtU3JgFUh4MWH4H5G6biJt0n\r\njzP0gHuUR0UpYLk/27Cy1qFmP3xTtam0L520bwNu5uWhajDFq7Kzj4Oi+Tad\r\nj9dHsalWwDMx/xynUIVJHH9p7DFriOAioBe8brxOYohe9kpisoSV8yWuRw0C\r\nxewcJL3hMQiIJRhRYnwE0T47lHE196oTxLiWu4fLprW8GLY6A9F5Zw949zPG\r\nVv2kmSZvKc/zrZhwxJcQJTlccuzXSwSgJefFWrNGHipVpaqaYXF6+BFkHsS9\r\nWI4GG2TTeNH8gdORETr/t3wRy3Jk0BJnuwIGW++GX8nOCjppFL/Pnp460WUB\r\nO+3M70PT55USmIWZYTvKe3H4F4Df7CNmyvrmB5KgAHfTXArhebr0lRmJUiJJ\r\nfXPZ51OsADTR+GHq32JJjcB6A/cmL1rO2FS+PmveMSPiZJbob339YdMKaBh0\r\nUw39qwJM+AReHtvdnv6RnF89d810Dm1/rsiTDcTCs+QCBMb4veSFq+1tm0EG\r\nawQ91/g9W9BOS0lMewPTTvEBYzKDGxNgSgTJyWK6Y4DqjTmA92zyYIuPr/CG\r\nsbAsLT0bIPh6zyiQNaXiT9m3GqmTCer3Uas=\r\n=vCpU\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.48261a2.0_1649195464865_0.3214559118049629"},"_hasShrinkwrap":false},"0.0.0-canary.e4a0af5.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.e4a0af5.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"0.0.0-canary.e4a0af5.0","fusion-test-utils":"0.0.0-canary.e4a0af5.0","fusion-tokens":"0.0.0-canary.e4a0af5.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.e4a0af5.0","fusion-tokens":"0.0.0-canary.e4a0af5.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.e4a0af5.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.e4a0af5.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-PotL4mQXujT7fNfebKdzdu1WRvK5VYNGKIlVWJfIUpm/jFQP8SktiBxMJ3l95FLDvajPxFkcoqvjDWTDPQWonA==","shasum":"5db0c48fe4ab55bb0adb932ffc69ea441b3115a1","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.e4a0af5.0.tgz","fileCount":25,"unpackedSize":61879,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIGSGUg3r0of07lBGOZCIBj53QurMKUYwVwFAh4BCrGmBAiBOk4A7zAAu0HdKy4DCPqHqCjo62zEU384MTM/a3OS6HQ=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiTMc/ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmp5OhAAmiXzcHmys42NWl0UQTXtlOCVEwGOcb89LPlaWGC53FE31NWK\r\nCkvNF80tXHhD8woxALXW2V42VMwngH4224kreaUoOdkDaMzYdnl8qrizolXw\r\nViMgQ8OZ4ouRYVFE1dWcnhRxv0yLDL1CPEqteJorD3O5HUf9OSnur0wMPu1/\r\nLDuO3d/WAgAOzDHz8lb/YG9dPH8TLlR6ifyvoyRP8LLT6U7NZN//lAG5/7l/\r\nPce1ysjjO0dadd7+2zxYRb3lVIMRfftzOPm6hjQ5Dyl/Qix3jOwYCR1yTzww\r\n3SWFHs/YMXLonSlxJxcdeDgoV8gVSVaErBHtCJkvjEXnOZbRaolRg7iSGsrQ\r\n1gldPloBrmOrZP+5nwj4Frkd82wRFGNCGpRFrKcUNDtAR1KSWdJL62RtMxDb\r\nnCvZjd+oMLAgqPKEB1kMxTPYc8BKbOfNVXZDs5s7x8eWsU/COI6zr1av+FFm\r\nlyJsqdDmz2euB6lHPynaHQDo+Mpk+ddEEaIdz81RI/4T6Jx8sks2267fVYfn\r\nTBIWlo+26pVkRDycbsv+Th/gmP0g6UEq2WiATGf9XLyrgzI7FsB7mhahf0x0\r\n0KLOYWK50RT/mJ9D/aeGjsAUFNCnMZ8GgvxAbrmKuTuIytEDX7yqFZbnkTYH\r\nPYHTjSHK6DxOJe41GbtnlOM7POezDfCsXUA=\r\n=qUeG\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.e4a0af5.0_1649198911037_0.8499510147383851"},"_hasShrinkwrap":false},"0.0.0-canary.a5387d7.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.a5387d7.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"0.0.0-canary.a5387d7.0","fusion-test-utils":"0.0.0-canary.a5387d7.0","fusion-tokens":"0.0.0-canary.a5387d7.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.a5387d7.0","fusion-tokens":"0.0.0-canary.a5387d7.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.a5387d7.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.a5387d7.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-nAB/PiyDS8PsYCtZ/Smlfe3YvpZ+ZFCXojDoAhKbVriR6LKlGphYkz6s9lMwyUBLe74TKpYdzp2bRZNOW/9NsQ==","shasum":"a579624c4f9ed452a6a8cf6b70362f25ebe54f5d","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.a5387d7.0.tgz","fileCount":25,"unpackedSize":61879,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCICbl+pCJHVhV/Btw1nezjKxjCn40OjzRhf7HUKuCxBV+AiBJppNEXoCN1vsY3pqOEbjOov92/Ox8V6wuEvJlyE9dAQ=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiTbwsACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmq8mA//WFI4p39gEoOEtCIKBjybmQ49UuRFA9StgT+JIrpflj7zgsHl\r\n2o2nKFbyXPv5EdwlHSq2DW0DVCMHlb5+nAc2sJ0vskjBuCa8EDM7xqxRYgFK\r\nc5dmT8ZBfZDoAYpIhUUCcnuOIF984nYq5g1A/q9CR7Ob6S22SROlXYeKTNed\r\nsLgAy9f2/9PD97aTdBNrlA3NVUDlk9K1/9ImqbnGiJwrW4fDctTGvn3Xb54n\r\nGffhizuhd2j4PDCq3DZGgDUhs107RlN+03NI2yvsUi94Pxhshn9XaPDFCaRF\r\nLQmWoxf6rkgaAyWEj5khfnSTDzPyluJJYgWBjxjDb6FG9ad5fgMBuL3m7ylR\r\nTfeFjCEBwsjExcNjlA7wSqDojHxF61dPcS7ur6hmK+wDCoowKPnk/Kg9/A8a\r\n23T2NvFS2x2PIVa+wXLsgYZXr1rNILqp4RROh6Vh9f/5e+Kye4xRnJGOrTYh\r\nds7QvyQ5JrGxmg9ygMX7HbpDe9go5VolZfc9Qsm26kHxzjhCBI+l7SBNkN9j\r\nUQZos362yf+Ff/MJ0u+F13rXwvr4Bj/yrXWqY5xWRQdpFeprmuWhvTGQp9Ti\r\nRsKcF4bzyQkkLBnlPAkIGLV+mVtJjZbyWpkWDEo+bq3+BUetka/yxXrFRrRR\r\n/7louYWGi60YX7ZWIF+BssrbZ4uxvyTUrPg=\r\n=yOxH\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.a5387d7.0_1649261611858_0.41702690303785483"},"_hasShrinkwrap":false},"0.0.0-canary.4f43ddb.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.4f43ddb.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"0.0.0-canary.4f43ddb.0","fusion-test-utils":"0.0.0-canary.4f43ddb.0","fusion-tokens":"0.0.0-canary.4f43ddb.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.4f43ddb.0","fusion-tokens":"0.0.0-canary.4f43ddb.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.4f43ddb.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.4f43ddb.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-D24nzPpP/G62UPMLPzYjp2PfVP85+TRc0ibpst42Wd8TFMtKkgGDUh/1nj6w9oiY7Rq7DHW/TtP5vtCbTCYBpg==","shasum":"1406fa0ca2d35b2797068725477174bd255a0bfa","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.4f43ddb.0.tgz","fileCount":25,"unpackedSize":61879,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQC9Hw1qAiyciOg/i5mz/UYBLwNqXXJ83c2rXLR6MJjQKwIgQi6wSvBHQqS05fmlP5ZKTzE5g9yjF+O38ziRJYBoixE="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiU6nZACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmq2xw//SvF8mE+Ano4uG5FeGKoPU1dtDLlyJfSyxrV7Eb8HT9JeayKI\r\n6e/vBvGyz50jyFTCDAEoiWHDjXQ2ZGTOtKBbIQ/JzTYNZuuGytCXdJkqlQha\r\n5mugPmVpEVigsbVdZt/+Jgor7FpzA9pulnV9Hjj0YObj8WrF6RqyQUAhboN6\r\n8QGjcIfQbT0uhl7AYM25/2hx8o+yApVhmo89o1bzTghSGmmMZ6hCZtLb+Swe\r\nP17p80fTB7G3sMPmkMuXKd/OaWAQmPn1miQz7Wer10cSwQJm8INK0XCXH63T\r\nMZDwHF9aD2VVmLZJ0zDQdbCbCX4UNK8DeE79iTLARCIi5KHv8xTUx6pulWXH\r\nb08jXogjQ5gvQeDFundP7GqrDX0Bpj5j92a98ALLgm2HVd+3AHWGq6qPi4Eu\r\nFw78SefGT2SdenNuIVO59/4TdqE1nu7R4hrmXs85WLuhUpciRLemArlP7jZW\r\nJLuI5EWomHnug2/+1cBWkLjgQ6lx6YOMJfV1gKC3f3B/kP7z1QXQCcjom2GP\r\nFOPiTos56SVeqmTGjBXtCULsPyfHE2DxmaCC99diUgIzfVCp5Wcal74B0Ss2\r\n7TYK4AunEppwFQksDxjx9693tVJ9mUckXEDO07mVIx1XqAHOAaFnKH2VCpVh\r\nZbaXaHuFzIXl5jYz+CgTBcd8P+g7NGSKI/Q=\r\n=uaBM\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.4f43ddb.0_1649650137143_0.2790130498627783"},"_hasShrinkwrap":false},"0.0.0-canary.f865478.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.f865478.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"0.0.0-canary.f865478.0","fusion-test-utils":"0.0.0-canary.f865478.0","fusion-tokens":"0.0.0-canary.f865478.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.f865478.0","fusion-tokens":"0.0.0-canary.f865478.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.f865478.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.f865478.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-8Tmf1oZWUwR0f+spfhrdYpXEu10aO3ilIZBW8xwuxp8J29rKCmJ+ayuSZrN7hOiostOpi27a3P/Fy+JScCZNdg==","shasum":"49e808c9eff4ccf30d71737149db146777a34849","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.f865478.0.tgz","fileCount":25,"unpackedSize":61879,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCVQCDCypWEP+hBZjdlhaodYkd97jMK0jfL6TOi3Fk1owIhAIExfX4iuZsPCbELL1hA+9fkVL7GrampHdjJyect2o/D"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiVRX6ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmo1xA//Rz5zOTVe86Ig6V978rQ99+h38X8jInOc5X2+mqUMyalnnEJ3\r\nlMEsU+2IcXAc6B53hYgAwGZs4Yt4AqO/ZYfJEsK2GQCxe9AXhREih1SBjC+S\r\nrhkBEFwNCgCHU5CvflWSMRVIJKuqlUOKn6lQIsNQqgKodVbTWU6zUUNyuc7G\r\nw4ufg/RSWDek/RsrVw5UJxIBCyDjyrw84MMDm9Hj5gRMxheE6gdCSbnIKjqn\r\n5+1qH9eYUctFpiX2VEzUyxOgdKKTUJFt2kpNsJhMKnVHpscFeJQnQV2R2y4f\r\nAzz3wEYTnLqfy1iLEClEMbTu8Bc8j1WTxAdtIkF0ZJq4XPDxSIPa29c4XTEy\r\naOiEBJr9FIXuhHCq0dzLPu/saYnU/V3gMBIhPrk63cK+5VSHcAPZDveMRd+6\r\nFZH3SeMDJA1wr3IOnUgjlfmIeQuI/6fh6tyaQ7YpKolbu7olEbJbOYwiPtlN\r\nLNRsdWI+fBFJI4cYINVj9nk6OO++fy0/HgtFdPeZhqx6yMVxmLTMfQRc++7N\r\nBhLd93iKhcMkYHsvFsOIC9dBTfzoEPEg8vh1nPkqyFIQnSjZevIcfuTMyOnh\r\nW9EJvCdxbNhrsnyQSlt10i9y0yJALrVoiS+odiVwj+KnUx5is3YuIGPncO46\r\nNXDGDeJA2t/P0pyzn7hjxiQKG2whagwxd/o=\r\n=wY5z\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.f865478.0_1649743354522_0.7716108831377879"},"_hasShrinkwrap":false},"0.0.0-canary.901e6a9.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.901e6a9.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"0.0.0-canary.901e6a9.0","fusion-test-utils":"0.0.0-canary.901e6a9.0","fusion-tokens":"0.0.0-canary.901e6a9.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.901e6a9.0","fusion-tokens":"0.0.0-canary.901e6a9.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.901e6a9.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.901e6a9.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-MAVTus2wI1OjRO8eS4+gXtqdTYkhg19dxHoF1PptXGl2HWR58Qfm1WsyiIu9gAStHYdcSSjehfcZ+R/XtdwqrA==","shasum":"0f5d93cc5ab1c3e5fb5669a159183edb16721af7","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.901e6a9.0.tgz","fileCount":25,"unpackedSize":61879,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDsb2ukNcm9uFZp83ZmR/MG3TCB2nfzIl+I7P5QSA4WJQIhALK3g4/xzjh6ISTZyd3SwUW8R6zvmhCLO5Ud2mnAODOj"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiVRxqACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrHfA//eSqkOM9c/TdnEzDdIkLvU92ObiURvBBefU3HSAI0x1kd5kis\r\n62LLW4EOWa1vAc58oedCdr3owBNqKEJeHSzHT+M5afdBIfa5Ab/aQHiJ7nP0\r\n29oj3NWg8Ds1nN59kXn+/iKornmvBB4FTiAA+DUqFEBp3LsPmYFxdYUF4fqW\r\n3KGJa/lgxHpB1jr26L+AAYK4eDTH+97uWUVDuh0DtJ9LpquCxxzzDi+N/eYp\r\n7d4KW8jSYdhzq/xz81S37XC3P1CXmwXAI2US+dqmiOtp9aLo+/lFsicO2kEd\r\n6JVnk18XoWsOBtCb63nQ0NIZeR9q5kaI1A1R43tip4OClEGZyjnAWldB6qCV\r\nF4tGfgbJGw9bB6uw20azn6J1py9nYYimKO2HiGb1h9zQvuagIAKmiF3VJegp\r\nuDO0tglUtwAXxMWRjc7VmE6nWAf3mWbLU1KpjxGpg/iVsbZ0+GIprEADN8LR\r\nBlbK+Bn7fGxRv9xRFZo+Q8HY4ysn5sfDeDqT9S4pA3p3mr98KUZ1GPwoJTgX\r\nAv8df3jrkPDd9ED5D+8tlEVzdHJhArShrFN3ZFhjVfjNaWb2ncUVk4BH/Y9N\r\nvsY+lley2qCTlfAvkVvegmUDaLZ7mX0yIblV3AQOeP7jKFGqBrA+TraTn2jQ\r\n0EFWKEZdO2RYxqTDwrtd11YjHbIMWzVHV84=\r\n=1Hgb\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.901e6a9.0_1649745002750_0.1614410742141399"},"_hasShrinkwrap":false},"0.0.0-canary.5f75a67.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.5f75a67.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"0.0.0-canary.5f75a67.0","fusion-test-utils":"0.0.0-canary.5f75a67.0","fusion-tokens":"0.0.0-canary.5f75a67.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.5f75a67.0","fusion-tokens":"0.0.0-canary.5f75a67.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.5f75a67.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.5f75a67.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-zEI/pPUJMIJ35yPOxC7mETyvHo84jRtb2OYuRtLyYfsid6ykqTrmMJPT/WQQgOd6fCwJJgMK6mwvfYVC62Orsw==","shasum":"461791b42e41acf86b082ef0f0eb4e0ed37dc65b","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.5f75a67.0.tgz","fileCount":25,"unpackedSize":61879,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDQgJtwJi0oYfs/OzdE1tpcHFtaBDDrPgdnAS0b9qBYhQIhAMLp8LEFLVI0sPkp1u4V7nXBncylRXb779YHHIOsHGF9"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiVSBtACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmosvQ//UanvyfH8snK/FmMJMLbYS235A4Rya2XWOTVOLGPfyclyI/pu\r\nmRD8jFhO5EAxOgnNPzgCGjSTU2WoTs+4cX2RwIJAIqVo4C2zKuDvDdHf/MWW\r\nFiM514v+ACIb2HNshuA7JDmvBPsweiDPNlU9YRX6nNxTItKozrVJqHZJE5WI\r\nyaaluocO/KwCyaA2ZE17yG5HO5bjY69Yz9q6cBE0ky5T/HPFpfeqiex8/gyr\r\nnVn0RgtHCLRNkCTtKK/QWP9CXOgBjyjJ8b8A0JQg677nBOiUYAaZoXZLgYl8\r\nVjPGvS70cBAwtHcj5uyZF6xopKN4qdYzSDMUJP9T0tZqBod7RXxvx4HSfTBd\r\nbQ+Fyi37p53e8Dy5lyqLlTx6Gze/9V9YvzDYmuzk1RpI5/Wcgq2Okjaw5GqB\r\nA3x3CHFBa0XwwXltLaJopGsXw1e+bkTxbo5WZlapts0bdKBgSrn35qEUn75G\r\nHXY+ZZnmwueFuWciWyFzT5gMfYjANxkaKeliB1Ud5sxFsxEGwDfXTvFWQskN\r\nfbCTSFNcYodttxOcnuhAuXhvhsBk5sqXB1LAhhJWLmJeV8TVmgDYH08u7CyV\r\nAht9upkHk+67u+Hrh/6NikhVEAxtlu1x2dx8Ma+swlloC+Ev40FZirB1qy0d\r\nOUm3bTT8EGu+fyUqohlCBd1Ek8N+mgrjSLA=\r\n=gpza\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.5f75a67.0_1649746029685_0.6147715355677696"},"_hasShrinkwrap":false},"0.0.0-canary.66acb26.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.66acb26.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"0.0.0-canary.66acb26.0","fusion-test-utils":"0.0.0-canary.66acb26.0","fusion-tokens":"0.0.0-canary.66acb26.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.66acb26.0","fusion-tokens":"0.0.0-canary.66acb26.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.66acb26.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.66acb26.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-gYJd0KKBnpUJ9Pxd2Wj4Lu33Q3Z6ML2kIXEl/s+g+YOZ0xs018+lyLeVx3RjwqQXUx7MxQnG8jBBX5RPpdF1+g==","shasum":"a554464468d03a3541a5bad5bde20be0dabcab96","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.66acb26.0.tgz","fileCount":25,"unpackedSize":61879,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIG9dS2W2gwf04A6Ex48XFHr8TIQZW19PeHXrDk379NSgAiAU5f2g3XuFbKpzyhAK6vjtYqyvBp1ukuF+yc0VuGtP0Q=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiXP5cACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmocPBAAlWyHEX2ybaXQevUTjNJ1Ce1mL/0TYL2qADMOtwywLfKTsCZO\r\nJrrjHeYllSi9sw7boMdimaF+A/bJa/KnlrGWd62N8VXGMFh0kgW0byJA2clX\r\nSOXlWlbnKfGy4xoH77jG7bn1YUCjqGUCQn5hr7wmHqs4NMX9w7HXOSc1VRkT\r\nSE2icQ/Zo7XjdZlkwQ+l6JmeWR7gYF4yy6QZGKxjoMHY3xt+TZ7fXEezZb0k\r\nonhWsvuYLIbRDD9/KVp2uBFC4ijGJ5nRcGvx5TQxRlhIjSVG0sCPj6sGbBpB\r\n+wiWBpc0bwTLz7Ih9e9vm/SD6jQOhH9IUU/XFXYr6EhODZWOjyAvFDzVJWxt\r\nlxREvlkk9ZCO8Tvc7eya0vFg0KgAp9kOGe/K7nIJpisVfWc80DHN1XtX2t3h\r\n2Vm6woTKnKkS6USYtTN+egV9CiIALdyyXrBIX6RA8DO7zC+RU0qVtmbfDfDy\r\n29L0to/clbflYRAbfj1ubKfS9J+ELQK85TCzWfWIElPQG/rGnu4+9icLcK+P\r\ndpxUQpID9UTOhz5ZeE7sLsTbRM7QrcoEPO3mfV3iM0qr148SGKfC19JGPxoQ\r\nFKynAH5zndwIgTUCgYsTbYin/9u4tDPBS8TPAkpYzKOLW/lGHblZroFqvvpS\r\nf0ftfU41nT38FHyCKQg8gTwuhwToUrZn+MU=\r\n=SZ51\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.66acb26.0_1650261595913_0.022309596546274957"},"_hasShrinkwrap":false},"0.0.0-canary.0abc031.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.0abc031.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"0.0.0-canary.0abc031.0","fusion-test-utils":"0.0.0-canary.0abc031.0","fusion-tokens":"0.0.0-canary.0abc031.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.0abc031.0","fusion-tokens":"0.0.0-canary.0abc031.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.0abc031.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.0abc031.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-9rSpTy9wVWp3ZUvf43dWTukNbrS2YVBP54YX+EZFKTTxWxTQj9tDFawzyOixPIviG6iglLKx7iEhqcyanvsj7g==","shasum":"14406ec799dd58f5e5737604e0af5f7b31159cb6","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.0abc031.0.tgz","fileCount":25,"unpackedSize":61879,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIGulEVzoH8JkgtmaYAuTk+NSzhQ7OY77lbw9BMpKpOCIAiBZR+tWpAyNZHbtDAC1fSFZ2kBR0XOowOYmD4zmy3N7yw=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiXe0DACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrUNA/+JuDm2c3NPlab9c0zdXfUwJN0zEntF6ejn/xZW4mb6nJNZWV4\r\nfTP7AuJQik8S8j8VpcsES+1yfk5ZXv3j/omXc8p4BEAnkZqWm80JPCJPFUpn\r\ndSZn76XAqq6Uq6MEDyN9pmKbH8Enyge3vz3PzgVawcn0UbmzAJ2b3lEPZb4I\r\nEgk6HO6fsL69Ld+kZkI/k9uAtjWVbQkYIzZPLUNhzkh5lonbM0B3mlgEAnL0\r\n46t7caoo4Qghsqe21Ggt2P9oCdbxA6DMnLeh51WL7szObHNBvfpa86u3pJlp\r\nwXKynMmKXiZ1DsNnqF/gf4GbuPUMn4DmnY2fXcesQ13eMdPU/ApZGL6bXISe\r\nQEY116L8EbuLBdnRvMOQ01ZG6aqBiK6zvj/Po6S5JQATIWN4d6OsuyfObQ/4\r\nGNEISQf1GGwv22tjpFUr+3YlMoiQcrlshVvJ3p4UEQmBFJ3nrUuZUCIQx57m\r\nWVRRMwUxQKiyvmos7ro+JP/lVH3pEupEjr8UUqsgquyAcD5XX4cbAOwcquuw\r\n5QCDVCrgsPnAGV4wPQKX3F221WvcsaiEBlmn3t2brxVCTFjCOzg3S/STOuzL\r\nb4GeNZQsYfFnRKLmCDJczkhLui2Mzr83afIpsgrDQyGqIA31nosr9tMIK7Vi\r\ntcLhahLgm9IzOSBY/L0vE8K7CaAiSXCnkZI=\r\n=3Tdy\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.0abc031.0_1650322691448_0.061485011418371815"},"_hasShrinkwrap":false},"0.0.0-canary.4fa95ac.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.4fa95ac.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"0.0.0-canary.4fa95ac.0","fusion-test-utils":"0.0.0-canary.4fa95ac.0","fusion-tokens":"0.0.0-canary.4fa95ac.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.4fa95ac.0","fusion-tokens":"0.0.0-canary.4fa95ac.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.4fa95ac.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.4fa95ac.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-kEIlnbDNzRaFR2glSdflwHTeuA/fIIQ+9C6AZRZay+KaRSAqJTuv2vwj4a0d8hz2mFZBUO2L+8MhfPdHzsV5vg==","shasum":"3787f7ec56849c118d1d8ee3e546ccca1a2f5c0c","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.4fa95ac.0.tgz","fileCount":25,"unpackedSize":61879,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDD8WocQCgSCQekoZenUC3lRcyljVWmQ8vdhltDbKWYEQIhAOKptx86vGXo+YDUeTjzN7wAmMKGq9rhQnsvbslt7Fv5"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiXzD2ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqGtg/8C1yuSaIA9Xg9Ier1aWZT/rRQYIwup485wS/WjOEeZgcAY8JZ\r\n+ium8Rpukm0jIjXzRbxe7K4dTCrh9eAkR3BqssLYqANR+zCXb/dxi9+RletQ\r\nVJJ723ChTcLofEhjILUmriMzfGedOqSn2K3hmdX5UF6heshJtM9y6osdNH6G\r\nY0i5B0uIGhHPkOc6Y8ryV1qR+K1gh9YiEJJYsn8UeWKXtAEiMWsmP0F9Ddd4\r\nCWX6tbMG6uI0xOQ6McefLSJjcWZFwMX81FYZLK5uYDB4J5Wof0WB1K/ba6t+\r\n3zfR0xECh/kYK3FXF1PuqVLUPV/Fkcq+zBo+ZSaTY+/ZPxOy8oE0DAl1Q6XT\r\n/zp20MnbuIB0zFusVr53tqHztTvpXDcVCumGAkxuKoO6JQXdN7r7taZ46q9a\r\nGm5GGvTcoSLgvEFf5hVzsduNX1GZDmfvpTckLn6Z6I6u/t0uAU3BSg04H4mc\r\n1oVm16U0tCtHpwwrpGQpuWcFrBmkEqdTE/ZkFvLnIvFqbw3bI8VtMeNeIS+P\r\nLqit0hOIJfIxALKF5CiUl+WL+KQueZwDleKuO5hZfjZp7WOhiTfjPOK7DCid\r\nAotg99J6oQtPGUxKT4X08E+RIsdp5FbOJSrMa5U7Y3FpsQDORTM01MOAKNHE\r\n8uVXAIvUvMiJmNLBLJRlATusXJyLQqCIeCw=\r\n=Dcsq\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.4fa95ac.0_1650405622754_0.38396537561915656"},"_hasShrinkwrap":false},"0.0.0-canary.483ee52.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.483ee52.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"0.0.0-canary.483ee52.0","fusion-test-utils":"0.0.0-canary.483ee52.0","fusion-tokens":"0.0.0-canary.483ee52.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.483ee52.0","fusion-tokens":"0.0.0-canary.483ee52.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.483ee52.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.483ee52.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-IWGTvvAWMobtWNwEd0b1Fq0WDd8c7F6ykSCKGxm0qjgb1XFTcIIIw6ChHfvluaWE7of23KYiLeuTWcGqF97BYw==","shasum":"a2a56dc34ad90b5868a89ae7de680ffcf0d39e3c","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.483ee52.0.tgz","fileCount":25,"unpackedSize":61879,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIBLaBwU8/mcIYipZKerI4q9EnRJxtq0tQADpV1j/lsbHAiEA0UQd7QeiuyLX9lGSqZ+pKfS3n4ghNPRopho2TH8bpdM="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiYGoxACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmrwfw/+OMVkJ/jDHHIkihXNGycOCMz0+F1UnjsagDzjMf/vqjl2F1lQ\r\nMHbMvmgCLkH/DwznrmyCOHsrvTTNGNIzXqeTjUNXsntylEt0jkZA8gzUvPFm\r\nbYwGgBt1mp9vLwNjfUaVre+YXE/OFfOthgux5e0g1hdQ6rUv8L5mx8reZu7V\r\nOo5etNig4M1kFjzBPFd9vy0lQDhfV0GhJEh2jBAm2YKzWh4yofBEXhJ/2zzW\r\nv00YZlOt78ct25obPn35Nzk4weVVGD2gE/AGD77LV0OzxYoBrwtpgn/XH0hx\r\nc8LiegpnNKGm/7Z9p7h82TKl+RyrbJfRqbM9mk7xNEAC8fL2jPbdFQY5HiSM\r\nyFyJdbKPzkCUZuJNBp66LoAdF56MOfY7zDLuKtbqf08EdDdCh866TJ/+vRag\r\nLUcdInlRWSn3Q2bdxI92V8YTVPs10qZCksnYJTn0n+/7z+NUqCjG+Y0NZRsI\r\n1evBloBGvh75Spg7qwYt6PgYmuISbxwOcgZhQAQwQeiEymvLLWcSmJMz0KWk\r\nWT5RUr4WT27yzD7JRIvNM2MgPfDkY5eG8Z1AUpeWVa84ZdImBeEc2OwM+mSh\r\nL6szK2+cxXGhz/39XIwxAsBb92CROdMAIxUyYwnzj60sml6MuOT/lH04zsem\r\nj46UamIvQNHkEYZOwvWhYx5BIK4ZBeho81k=\r\n=4GQ9\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.483ee52.0_1650485808895_0.13006664613672636"},"_hasShrinkwrap":false},"0.0.0-canary.c2e995a.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.c2e995a.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"0.0.0-canary.c2e995a.0","fusion-test-utils":"0.0.0-canary.c2e995a.0","fusion-tokens":"0.0.0-canary.c2e995a.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.c2e995a.0","fusion-tokens":"0.0.0-canary.c2e995a.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.c2e995a.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.c2e995a.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-0cZY8q4fCO4zNFTtjdK0jyvQL49Glp0vBXL/+gYjRy+9Z25JWqGcDaTHiLxaKpgyh7NFWSbKEFwkRmgGBPz/QA==","shasum":"8ff4bbedc3f1ee4ebab883946b39ebeba063e713","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.c2e995a.0.tgz","fileCount":25,"unpackedSize":61879,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIALnK85e/yID3JlWnY014WAzaRfP5qwUbbhCuJd7U6Q+AiEA2WLV7bDbO+nPpSQjGfeAUsZD/leyBf+WdXy2QhuY5N0="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiYKQ9ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmp2Mw//RJjVLHaLuwr3sv18dCAXaLlj5EVcqMCdVgXupUHETcnXb+l4\r\nvAP+QC90zbj1qyH7gYNUQV8bpYXslGA5uUKlQzFiYpeIwZUtR0mJw+FeEyhO\r\nz81sFNbN6s2VBDqpMOGPHaP86lT9KHUk8/R6IZ9ncwf7Vtn87tUxKmhmC6fe\r\nW5JolkicvpVkpIYUB8KVwItiSX6SDhJRLNqzugLVXcIhADDR6L71g/23rPN/\r\nN/ZiTnPlKXpVTH6HjTHIgKZLZ1rAnGcCCr/jpoAC1Rx7kReFPSlFf9ldp6lP\r\nueJKGqDJPyK7hM9ZrtJxiqUjOxD1vN0JdMuKjOC/mRl26RI8kVPliy7u7E2T\r\nmABYTljko06VhdCQ5EPs6TSjJCC5JNRRAsqdVzqDyl91oTLBOInBkJ5FtBpQ\r\n9CNznugBt4H9qtMd1LyEoHGy8kTGOmuf9+Ci1be1fxqafEEzsmKcsSx304dp\r\nxiOse4/iRyNDIz52ZCHpvCZSyhv481HPWibFscI3AF5++DSSEntaNWNwS545\r\n+sk+sJAUPlcLtMI1wH0+KQVU1Fh7etGqLoIccZcWbr72nQO72SwSHWDWjFED\r\nJ2FOJ8CzGgddnCB5kY7fxoGTdTwXRcYGm0zKDXVrXp5i21fNzSg0DFATZA38\r\nUxDD4iSgodBRhweChksSodF8PP2wKlohj5Y=\r\n=Aj1h\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.c2e995a.0_1650500668823_0.31382257402141134"},"_hasShrinkwrap":false},"0.0.0-canary.03b7f8c.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.03b7f8c.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"0.0.0-canary.03b7f8c.0","fusion-test-utils":"0.0.0-canary.03b7f8c.0","fusion-tokens":"0.0.0-canary.03b7f8c.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.03b7f8c.0","fusion-tokens":"0.0.0-canary.03b7f8c.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.03b7f8c.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.03b7f8c.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-0sHnxOuI7fQYxr+QZS0akxugxLVVBysawQtXkRqHzEjjkxvDEk2Yy0/GUNVUPXmT2CwdOj3raURMWNyhdud2LA==","shasum":"6e39ab474771b40c367a7b10face50a86bd69dfa","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.03b7f8c.0.tgz","fileCount":25,"unpackedSize":61879,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDMcdVfe/zo/tFnhQuHQ2H8H/0xBI9g3p1jUcjvLqqwPwIgKpPaZUqdta2JKtLVt3M/zQECN5KQZDT51wMokWEPpOg="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiYZtxACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrkGQ/+NwbU6VZVFlFbfRssY4JSZblJxiCKOXycHXH5XI2s0ScNCVwn\r\n5S7zcLtsx2mkcdRfIxZHBAqrEQ1GHAwahJSxBXcWMIdtcAEhJ2ghSlIdmIaz\r\nH/VgT93tn20YAHtQHoYm5pEFpMfGlafPgH6hLi4PCSrVav9GaN/G5mYX+zse\r\nQJPst0UimKfiO4WWkHb+DT863NraNqikFH8p5mszt5VcFyLnP+qtqqaTFWgN\r\nxf/E+tOWY2qbqHKpPgx85Bpi9sjEkGm43imTAzdz9oJxymTRN6aVl95WcPUR\r\nbAjuXNE9870TTvIT9Ww8scRmZvqubD12xbOVQr/leLRPq25pT5i0V7aiGxTR\r\ndHFkmxukXjdNev0CZOVNwxAZY0yT2ECFI2PnaleKAuh4rxnioPkOI/HrKMyO\r\nAy3KtnKNtu2oQyDAIUuChnWpfc0xDzSwgcwLEv7xMS5QHHB41uJ1qoO4yXPu\r\nwxYcNAynHYoseJhOIZfIR0qAm7QCQiVyYfDJe4vHbLY4rEyPHHuA7RvuY/TB\r\nMoFK2esjdXIw5r4yJwcLjgLI2qx+OF/HUwUsgWtXCjLc4KN5xNoC4c3mnJOp\r\n0oP/410dVqZFtmLNrJrmHQ0FTRUqkqeLRp4topbnRXCjFmrkU5PpDzQhH/QJ\r\nYy/Jz0UtEp+gg9pfhcIZJAz7INuBKM4BLc0=\r\n=xnb3\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.03b7f8c.0_1650563953658_0.2881699555371864"},"_hasShrinkwrap":false},"3.2.5":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"3.2.5","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"2.6.0","fusion-test-utils":"2.3.6","fusion-tokens":"2.2.5","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"2.6.0","fusion-tokens":"2.2.5"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-3.2.5.tgz","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@3.2.5","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-Vx4Gh2BU4PyOLLcctI2uJ9H/fRkgBLTiupo0XnZ2DYN/wFQYKr8WYgtLH2YVtLOlx55yQ/dsQLUf8qOJxLZgTw==","shasum":"37d5d6ee67ee24571f075df5442a254e6e31630b","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-3.2.5.tgz","fileCount":25,"unpackedSize":61777,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIALz6kIhkhLQ4k9SLInN3tGR+gkgydjWQVGmQWFCWSdkAiAYD2aETG1kovF0ekuwrhVzB1xvVtPNmSUdjfSMbBW1mA=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiZxpSACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoJbw/+OVoaRi05h/Flg/PstBwx6/VKl1ThkdC/YGu/5mAdsAt3qOe5\r\nKv2vBngN8TO/0PglTivDz5FRgRlIrtfZjLC11aCgLFbmFX2U/1bQ/XMQAox8\r\ncF8VeDv5+oCiCj6mJjnIkbw0yJkyIw9sAdNUXfkSQ4vlj5zFVLh/x2//c1fq\r\nUsk2ATHLGy7GUFZL0wtgseKWmRXkvo11wZ/qmQptrpEmq2bTlONb7Glrt1OT\r\nPcdWFquNrLifb+0KtIMgvePQRhr9iHPpaeRME509u0uqtbwNpcZxAFv3e2wY\r\nT5dK+3WTRW6fGdZ/dVflRiviIjDGdcJf8lqvlhQB25WIXVAy62rkZiUCpJPD\r\nwr2oBhz56ucDqX3Gg1X3MzCJsLlhK6F09Ufrc1xv8E+Kb40giOsDtn0Yg3mk\r\nsJWKbv5Zl659lI3kXSXNGdfzmfzLGOXuv9PPMhevldh85dNkmfDmewYmOlNa\r\na0qJgdF3h4aR1Dq7NCwWakiApXV16P64AS73uB6PD8flXf4rpS+c98UnKHVa\r\n9qBGaKJIkKZV3vA6+Asa3Fcq+Ot9mWSCZLNJVvjFVBhhQbh8MiAIywfIGfhk\r\n2kwn5p1ngGLcraliE8yXCDnz/j0i4Na6CK23hgs2jrEBb0imIuVVBrIXJjf9\r\nbZzjidGn35Qy2dSrf7sOhBv4/ggS3swF3bg=\r\n=+wDj\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_3.2.5_1650924114233_0.6272884507437098"},"_hasShrinkwrap":false},"0.0.0-canary.d9125fa.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.d9125fa.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"0.0.0-canary.d9125fa.0","fusion-test-utils":"0.0.0-canary.d9125fa.0","fusion-tokens":"0.0.0-canary.d9125fa.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.d9125fa.0","fusion-tokens":"0.0.0-canary.d9125fa.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.d9125fa.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.d9125fa.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-KKsnTzJ3UxWx+pAbfuFqioy5XGQgLdL6a3YZSrkQmyB5Tn2Ua7C7gEO7IL6O6hLBy3/idLu9EIXUBHLCZmD5qw==","shasum":"18916581b25abc5a73fc2d2bf9752f559804106d","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.d9125fa.0.tgz","fileCount":25,"unpackedSize":61879,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDo5mwmuZFN85VLKbq4PrEFOKlbTQgXfVrFO31GgTZvLwIhALpHsrKPL4SSabYCDAj4/acHB/+u/dEgpyITL1jl4CAV"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiZzx8ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrQSQ//QG45SFlC3zC1IMso/J0aK+jl6UfrfiLMskeg3DJ8SpfJSkH4\r\nC+zWvNbiJ+OJP0Yn4LZdGRGRR188vHSKnAM+Io21ZI7rhsf1c3ll27R8UVEV\r\nfB3LFZxs6IxqDwHUEcCDdxxu2Eja2zHBMrHPEUL79IDRgZa1Ac109T+3fWJ9\r\nzATXpeETNACC91gQ0Ad/Wa7NT8YvbcxLN8vJ3Q+Ay4un1N1hkkH3qaDvEucF\r\nXKLHKAZhivybpR9CQzCUmuhVCksjiAfuPNTO1VtJNbmzrTJCI9nLk5zJq1N3\r\nzEKQePwPIMTr3fpuVONpXC1I2o6nyfZqfEmB9EBROEk79bq0C3lhPNpFe2XN\r\nDLQyWHnmDKw+7PWo0rMPuEt+2B7AtdwCYpNmiROlbExhzFgJVcrAnHXoXQlA\r\nlvHzw8rm1yNdGv0fdPd/6+DL9qSDCJhXORKxz4wlhuLuzEw+78tvVYsj9/CT\r\nkxpytOopd44WnoBQUspW9kqXKHNxWlU89QfP1UTcDo8DpvX5m9B11C0wLYwi\r\nrOc0OiHbZoRGhdx+SIyMPu29oqPaEgtsjDVlMqwcTv9B/Ht+BKe08bnKgz5r\r\nnlCLCfh7Xe4iyitC62GqQpTEBQXaYVv6f2/UZ/658O1+1SnfRSc70ES77sMK\r\nt0HVLGa4UkF/lW6MrXdWTN6eVvpjT2zRSmc=\r\n=nATg\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.d9125fa.0_1650932860477_0.6026756828878621"},"_hasShrinkwrap":false},"0.0.0-canary.9081ecc.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.9081ecc.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"0.0.0-canary.9081ecc.0","fusion-test-utils":"0.0.0-canary.9081ecc.0","fusion-tokens":"0.0.0-canary.9081ecc.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.9081ecc.0","fusion-tokens":"0.0.0-canary.9081ecc.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.9081ecc.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.9081ecc.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-FfnZZGL/+iNGfnwdZlv9nLX6QDy7x9BUi98jZMzm8xF39dpnjlUWEs93sj43GnIQtxRlf2TLQD4KLRaL/xNfVA==","shasum":"087942d0c36b885c191d08792f435aed0b907b0e","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.9081ecc.0.tgz","fileCount":25,"unpackedSize":61879,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIHQKgF397ho8hgbfsJC8qAUHCy1vKylyJHlW63eF4Ky9AiEA8JfvR7i27picXz6B3bPUxAqP0Twra+OrbRTYvl99evc="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJibgMTACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmp8jQ/+I5tFWUwMqUKpf23NCtc/2uxBUWtuety19q6zQNB305gMgcSB\r\nGH1OT1rKEIm6gi8vVjybFTGacFkxbEInhL/mw/pOB7YMjIg+siYuxPJfOJG7\r\n2mdJ/lnCC+SgTHEWdYlVZglBZ4PakqAwrD4j6GkImLVSFAhkohKZURZtB95F\r\nSUDcy24afDkMluyh879mtQvprkbhmFPzOX+DEgDQWnuHNdFN8p+CrnUm8B4I\r\nQwdebp+AxGKf3Vuu7aUS3YkiMBI6h+13F2flqcdQk3SJlXB2CmL/q+Q+7JE2\r\nqQk6eizN/TyZdhHOp/g/3GYyz3O/wjrCvaVYK4ZhfWLf1ng8FVUR5qTHgNmz\r\ntAYKImwl/AcnO0S611saDIhOTx9slPyYl9JZWkhSqoqKEttQyMt0BLYsbVwV\r\n1ygBhc0RGfob188q6Az+FtxSa12dNB7NCb5vN0IlrILpbXL//ZUxOU3x2bdz\r\nlc63S8jCfAmhKjj7t7mDBk9P1aw8zVgq29oboiEqHm13SuKJvIcJKvOBPtGD\r\ndMH5T4OVjZFyuZE9MeQPnQifQflo9yW3/Wl6cQyvelPo+tLetN2cYCdH7uat\r\nQzNw1OyTzlecKYnOD7y+0u3sY3WxD+/p/+bg9GOSr9EC8rOs9U3aPrIV/omN\r\nMJbCX9wjETWYHDRzKMWna+c9ygLxvMw1eAs=\r\n=GXp8\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.9081ecc.0_1651376915473_0.1163161668286603"},"_hasShrinkwrap":false},"0.0.0-canary.82afe51.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.82afe51.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"0.0.0-canary.82afe51.0","fusion-test-utils":"0.0.0-canary.82afe51.0","fusion-tokens":"0.0.0-canary.82afe51.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.82afe51.0","fusion-tokens":"0.0.0-canary.82afe51.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.82afe51.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.82afe51.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-PNP9c9ZmM7Mn5RXYoTeXltyFinPCZ8ohJUOqQCkipACmsTJDEA48n4tfDM6q5OAdadq14h7NjXNJgR/nStXT0g==","shasum":"e417cd9e3a664c62e683c87a418b27386502d554","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.82afe51.0.tgz","fileCount":25,"unpackedSize":61879,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCVHqjYkHAkNJfYLDhhjF5pr+lf6gscE616q5foAJOVgwIhAKmsh8HT+KoXP7Wc527cigbcFCHob8nuzgjNwsAXM4Gm"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJicdLwACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpVZQ/9HMP34Jwly73cq6YaxTFNsQHbvfeZhcF0NjMC8OzgX7hwJxqS\r\nYsQnpAsQAbyJU9jbnqzmm2yKUe3pSJLQ5NttgZs/0JqZzDmxH/NWJ4Z4e7aw\r\nIibrRuCiRYPYSACy/QRCXnHK0Pf26VyHEbTOW2MPSesuVL6jmKp0YSSCRHoR\r\nsFE9+05YPpdWP/U/AZk0vCw5ENszyvcVZ/+bK/57fIOUf+6z+YYDjwOumLwu\r\nnYOxQ2pfp5EsXLbiv6n/wx1yJ5FawGdhpRKyf7OwSD8k6Cx2HYiKpC4940hQ\r\n8P8MUzFw1bJvGl6n1L3lnWnwNYD9feIsEhpmdrDsGZqlny5NtoS+isTwv5U6\r\n0J6+MItA5Xq1jus3JDWFHN5AWWDEBMU92z0y7F0o0px9NnqDHKobasFd+ZpX\r\n4dId0je/7uLOKcy1vXWaEA/gM8IONT0Zdmwxb2ZMK1ZS4Hj4y1G2xLPC/gUT\r\n/2DxxaFL5R0ZJl9+Nmyh94/m1d7x0a4+CRNoWika7alCMPMNQT3aWvzQYeKP\r\nNfVXMDuhzt+gqJKi1EMAt2g8abyBOkI3qt1OBHMrvEekZN15cQZcEM3b4igL\r\nODNgNdEabfK5J5RqaTHYIcft765FI/xhZ+QzHHk5hsekACiOvJw0fFX//mBs\r\nFkCrb0BsZd4c1gR0I73uipftTgQRxfXOlkE=\r\n=v6Go\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.82afe51.0_1651626736294_0.7304704812733445"},"_hasShrinkwrap":false},"0.0.0-canary.3afacb1.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.3afacb1.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"0.0.0-canary.3afacb1.0","fusion-test-utils":"0.0.0-canary.3afacb1.0","fusion-tokens":"0.0.0-canary.3afacb1.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.3afacb1.0","fusion-tokens":"0.0.0-canary.3afacb1.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.3afacb1.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.3afacb1.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-vY8WwND1YvmvjAPiQ4rtWBCE2J0fo09zFIe/fab0LGgaCk4IwLIGip1ZXoVoXbyJMtZX+cmZ9qRhiCeH7eLywg==","shasum":"e35a7eab4f6e4ea31acecc3b79dd7e4befa7286b","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.3afacb1.0.tgz","fileCount":25,"unpackedSize":61879,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCbk8qOeOt8wtn9vQ7PEVtrHGrIxi6pqZwIt+Ws+wE0pgIgWOPxg26oKaFIowRAFXAIeI0Xpt+K9l3b4h2CwCi2inE="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJici2qACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpCxg/+I8GKZpglEBhss8wsAvCBB8BzXiycG2vkM40GgcwzbJ0uAOgS\r\n+ZczVwITgNoV+XgEwf84ar2WSZz2KNqhsgLF6nrL0mP9JNB5M+pQqVDL1CEq\r\n+bpVhq58uIs866NCRTTpA3bmNNrMYYbR/LTzbF+MGU1INnRd/Ejcus6yRHoM\r\nf2XY7yjKb+l8MPyudEUYoX+JB0bsMnUtNiUmPpYkdrYmLiTvtWrkuTuzA47A\r\nki+PT1KlKuQY7gNcdOEOqIV119LYd2EKywSMay1Qou7hmErSNK4k2vixcW62\r\nrF1SUJPBv9rlVBzAqJ61TmdihqUPAGU70jr2U9sMZZ+Q/xDkR3QaiMMBDaSj\r\nghHBr7+TjHa8KZHRITyRp+OndnQdxbXdWtFHfHrttkxT8W9M9qBy+hY7ZHYD\r\nrfJPlOZPj6QtXjWZcJ32o93ukWSz+wvHkBX6PEDGqKXpJxsgZSlvuSyfLHJi\r\nq5vK60c0e44MzTvLxWyHWRRxZNth4BTR35614WgeEkBobMykCzTGeemGORZw\r\npHjOXBhnhY+sU5svl+ejBDjq6O57xTww2pznlzbnByZ950j1hal7ZvKO9LwV\r\nz8LVU2Qbc/smVqyltifUc3xMpMeT1n20EKpfhJy8grTpNiRxC1u65YKWvAc6\r\n8U484B0qRtt5OXAbbhtrlXsgoeHwyb2vSF4=\r\n=GTL1\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.3afacb1.0_1651649962352_0.0339788782473458"},"_hasShrinkwrap":false},"0.0.0-canary.dc38594.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.dc38594.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"0.0.0-canary.dc38594.0","fusion-test-utils":"0.0.0-canary.dc38594.0","fusion-tokens":"0.0.0-canary.dc38594.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.dc38594.0","fusion-tokens":"0.0.0-canary.dc38594.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.dc38594.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.dc38594.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-WAa9ayjAM8GvAdOqp025fva7i+n7Y+QTWIfEHScBRVRBVnQop77EUvgkk7pcJr9mIus8SrvlZ/ZDZ1OlgVbDdA==","shasum":"aa507ccddcb83ee0ecf98ed4ec88487d20b51d22","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.dc38594.0.tgz","fileCount":25,"unpackedSize":61879,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIC/VD4CG7fV0ZcTU+dV/w9DpGPKtOkk/a9chU96hOWhOAiEAmtfC5Z20Fz8bQ0fTai8t165UAkxjgqPYqpN+XsxASG4="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJidHsKACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpV/w/6AyqlZq/ChzLLZ0Pap5t7bWs0xJ9iP9jdWBeAEqbGezNR+31k\r\nczK/2sS/AAUGlSi9GNR+5NB8Q7bU55u5lzE9ScLfuvY7Gx3slzuTPA4xASgZ\r\n7mmGG9OkMyV/qivcf7Cq1RiqSV3UupB7uMtqnzN1NnfE3k04A147veZIcwOe\r\ntkI22UHL5MIEmEnIcW2xh2WricEOIq78hMiYp0omiCOvv+p5lkL3nANSTArg\r\nY/IzQ4wvgOrtqZ3d7uXCfrKk75RC3FkcEY9iz0frz5tm6lZbefTf393zb4D0\r\n1j15yljseKXkZPma1tkQZjFxjavbHcKS8RKzHIqu6nXSouBqnYd9nh7utX+i\r\n/vkA1MwuXpaUoblLf+Jtsid/2cLFDlkWJv7lNj/Xytlrxs56plbhckZWj9vB\r\niUdhw+jRKtMJq6CZD+vRmoc9+R4IOtM+OvMpkw1LoawQhkDYRZrM5mXF1+NJ\r\nCcHAhieu/aF4kZPfVraGLfobQUqiOSAJyEo52ezp4b2+kicw17KJSkESQ8ey\r\nIFeIpBX60FAmCWzVc03wc0k78O22DTYPo2WSignyNiHjutXkJ6VUf5Qrf8ms\r\n2yzjjrY607omwyG/vRU8p7eCpgjdJeohK0qZf64ELehBXOtzvIUkxU2EtmSd\r\n/zSDUvzASUnj1AWshrXj8EiNzKuz3ezU9iE=\r\n=dNW6\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.dc38594.0_1651800842276_0.07333550000885047"},"_hasShrinkwrap":false},"0.0.0-canary.9bf73bd.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.9bf73bd.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"0.0.0-canary.9bf73bd.0","fusion-test-utils":"0.0.0-canary.9bf73bd.0","fusion-tokens":"0.0.0-canary.9bf73bd.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.9bf73bd.0","fusion-tokens":"0.0.0-canary.9bf73bd.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.9bf73bd.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.9bf73bd.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-L3sVWiavFosak1YrWjIsRo7hj/igYhypecYy+pEpqyWjw461XAtTzGh4H6ShPz4vxNxDEu0Cn64N3SL0QSbbVQ==","shasum":"aaabdee2f23efda5f628b35325b11010fd25c174","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.9bf73bd.0.tgz","fileCount":25,"unpackedSize":61879,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIB+QLwXiJywJt/7DYK8BzHicwPw4klq1ujb1ESyZk2J+AiBwOvR2H/R8TwxasyiLtujEbbeXjwh0zUa9ziLDtMr2Jg=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJieFv9ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoVFA//eSZWswZt+++CXkikzg9/vxF+pA9Kq85B+CST9UFlzfW5O7Ou\r\n6pn30U2CVPGajPLyQvAWifUmVQG0LDZVN8q6Ng6URlyvTJeI/TguiO/1O7fD\r\nc1QIipDFSXtoS+Zu1CfJERS5eUJdMtIA8YtqTnEd70CNgbpkkdw9KVtQ0HSK\r\nUNUE/upmkghZvTDDL6RhlKftRzktTt5V/hGYpgquvJIUembZb6KUOYtEDnKT\r\nVDEjtdr3MfP5/VlqrgAQSbrdB6fd1DPHXtN4zY43zNktftiVzjJjem0TZsX6\r\n+g5pfCdsk0BdBDAWUEAe+vE3TcJI+ySC2YPQiYL3+UQD5K6yFuHsIsTqOT6U\r\nRwpdPiMMWi7bkDZa22GAYJkif5DYK5ZijmtGvw1mTJIzjEk6xOxD1kTELGtn\r\nGcTTPu9NraQJ1LzOnTBZ8DtXAo354GQwQRffJl5st4sAWzunHyBB2lnViOcP\r\nPNeIj7iSEhiXvpRh1tIZrXfDZ/RNhdUrzmAqbhZsMZyexgDimz98LDOVM6eV\r\nOn+bigCiBtSSp46DrUAJZ71tKkxiX82Z0DcWJXnMzb9m5buwL7khnT7nmH1O\r\nexQC5UGLOj+scaJvy33oaI5Be2ild8xfxu8fkegD3WMYse18JOE0NEJiRC/E\r\neTZq0XhVcVRURcMwbj/kNlpm5eCCpsAzoAM=\r\n=Ny/l\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.9bf73bd.0_1652055037332_0.5503970939102334"},"_hasShrinkwrap":false},"0.0.0-canary.0d8f1cb.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.0d8f1cb.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"0.0.0-canary.0d8f1cb.0","fusion-test-utils":"0.0.0-canary.0d8f1cb.0","fusion-tokens":"0.0.0-canary.0d8f1cb.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.0d8f1cb.0","fusion-tokens":"0.0.0-canary.0d8f1cb.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.0d8f1cb.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.0d8f1cb.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-ropXBwa3Um5/rfHr/MmX1MlMO8WMeoXJuz0B8tAzRJIKByrw6RA/W+24I8dbUudlQX3Q77p/h29FzyVwyZUHdg==","shasum":"70f88287f693cc2029a5f00b883cdcce183cdfee","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.0d8f1cb.0.tgz","fileCount":25,"unpackedSize":61879,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCT7YDi97c80Jqe1nfYIJxTo5qG4vdvfDYmG6kS7ljUSwIgTSg710SAI6NJ1+cmvECwmQDqStlkBYQZjaAJOQ5hOPw="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiecP+ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqYCA//ajQGH72Tt5gpW6CchD/EjrUyEXYEqPHKfybob2xn66fECChP\r\nYqJJhBMp6mUMjax+SwhccTgP+ZobjmbRq7ExENYmpHB2QwZf8AJz0O1QV9sN\r\nJG/5FI7lRD4uokDx+ibfoN0/OrKU57+rCWrTUvqGrZ7DogXEFjdc97ZrWxKU\r\nEddTGT2jhAg1MF4mqoCHFkV7A5fqbiNnUMS+bAMCM2Y4QW5X/zFVQtpae8Il\r\nMOAv+OWb3hf3I+jWNcbAKpJxZFzeZJ/iMap+84wb9N7i4Naq2+HnTthbuoSb\r\nCXH1ScmBtA6qpqrw8RLbz352TS8PWgBy9K0t8B2GcB33HO86PmaIYtx0niAu\r\nucOhQwwNEmzARsQeEpA2sm0ie3nP+e6UXMI3SF40apAmnk3K4f1iOP43J6uR\r\naDLCWypnONoqhn2XlBFsehU/2pzrila6bTw4E/irDn+R2fHjxAJSBYkfCSpb\r\nrynWcNOMxcI6bFC/Vv0QA5lpE3N20AmQ6uSf7DOX2pDnro0Qu5yGv39djhUk\r\nM0aEd/TmwmdMIhyW1Gvv7PzeDgW7TWLs2PraLnC5RQujM6iI4VgYghovuSJt\r\nIWvjYRVZxeHZyboczOC4Hi839i/+dBt8qjhqPgxs5i7hLbaDLEffGvIHGr0n\r\n2utdOWxkKBlj+Ikgapp/uQ9jEo+Pq1m5H60=\r\n=Ysat\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.0d8f1cb.0_1652147198056_0.6930095634913398"},"_hasShrinkwrap":false},"3.3.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"3.3.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"2.6.1","fusion-test-utils":"2.3.7","fusion-tokens":"2.2.6","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"2.6.1","fusion-tokens":"2.2.6"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-3.3.0.tgz","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@3.3.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-CnqfkXPP+ePSGgkf5fMqEf4It+Jl4G6XxtkeNrglVMdP8zTnyR7PLxdsxx/XihE1Jo+ll5N2dnlD3l/8xlWSag==","shasum":"0abd371a478ce96278d5b9fc15d9fb8f89279ccd","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-3.3.0.tgz","fileCount":25,"unpackedSize":65179,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDVOI4X0FRF+21WVsg0e2GsDKBz51PnxFoINChCMdjxlgIhAJ6gAdOyuxPjg/7JoOf0CQLgjtWLaV7CMXBRINfoL59e"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJigs8oACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqJQxAAos+Uy7AdIU5/AyumTlVmtSFGFgI6SbmVGL57Pe0MqjezhKq9\r\nrHcQHbrI45KjvK4RKN1AvNipYuK/UP5nYoYt71jMu6OIqGPdBhTkW4q9grRN\r\nVPi8g1In4d32HhPssunqacy+M4CwzK5MD9oA6coDfPdYwxvasHuDUbOs5Rfv\r\nki1lzRj2SIBkTcxHGbx5hWjbRay9ssa4iYRv2gjufcnqbHH9m3jY7JGdIp9q\r\noWpTEf1/jXsSqATpCNZ25S+kb2gw/z5kRAAJjI+hBQAFtBgoUcIcFVp8z/rZ\r\n4q4961K/4qjVWbNxmXiWNgvWwi3hd0raV0IhJ7YjOaHV1VyVFz9YIvS0Cgvu\r\nF7+XZi9dHTLWpa+Nn/pZ+FWOmdxBCvCo2+YQpG7hzmzlWwSjAQshWwsijaRj\r\nBG/5SRIXf2loACeCjIEPMvpZ534uHcLCrLwpF5QPINuRzv8987M8EHp1McY5\r\nMpOlS6rMKJ1Bv4QHwzpE/Mb2riDVq6uLa18BmdJE+/VDiph2JELggZsguDYP\r\nQfKV+sryKzEuQpVXZBoGR7C6X5fXQi0SiF2P24PTtl9uWBaDP8u0Ql/GUcJ9\r\nNVujuGvFpXZtuNGQ75pr6EyLAa2H6axKZU0fv0616LILQhUAk2AXJFPX2sgA\r\npyeejEJk4uM87NPn3KRr8eE/1k3mSLj26WI=\r\n=Wdxl\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_3.3.0_1652739880536_0.9819551013800791"},"_hasShrinkwrap":false},"0.0.0-canary.441c97e.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.441c97e.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"0.0.0-canary.441c97e.0","fusion-test-utils":"0.0.0-canary.441c97e.0","fusion-tokens":"0.0.0-canary.441c97e.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.441c97e.0","fusion-tokens":"0.0.0-canary.441c97e.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.441c97e.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.441c97e.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-pDJNJtAu5iAxF88HPPyoqjxEi6fe5rrVRWW2J4BD770s2lGeufaCxhcMIEXw3jNwjnbZDW8l7WacuzMgfOUnTQ==","shasum":"6c335f243f5111115ab1849cbccd550151ec54b4","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.441c97e.0.tgz","fileCount":25,"unpackedSize":65281,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDJd1jZbihLRpl6LUhWNvyI7jrVTFenNAnXOo+jDEO/XQIgGLPk4/wr8jNbGcrfNRobGfsX3IpZhUwzOaIkm3nWhC8="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJigvUbACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoOpg//e75FhBk3rBFViHvuOc2BA4jqVm4XkwCr8fMt9aiiV2FwmMe+\r\njG+MEL0q8F40qCyqUfenMaJzUs1APqbB8GwqlXK+36WEDL1CDewXYX2Qh8mH\r\nmujFk6s9d4WLNfHlFzv4XKx3Vdj3Q0bPTtnpIfR1bbS9RZsdvIFRVsR1hf8W\r\nLL7AlcSgSaJ1wDYc21yCWW84cAzL22/y8DdGKU/oYiPkbFMU6WkUZmAs/6H+\r\n58a79Z/MF5z19Wtjc/dwp2rvNKopM1Z4ClDVMeJJWpzflOFVfYUZRlgsuHiQ\r\njDAmhR1DR9PLPgyNd7Vvz6UnPOEmScYZrm6QHCS5UjU5i7AXZ9NtEPWjFVFf\r\n2ZxMNC3OS9iJEsKPk4wq9V4R5s+VCvLTqnL7n7n/QxsXvQrqA/q6SgdIGghV\r\nWH4gZHNUmH+5IzKUH4dmUD0bgL8N0pv0S850DWkCt8hfiVcVu58mGOt1lNmZ\r\nSrFcQ66XDV8slsy7qoizVv+ihE7adXo5F2/5equ4fBVcwUs6/t0M5GiwNba/\r\nO3VK0n24ICNTTcNuB4ZBSs6zoRgtlkDVB5yAmJGykX24b84KGq8zeBWMLYUx\r\ngejj99v1CK6IXWZYOy+SpF7B6TdUUmhjW5wN+nr280RKwieifioOxdfbAwcw\r\nqq6CnS8Q3HsET3B2EFCYWcH3zccwlim9fSU=\r\n=5Z6Z\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.441c97e.0_1652749595747_0.38595798423919647"},"_hasShrinkwrap":false},"0.0.0-canary.94de910.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.94de910.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"0.0.0-canary.94de910.0","fusion-test-utils":"0.0.0-canary.94de910.0","fusion-tokens":"0.0.0-canary.94de910.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.94de910.0","fusion-tokens":"0.0.0-canary.94de910.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.94de910.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.94de910.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-cZt1/WRwamlil08qJ9KtnsGczC6+YVfZlTADzLN9DJOLN0laWnuMrDn7tI8OHk9n+YU7LW0K76X+mq9gHDbVow==","shasum":"f190bb31fbc91a9fec73ff42f63704285b05dd65","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.94de910.0.tgz","fileCount":25,"unpackedSize":65281,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCICQ8PqeXyxF1mxiEBEDtJT+VXj2NZoOO4+/p06kqpTvCAiEAnhAfPhG68xnTWSwUTj6o9fEBxyIlo+Ggb16O0awSyqY="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJig1VmACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqBPw//QAM6MEZPzYhHrAS/k/VqZ+ad5H01213pU7YSYYsFh5/Da6vX\r\nRCFH6X2gz6N+G379lsEgrtlmW+fsRXCcYgutlM9QMdFAgetDlwuCshN/Y9mW\r\nXH/SKA7g2KYLwS8lvjWHxVxAQXjF4PggIToP0jICl6DbQ7tDUzMlAk7Rwfc1\r\nHsXpbh13iD7Glep65wH4kWooSLxvUtjy4hzXLP9rSFZ27+BGz8WXjOtUZTRC\r\nQNO2OaWGOq3tH3ZsHux1d8e12TTpNzX8lh5znPH7ff+KGCzKHOz8BSQ2e1P3\r\ne2vA5Q9G46Ns7Q3bTpmU/f4KhIShHwqU+0NEW6oPQL8t766hOEy5PsDziSgr\r\nyri5IXTftXns3DsOl/R9QqsOqUnwVjnd3oFRxuDTJy2OcSNB/qe0bm13gFQJ\r\nI5vUMFSeIG1PyDvv83cPciMNPKV38s0n98IKnOEKC+8pbRShVLurgza9MSMZ\r\nG2NnWOI/3r6MNH/5XpZkTAIUTfG+W9cDgGqfTy7E6Uz5pnY0AI/ZDoI+RAh3\r\n2qz1oiBUcB6aWDcsUt6JovTi+lUfP5epIhg4FSNfWaq6/6NnViCt+eY+/Avm\r\n+OiG4KtA9OnZvbb8d77bpyu9fHoZxDOX4jmkYzfHJHlZ3juE1Fks/Wi6DJ6x\r\nhzqU4N2FV4FTqOoXefsZ3v/18mIsOJ3nEZ8=\r\n=1qeQ\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.94de910.0_1652774246724_0.4759291472129854"},"_hasShrinkwrap":false},"0.0.0-canary.a8535bf.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.a8535bf.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"0.0.0-canary.a8535bf.0","fusion-test-utils":"0.0.0-canary.a8535bf.0","fusion-tokens":"0.0.0-canary.a8535bf.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.a8535bf.0","fusion-tokens":"0.0.0-canary.a8535bf.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.a8535bf.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.a8535bf.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-20ZtdiZsvEosTJ8FvhJk+Ptk9ZVI6VX7U00gnqfjOfo2hY59znmOdNsG05ENNI6vDf1MqsyHHNTLVUOWhYzQ3Q==","shasum":"b38f6a417ffe0122f48f72bb24b8c86e28005abb","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.a8535bf.0.tgz","fileCount":25,"unpackedSize":65281,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIBap+USgzxajPV5WNyXFI5HEkHcmZZDqTUQynBYKFGIxAiASgY7TcQJlJgh1NDH8gD/jBW67P72NNgAxCkBThccU7w=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJihBKZACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqOng//TOIOdPLQ7yHJVJtTcJYf0SI7mlMT5m69bVgk7t1UOiqPdrQ+\r\nUodBJBgOqxWcDQUH0oxDJYoFmQ08vIIjIvGucmj0y7+QtOO4pgcxl1HLAHer\r\n4Jzh2foHrPciWDBZyiLdXoUBWLkUCkPobyvKuiblZ+qJMsiSjoEhJmv5WWvd\r\nVTg5Pampw85b57EfvKYc1qmo2TaAmZZVLc8S+Hnw37nCyQE7QJPE2yNMPfTv\r\nv5RJ6a8UQoq1jWt7p1FbPnVk4zQSTPp21jccZcDqdlTQlOKcPQO41vPCnZ2O\r\nH7ctJbsOR1nGgKfgoMLwXZUdwhrIQvWVvpXijnVcqBYYesekHn8OAV0A80/C\r\n/qVnx1eHOyU2pWAEoGaflwvSDvBORDg0QKHeLumYKDCJaMfxoES1yUExPOKF\r\nARh+rxuDcn24qcw2+Wh9baXxVFI+mYB17Vm0yPXyxxoWo/z4hrN5FOaZNK38\r\nnrClGVBFifWuEwomCGtpXYr66La36i9889FH00hzz7oIgotqiVmKPuWC+KJh\r\n7oNzN/lLgjivwWqu/jZuAoZQZv611KJR3Uhp1yb9XRl1+oWvRgRYetW6JT1F\r\n+pv4mbOIFK0klHz+mHOHhospy2rEJHe2w7zC/d3gk90Zmjgf8/6jPuG/BlHx\r\nIoixqAIsVTcqBIQeHIKxVcNs6AwtTFyGg6g=\r\n=hzgN\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.a8535bf.0_1652822681687_0.21112909977777417"},"_hasShrinkwrap":false},"0.0.0-canary.7805140.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.7805140.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"0.0.0-canary.7805140.0","fusion-test-utils":"0.0.0-canary.7805140.0","fusion-tokens":"0.0.0-canary.7805140.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.7805140.0","fusion-tokens":"0.0.0-canary.7805140.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.7805140.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.7805140.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-YJ9YiEN/eK6/Efsacqob8Ta9m20EDsy0PME8/C91+wPvb/qWFkHzpEBw3BnzYDR7vSkdVcMkZ1X4BP/eo1G94w==","shasum":"0a62e7283b3d1b6445de1992b2105ec62adfa31c","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.7805140.0.tgz","fileCount":25,"unpackedSize":65281,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCICJ9tpLNxXeeWIZP5VqkU+iLB58UcG6e1mY/TgHDV9TUAiByh8uPM+ipcXuxFrSETMYu61X4+W3jx3OvAmxMq5v6bw=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJihF5+ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoxmBAAmVt1H6dF8snISsJWhWFnee5SPEaWv+9vG2eH/qrqN92+/l2W\r\n9pAAnF7udNq965w/DiIklKGLmfRPmJQwe2vaD3jNAbciXUhZiSZfIslF2HXy\r\ndr+ea9sxYGWmxDLu51J3DkC3wZBDmrmyGfsrkItyw0YgZGrTs9q9YCCGRwpr\r\nKlxU/mWKanftXXmZG24v2AuN5S7fSNlnwJFKwsmk5E4aEWLpG8BCmoFAE1Ct\r\nxtgxdOhZU0338DminxNJT/1EIDxCU5EObivfc2Yzt0S5ek+ctXup4+hTNHy4\r\nHUAOnLziu6P1MPQvquQk2+txGIOjs+l/6UZ+fQOFLHX/YNpytKPN4VJqwzCS\r\nZ6fDQttvHI74kRh4Vv5hWDyMVgIHld2oV8rPXSGe1pw+PvemBKxxxHgfRiJz\r\na5DzoLypHTGzDa8a6TcixRqcF9JMkIa7YzEYrRU89nbwfWCUvMNUG6uSlYL+\r\nl6WIBzmqRWgvmtLzytfo7whmE+aStp44KhHXidwqlvDTL2MvMPYPXBll2XdP\r\nAbqEyu0J7Hhn6q4QFW8bAzmNG7ZtoOhBldfTz6ZlBLqVGLCZlRRTU8LOxl8R\r\nGu605mz19dk9LvwRXVS0C7JukSVb3WDw9YPAtlDRN6fmI7lKWoHWNGxqlYVG\r\nAh9FKz4bYLU8/OZW1ZVXKMuTeKMN6/GHuxc=\r\n=boD7\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.7805140.0_1652842110589_0.08270219416350422"},"_hasShrinkwrap":false},"0.0.0-canary.c454879.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.c454879.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"0.0.0-canary.c454879.0","fusion-test-utils":"0.0.0-canary.c454879.0","fusion-tokens":"0.0.0-canary.c454879.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.c454879.0","fusion-tokens":"0.0.0-canary.c454879.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.c454879.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.c454879.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-OVyG3vhSDaBOxISgi+qS31hCDUvOTyIhuNTUhag/RUzSPfegy3hIYG3DSPO3jfY5ccEkQJdoN4AtJeO0OBTGqg==","shasum":"52cd5fa2c2e4919dfdd9b8fbd48e2334ca89fb31","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.c454879.0.tgz","fileCount":25,"unpackedSize":65281,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIBIedIe8aD/HDWRcytmzYh6Qr3L3Su8/Thu4ZeURAb9vAiAM6FsQuYywzab56jAAbi8XBVQXO9VfW74irJRshSp6DA=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJihpxHACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpqqBAAleKppbRxy8ApEdjeS6Qb2rPEUa4GQqTqEiUoEy4Gk0q701ZV\r\nc51HZydQuaH0Kymues7E5X268JWPMJmtN6R+Jl5b7/qCEcqpAj7ZXiTRV33f\r\npf2j9fQVYY7kL4nDlgoQ2UOXnV9AlEj6nEi9NzWW4yzbQYd2QkzRByhmY+5Q\r\nQVmQO6nQvLrwvT+McJpBnUhVHvLuymCw0W681KZI/p+u6AtEKKkvu16fbR3J\r\n7+8SXyeL6NRcTIujQ2m3Qucu5mDBXMNYx7uRCz4Rfulcf+QXNuI5ST20NQ/p\r\nhOY2i6SKdOnfl4VVcu8qVyplwSbPFH+0E8vywWKvzZFZTwN0MSh4GUQHIGV4\r\nPWr6XpZmcae93CtrFFavFK9A+JZDlqz0iUKsgufkHYOzV+O7igP6fdGI0Je/\r\nVIJtr0o+3RkQj+b6D/lcrmOfvHFcPssDlp4yWq4qnmz+8+y26yHZF0IvcjAV\r\n6c50E4HUBowxiMNkKFj20XF8rcr24T0VQDYgvdAs9XfwtcE4sv5GNCnNGsyI\r\nZRjnT9qcWQbMLRWaXeDCwNNzIOu0BK3guwAwxtvt/tIrNAlvGyxdAM73U9sk\r\nM6Fly6HK2ILrA3vskExe1RA7oXMEiPnabIVPgdzvlNxkSVMWtvuTiygTbGU0\r\nirvTaV4hfLWOiQbVbZ/gG5EkIgn8Lj/LyNs=\r\n=asRm\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.c454879.0_1652988999225_0.4259744130981813"},"_hasShrinkwrap":false},"3.3.1":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"3.3.1","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"2.6.2","fusion-test-utils":"2.3.8","fusion-tokens":"2.2.7","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"2.6.2","fusion-tokens":"2.2.7"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-3.3.1.tgz","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@3.3.1","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-IclFaBatAJBKaCKp+nLu6RAMsv/71f3CgJ1+NnDqj9tR1PO3LYY6kIrXnLS2LtrpOycXY4mg2mboWOUWwblP6w==","shasum":"af4fc1c43e48af7895b62f1795c686963e757c6c","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-3.3.1.tgz","fileCount":25,"unpackedSize":65179,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCICqanX4awwlqUIR7d1QYWzkbGsAOnxH41m7rRmxpAAgXAiEAtwIu/D3mcy5jGZwu7h2dRcmA4/sDJPz/0L08LjDoWYM="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJihvE0ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpyPw//Sen/YYLpoZLyVRqJ48K5E9eXcCCvOyXEu7xcf4//mihyexiG\r\nHrFX5NFWUctI4SiUOvSidAev6h/ypmPNNXt8t2dprJdy+iKAF7vcjdC4rQKp\r\nATejFvW78e7G8pdnvg3tz1k55wFVonkEseIHpT/haM9LMiLQ6Rs2SSyN/DGo\r\nwxxfEoS1jJ5Hjfy9aF+pw4ikc3zIJyt6TNBRHyNWXeH82q4y/VbyjrgviGq0\r\nVawdBsCPyu9dBNV+gAAZz7eoW1I9AR+RH1gtTQphGGr/4SsQT8+hSJGGaa8r\r\njirLK9ftxDmmiephK7yNqVqHg5BBruwPJIQuHD9NyHvRp+fnXxBUfpEH9jmz\r\nwkz4X9+AVNokz4O4P3Sm4dsUG8R/aPjN5XFH8QGWnTRi3RxojsDc275KSNcU\r\nZ5rIBio3KwKPQwsJBunM8Ty/pawX1pigILQl2XScAGoyV/lbDSymf6dTcHMr\r\nPnxgfP1BEuFf06CL1aSdXtT4+psHZDvpo4W1ATYKHG3o1k3LbrXJ2g1joCfC\r\n75sJwE1O+DbyuDaHnlM2l6LvOqvFNkJDl2oObtmEtCTiQgRuFRHgwazTO+dH\r\nclyjSnQ3Z+QZohF7GHb9moq3Uh0IVwx988aDgsTI5cKZRk5jvtdH+WVFncQf\r\n4XyyJK3gDt2tkdX17jXJqiyuC3L1IekdNVs=\r\n=Eiz5\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_3.3.1_1653010740732_0.8930122773720459"},"_hasShrinkwrap":false},"0.0.0-canary.234cdec.1":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.234cdec.1","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"0.0.0-canary.234cdec.1","fusion-test-utils":"0.0.0-canary.234cdec.1","fusion-tokens":"0.0.0-canary.234cdec.1","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.234cdec.1","fusion-tokens":"0.0.0-canary.234cdec.1"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.234cdec.1.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.234cdec.1","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-+uhbd81m/bPJze1LfYaJzj7O+TZ76At8mzXCSuMVVS+maYFc6o4kn9dHOe8c6t/t0Z+kc7muWmH7JwsN5Ndu5g==","shasum":"f708ebcd67c70221014abec03bb57d4d6d53bb59","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.234cdec.1.tgz","fileCount":25,"unpackedSize":65281,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCQMaqpbZby59C+vJbo9jOnSmYuDHbRZ+FZfKo5PcPJzgIhAICGAJOqxvKjGRWoRQOBh/D8PHPTcgSbYB4BTw5dCiLd"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJijvu8ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqMmQ/+IaKzhWRlHzVzqAf65RZqnlfH4IbbEm9JnOWQZCI3ol0E+XHF\r\nXqoPjuIpm0yzECE2JAen0HPPBxM9ceCG0UX33h0jX3f9tERRT3Dj06//edDO\r\n7k7wkwhMoIVX4Ux8Ssz4LHpIPPaNxGF6CQUvCF6TV+drDvSt9aZ9Vipw679U\r\neVnCGitb7G1WXQ6l1paevIfD2EY6zyf6nMnfKc64SJ+CVQarYT2Aat6L+DTe\r\nWwtPhIVpY7YyAQWLI5KkabAJ9QlSMumg6QYI2GinP5GUF++zEVlpWqyVJsa8\r\nGFd0mf+669ifTJ2CV5kYrUbl7MqBxjg3zwNaNeOf7lE1OrvSRE+bif7pUdnG\r\n44wFkfAMDeNb3EPxvZBgiCnztL4fIMjS+JVNFrIsLgW02uqlbcxa2HgDpRPQ\r\nENYXV1VdEaau9Qbs/Z8nz9PzlrP8G3fnkSphFJXUyfNg7V2rjL3b5L66IKwo\r\nw2+vvZmw/vnCUz9liEMF3mlnFDfQAsggOa8wP+RZDjuzX7Eh7kBnqlrVdFS8\r\nj0DssuUOKP6Js4YcqyMOqBGL14DiGV4BjgCdU+XcCpFdTjDHCNemAunJk8W2\r\nhVle9KqYZGguIVo2yeUUWWiPh6bHVakHa+5B+6aAYgA35V320YGUtJ8ra0sU\r\nAuOuiTJVg3yuvqBwwrhssI8LpCfE6munU9M=\r\n=4q7V\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.234cdec.1_1653537724219_0.22485434880806765"},"_hasShrinkwrap":false},"0.0.0-canary.ce07ef1.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.ce07ef1.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"0.0.0-canary.ce07ef1.0","fusion-test-utils":"0.0.0-canary.ce07ef1.0","fusion-tokens":"0.0.0-canary.ce07ef1.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.ce07ef1.0","fusion-tokens":"0.0.0-canary.ce07ef1.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.ce07ef1.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.ce07ef1.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-bro3fc1Ldmd3YIw2DPk9+fpocjW5kl4NzDzgX3rkzEMyhgGrkQcLN7yeyq2xmroeyRPSI0Gp30Asi2X5RLvwvw==","shasum":"3e897a9be8b3966ecc129edeeac89303148d5799","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.ce07ef1.0.tgz","fileCount":25,"unpackedSize":65281,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCICUthR6/VmhLYSNzlGAj+R1ly/BGrwxuO3OARJf2nCSAAiEA3LPo8wRtQKOCSCbvlravsqeJVDsLsqZ2wglWVKOgR0w="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJikyMgACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmraLQ//WRpggeTFu2bpLToMSMSkRsfIU3Z7xykRozUyLNT6aw7gaZ7i\r\nNxUCAx/9hBgO2GwFp7eFjoX1toos9tZUnpAEBR3m57QIrTzgSlyaB3iqwSTg\r\nvrJ1BrJr4c+RFz1i0MZHfQ2l1lAPGmOvY3rQcUml8RmMRAwoq3wGOu0OH9lh\r\n1+i0JpqkFiK2U9NO/IEGbRjuhthittJYHGu83XfzApA+W44cEZ0/mqXF4n9I\r\n73CHcQMK12OROT7YnEomFCmUrOrguzgK2B7X+z5gDGQ24rNvT0Sp/ybScila\r\n2NGf9zk7Sbs8G0xIGx4l+A6cSCYu75S9Qv+PDpCY/HrCnDDgPQYvraA34hUE\r\nycM4LnJOgsSO/56I3/7DchNSj9Y3mryLWVvWEYyhHxFE9DjaTmv9NNR9OoB2\r\n3fPMZ2E7/rajZRhmwkK6eQFzRiLITXfNRpeoLJy2witrVPDSDr+HaWz39I13\r\neax2I5b6dUdnepsckYqg7cOo3VZmEkMQ3exHLlRCNCbmloiaXEXmzJp9b4nM\r\nvFHaYcfqIWxJJEBgwTWQQ2Yu+uEMqlAiMPIwiiW4EvbfExD7l8MbwMI0yutj\r\nQkC77AYk7Y2o4VGjPSSb/HhbyFKyjxtc9TF9C87kUBcYqobey2MPi6VaTEmc\r\n1QncgYXY/s5MExY/mARGhs+2HijGygML+Lg=\r\n=r4v4\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.ce07ef1.0_1653809952441_0.23723850400041102"},"_hasShrinkwrap":false},"0.0.0-canary.6d29913.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.6d29913.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"0.0.0-canary.6d29913.0","fusion-test-utils":"0.0.0-canary.6d29913.0","fusion-tokens":"0.0.0-canary.6d29913.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.6d29913.0","fusion-tokens":"0.0.0-canary.6d29913.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.6d29913.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.6d29913.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-n+DTkeFh/fK8QhvlIff9W4sUIeyPzB2nx01WIuJ2OWhc450rB4t3drQ9rNgFwTPR+Ci95bUhBuTZLVHXmkzyFw==","shasum":"170ab0c120aef691b2555c8dad0b8187a9bae625","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.6d29913.0.tgz","fileCount":25,"unpackedSize":65281,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCRy9AIKgzBUgIHrS/w9INW9HyTVVVsL89xsdntyc7dKgIhAPZyhYEDKKaNFElZVBriQAyDKNfHsVubK3uQ9HTbqPt6"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJimaUtACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmr57BAAnY9OHWxVdKb00hd2Ybukb5oGDYoC4TRU0OV3FatPwK2t5KVn\r\nBodkx/tPWoiWjOEuXBZLw0ax31OUIKUCy9pscNjP5/yl0UFAenUYaweGvYbO\r\nChOqAQjXPSa+lO9SFbi88PiQ11udtMEYK7iYAgX7XwCUduCV3MOxqGS3V8oj\r\nU6KtBGfDf5lyHf13HAolsqG3oQg4a+JF+dLXMt1A+xiGH1vvlFwwHeYLZ0uO\r\nS38k5H6SzYwhcl1uk0kbgN2/UEnoXORe6dCjz/WRR4pXPYGLPiWBYXENL382\r\nHqlS1fT+ukRgaMm494xtETSy7TtOEOZX2U2STwSxzmYPwcaDIu9g53i0o1Hf\r\n4JgRihEnWkbZoHPPHz6CqrwN/XqIM8zKDD8h+D93iyEGjE6kCiq2J55Mbrdp\r\nxV7ElzJ9zaUZktfD+N7CfzKp1VAG8KKfta9YAX4f5/X0mOvDvZ6Z9LfFmqI1\r\nZ8bRGuH7h1gyAferofIAi3k5Bc4w1K8BgioEJnpXTWigChDOnuEMQarPnhB/\r\nCgpVkwUFMzOUsBvmrtFQFk6a+ej1xXgrf7mAsec5x89IINQww3T8oP2+XMlO\r\nIqyTc4yxqeHC4D20NhZ7pJKIHrzbSqxz1gMzUgfP4jSWPMkqK5mBBuGNZpRM\r\nu6za5pPgvoiZ2ZXAgWwIm/92s9mv2kDIyCU=\r\n=Du2e\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.6d29913.0_1654236461264_0.356765952689287"},"_hasShrinkwrap":false},"0.0.0-canary.eac89e2.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.eac89e2.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"0.0.0-canary.eac89e2.0","fusion-test-utils":"0.0.0-canary.eac89e2.0","fusion-tokens":"0.0.0-canary.eac89e2.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.eac89e2.0","fusion-tokens":"0.0.0-canary.eac89e2.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.eac89e2.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.eac89e2.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-1t3tBme7s/A42iADUjGrcmLrfAt9OM9g8c0YjA5F1vaWbpnYzYgGKbANHct2U08XNlEa63QLVafKNEO2cFgv5w==","shasum":"67c9e15e6ee3e1414593cb24801ec00dd09a81f7","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.eac89e2.0.tgz","fileCount":25,"unpackedSize":65281,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCXTgIRhx/LctzwiSvGmHq42NHfBLsLQQEuzWsw57Z+cQIhALcX0ag/t/e5e2VSjUIq/lFMZFkCSd76aS0DVJkF0ATI"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJimbdrACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpdKg/+PJUNwhbPEsXAKjyNIEFIGEtUvrLE2sn9s/FF0iZvSc617vZx\r\nmPrZjMPFiqdkgtyPunj5klibViOIBuDvBxVDLvAA0pY224pVIb7IV6PFUpye\r\nZ65CHdeQ9AikSC/WafIUda10GDyMCAG1glmty2Ujs7sxc5OuFiWe67k3LqG+\r\nRL+Updj6Ne/56xRkBeZUuW0TFAvJ82gNubp4znPO82BNhflfwUqUUTVB7/qe\r\nHag+KZNBPW/aIcQGzda9FNEt9LbwuWK60iKMi6m9tFqosEcahayskFuesKrh\r\nJxKEj8MUgLtCrno/IRkx6GgPkX35h/tk0PkoOPiHozXend/Yd785CxjY80wB\r\nG11h4csqnfoyoZM8cb6SjclawJRgiROcn9fRojhqpCzH9vWZ6sED6a1givBN\r\nrDFVTK+L/aoc2/nMiR2SNmTAoh8RMQ6J7Gr6vmJtaSYSEm6JLo+iiZ0jbHpU\r\njuWmAPa7b008nIfUmyy96yObt4qLaUJvLuyNDHrcO4Bn/myTrLk8HwbL0vlm\r\nNL8e5cyvuk3b0SoM+viU6PCuXuE/9AK7NU+R2a9kFn79BWfjmLVra5KOBQ+k\r\nvycXc3rM9e3qOBSSLKHAPNm7ZRn27f6ssVfFX7fzLtudjoWxfNWeEjVqhVBq\r\n/i9Etn16SBo4asBJJXihDTiOTe/8djZxn1k=\r\n=lYWD\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.eac89e2.0_1654241131540_0.058284394445673016"},"_hasShrinkwrap":false},"0.0.0-canary.c36b35a.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.c36b35a.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"0.0.0-canary.c36b35a.0","fusion-test-utils":"0.0.0-canary.c36b35a.0","fusion-tokens":"0.0.0-canary.c36b35a.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.c36b35a.0","fusion-tokens":"0.0.0-canary.c36b35a.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.c36b35a.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.c36b35a.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-yJGuZCuVmQRxbWbd90C90xwKWRIghcQyyoq3PFXEBoqkIyAb0njRFd5iTqJotdidrAdUvZQd85o51Ssz7DfRmQ==","shasum":"ef50e3841a6256ef1acb2906672527582d31903b","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.c36b35a.0.tgz","fileCount":25,"unpackedSize":65281,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDasELPQOzy06cgvkUvMzUq5UsFcSD6Dm119Sff+FCmwAIgeYvFMuNgt3G3zhyLVYSLjEWcv9bjv1zsKoGF2eeLcIc="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJimoeVACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqocQ/9E1qgHaFhkS9pYvxsWJpzREEUMrGsFwSEoJ+aJPYawmzSTIH4\r\nEpC0cJZHwIko6d2cLS6ZSwsF0bH6QkqhSCVzQPFCMKYYgxnHEI1jNak5g7hO\r\nSZHDic5kmayzYvzWhdtGAD+DZiJlCArRFsIkp4q2fgm1tGq/F1l+3iyTxzbn\r\nMhdec5ycP0QM3rdmMz4tdU6kKnL33/yU9TT/xyLdytQ7SGPubKkRkiuIOPaE\r\nGPBzbpXtLGe31gpdYsBsPMU3hm8O0Pg4FNy3SKg+idG6qznKodushVuz3l+L\r\nb9YVYl9Fs8thL9dssfiVbILLUdMACo5vQK2HM15g3PdtMVBy3y+K801FW1MJ\r\nifQqo90DEhxAePVf2ToD0BSHrFUPitHRekUx90dm+J8O55xnFiJR9xI7IULx\r\nVxdUqSe6zjlBpsf6jjmNUs00jBqcvkteT/ssRkapK3wQLteouT4XhmiqvbOm\r\nC8lT0u00pU8664nCtzPJ1ymnMv+wN25LH2yavMTIOXK2WDruiXVByI68UXGL\r\nBwKHUpmJZ6n8owTM6i+j9YVLh6zizkumEr3b0vT6in2n+uM0KaDuat/hq4hA\r\nD1TTOGZqqbnOPsaXL2yq6AHzfa0jB4II2wi49dlGK4BBoHFkKvBTj1EEEMD9\r\n1ODxqkwzSA17HOi/mEr6qNrLmn6+vlT1s1E=\r\n=0jML\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.c36b35a.0_1654294421216_0.722605305050859"},"_hasShrinkwrap":false},"0.0.0-canary.7c27df5.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.7c27df5.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"0.0.0-canary.7c27df5.0","fusion-test-utils":"0.0.0-canary.7c27df5.0","fusion-tokens":"0.0.0-canary.7c27df5.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.7c27df5.0","fusion-tokens":"0.0.0-canary.7c27df5.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.7c27df5.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.7c27df5.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-azYRzs6s+swnzuGegANJ0HHmHn8vltC4mugBVrwph1tgJm/Rp+Vgw17EYAqc21mvLiRYGFHOxK6+sG5mB3eTLA==","shasum":"62f2f44cf4b5ee912d61dd4f9f4ed09c3d82f65d","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.7c27df5.0.tgz","fileCount":25,"unpackedSize":65281,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCICIyRoaT+4lQrejIWrjXvcHf8mzLU6fRvbKGGUksBee4AiEA4t2f9wDPGxXTTy4bD/s0tbDkinXMldnTNneqrEYEc6A="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiqO1PACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqGYg/+KLUKVk0oFs+aRKFn8/IrBR7sZYujGE2AqfR/8WEOzUty06vo\r\nh+5JlKXoW0J1ecr5PnQ3mtCyExWRZIEfDIdGFfTAi1XLFwLc7jVLPQllVuNJ\r\nOMUrNJIUwramyO/BsnTML7VMMJh38EPYaBqufsk/zJPDSxFxE2xzRc9hUkGv\r\niH4BQf1NHhxr3pW7sU0SnOSSyEn43ejMRAMAwHjvjiaYgYgKsUcn6rfkybpd\r\nUv7+xJ6wOMQw9R5t7L3+XVDqT8ARbh03yomn+ChPWhquKaYuNPIgdRv7udUa\r\nIgpUoLi6VIwNygYvt5W3PXvCsHc6uNLoJMUivL6QmuqVwkVGOJOAzt+NKcIA\r\nV7x8iYOWuJKq7j2nmQX7GInMo0MdpwhoLc3xV9TXahsd9UI0cgKiQxGVz37c\r\nuQl7lWp++eelvAMrs1KH2qYM78Un55+d5LxZN5UMaLTOIhxjizV9GNMOfW/C\r\n5n5KGT1Z0sAjH6+PlL+rJ26ReXZ6PEeofvkqddoQyZe/yHDtjsNynnQiz0ew\r\npVuezKwwwbvvNJHfLaItWJwPpbM5OIlAS9MKzT9dvC92CWxJnRSNoLVf56Ok\r\nhZzfG8ELI3+6J0xKvUkYAtkLiEQRPvLHwboq+/PJtRgqQfQ3ezuTugC/k16M\r\nzaRmZ0PMr2EVvS0wDz7OooZlBqRORD8HqwQ=\r\n=oQHs\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.7c27df5.0_1655237966889_0.6881539006935986"},"_hasShrinkwrap":false},"0.0.0-canary.8894dd7.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.8894dd7.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"0.0.0-canary.8894dd7.0","fusion-test-utils":"0.0.0-canary.8894dd7.0","fusion-tokens":"0.0.0-canary.8894dd7.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.8894dd7.0","fusion-tokens":"0.0.0-canary.8894dd7.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.8894dd7.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.8894dd7.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-yhaIwcjnh8RlY6vCxYN1gFgeFh+hPdsbPxW5rQW5x0BqqXeDHZ6WU8T8EjcBEoEarTuHKPsC0wnM7DyyZC8Wdg==","shasum":"727dd1b404d13a78c8ff289b3b83a9c78faf871f","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.8894dd7.0.tgz","fileCount":25,"unpackedSize":65281,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIAJ7YTcLTGvgsje4stUjjxNz433g1U817ygsZXsUEsikAiBMgp/N8SGoGu0mWiNVCnXXkEvgJLpZOQn69Tt01vQZJg=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiqmSLACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmr+Vw//cOL/VmuOS3KLNpziYjPt6QplM4OGO7+n8ZUGVysRc8p+M61U\r\nWQYZ0D4WzTyWmjyZ7MseM6Xb02LGtLe3YuJZKghgJdIiu1XbgakKjDHwXKoy\r\nlEePSUeh4u9mbM2tDXaFVE0bBXONj1vmJhzAwUY2seT2nxG2MiKF1kMAfmhx\r\nyRgRHi/NDk9zsPNbr8w/qsgysIg/4H0HsjOW3yT2i7EXSkD+foMv80N8RRlG\r\nfkBfe3QCMmEudFyo7yteK66ZihH5Jcq2jm9d3dnoRWviG9vwtC8iebuEoUaM\r\nN1yqGFTSSml2jqXmiIR7aXyNqnhyUahGWQ9LhwpY/qac2/3ogT6L6qkIjCTJ\r\nuVdoWC1mPq3oyRCuMOWMovyLTvphBM6w/UTKXrvGxL9f5RCGt8hdpDM5lCRe\r\nLll61jxOH66iWLevUztuw5huiYy88j/vsC+uvTL/5zcAVuCYYj6Yj5SU4Q53\r\nX7m5PnopW89NK9ebHibh4VJoBqr/Ojd+5jWmDxcn83Kcn7UwEUt8OnsOsw7u\r\ni+YTO9Z7PgQNuX/7L/rWKZf5+X+ZBVj7/QjQdinb7CohLVH7+1Qfwb7tw2/F\r\n0NGPKG/L3I4RDwozU9q/3R3XvHQO1bHMQ0QqoQCkgrHCSuK/8B6d+8UKTaCA\r\nDYTCTsbq91suauhCr4o1JZgMQgLZjdMhQzU=\r\n=M6yX\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.8894dd7.0_1655334027328_0.7681930473501817"},"_hasShrinkwrap":false},"0.0.0-canary.5378c1f.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.5378c1f.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"0.0.0-canary.5378c1f.0","fusion-test-utils":"0.0.0-canary.5378c1f.0","fusion-tokens":"0.0.0-canary.5378c1f.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.5378c1f.0","fusion-tokens":"0.0.0-canary.5378c1f.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.5378c1f.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.5378c1f.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-n1NObjab5lEbHijYbHldu7tWX78j1xvPZDFbnZjIIWm8idL3rHJtFHUZ8dET5DT4vv38zQ+vpl35Ns8eb5p/oA==","shasum":"b077329cb47d411dae5150fb700d4b741a6a7a9e","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.5378c1f.0.tgz","fileCount":25,"unpackedSize":65281,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIFVzOT4BhnHLNxEIQ/vSlUJuifKM3y1ujbzDNeRgynK7AiAKY8QZVephZ/ob8e8FDLoj6X+UvMkj1BnWc1W9Kp3aDA=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJitkO1ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoxGA//XmcTIG6BbDhhJ4GBJe+gSOx3K+WokneOSiIiARMM2NhxR1VI\r\nIdcMqkTYKMDal4QlhNF0VWFOCvVYUeaxA73X7hEP2Jy0vqw9l1IcTAX/e4dT\r\n3oxRiTId+Llj8lFTeHp77cerhjjhWZii3G4atv9MZ1Zv7yW5PUyluJq9F7cK\r\nbUQR08jVnhkP0cy1hyUQ0AmwomsGqRiG83G4bG3C0EumNu2o3POJmkaA+Z6z\r\n7dL8rg0trYofTJV4eRNQvNiAH8ciK/doKo5ARApT4QPfHW7d8to3dW9L0Ts6\r\nHM0nMQXScjgucbShptZKqTWsn3OjxPES8extkKDrtp+hCD4cEfAQg3UCgbsa\r\nMpgG3laN8FDYnFhLoCVWG0KlO3DWGEzr2JjhFh65XLmxa2ZB9vlBU3T5kcW1\r\ncPqmt98oMvePOPWeNUv/Adl/XPKL/zGss+jMhpAM+s6S1SnJPQdZt30B+BqW\r\nk9iZ7Tx7PEhXpO1kGStpBgMkBf9VSeZycYeLHVYqSGCLjZ9OKHVhPVB9j4Hx\r\nI7qgTBm66Scf+GJt70iel0O0u/cYtYUcmm6eSqzyE3dJnPRr6Uz2Fsw83PSw\r\nGcoY6YD9QuXQ0yVHBol1SHUiN2tFvzLJTv0nIGXl0zYxXMwuX+QGGWQxOuZP\r\nl6EkSTrbvZiEfYhr9vMOVve/YChOHS6yFV0=\r\n=OzeL\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.5378c1f.0_1656112053684_0.49271386357213753"},"_hasShrinkwrap":false},"0.0.0-canary.e08ad19.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.e08ad19.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-proposal-class-properties":"^7.14.5","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"0.0.0-canary.e08ad19.0","fusion-test-utils":"0.0.0-canary.e08ad19.0","fusion-tokens":"0.0.0-canary.e08ad19.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.e08ad19.0","fusion-tokens":"0.0.0-canary.e08ad19.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.e08ad19.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.e08ad19.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-iiDyXlgekvlqKAfwBwL762VSmcu6Mq3Qa2EKpNgUp6jllzca2sK6xHuza1OglE72EqEyM8YqVStWKLOvEVwnzA==","shasum":"055fe490ea6ac16c91aa3291514eb2fcb6c3de21","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.e08ad19.0.tgz","fileCount":25,"unpackedSize":65281,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIHoZL1DPOp5cLZy/AJIH8ihB8jHCy7IAetJu9j80TfaoAiBM0xSK6HHAmSFPcW/vdHK3lsS9258Qn/UzjMr9ovpG3A=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJixN/BACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqiThAAmwjnvhw5DZ/WeDOiPSPsc31iOp0/dU3+WjJUd8dOrGzBTK3o\r\n3VFxzhu54UCHklP1oQzuO5Dh+tRciYhKIhQ/VZSy0pw95OeJd6cL0UGSOWTE\r\nQQAbPhu4ldOar8k3MJXkbKyIfpwDPLJPOLi6WZtKbBVOmFFxlw3s8TaGms9H\r\nGo51BVbGKbIxpm30fnlIeQDXbHHpHfYgj801PGB9RwmcZ9+07qxAGI3393gu\r\nhYGJX2Xwj6H1appIIwu2AdX67XndT940bnjuMF8Jrc8N2jRX6rpz9WbOEdJd\r\ntm9dX8lBc82l8H/hdBmDOx10e5/LIKNj9pbNBWNLiFPsZf7a3GVgnsLTeGtK\r\nUK20rUC7SIETB8UGvcdUxqSsgaKufOGj0ParmBwCaPLgD/i5MPYGecPjg/WL\r\nUFM1gW6bQhxBA4PKQffjJX++mxP2DyFdN0yw68e8pwxm2vh6o0Sor8RkcJaS\r\ntjVS/Qt4ImtC4pb5JejwotmOVfh/1mHo8RPLqRBoyr+cJ9iItLibHM31ZJXr\r\nalgxRrMeaUuSKybzxyFoZyAsMd/lisWPLyDtlu1OTH9RSXK0xUZ6Sbnr/I39\r\ndK/Vq4O3mNG5w7aUu9oBBs06pQmjYogeOuTJHfETctxED0bMn5OqgUCPUwIU\r\nFTsFseecQggIyvN5ZjB0Z28GCOmkX4kmXoE=\r\n=kwVy\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.e08ad19.0_1657069505485_0.04290005642640504"},"_hasShrinkwrap":false},"0.0.0-canary.57962c1.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.57962c1.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"0.0.0-canary.57962c1.0","fusion-test-utils":"0.0.0-canary.57962c1.0","fusion-tokens":"0.0.0-canary.57962c1.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.57962c1.0","fusion-tokens":"0.0.0-canary.57962c1.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.57962c1.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.57962c1.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-Y9XzN32jJ1+utsW458V3gl/Gen/kIlRy9/iZbYiKJaPo0xovC9U7BP4oMyvUNVCjqlqiUDr8tqj/lBmkx1vGaw==","shasum":"c69743fbd7c85d91a203b4b5a6ed352d2fc4747c","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.57962c1.0.tgz","fileCount":25,"unpackedSize":65223,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIDI1nbC7EF/b/wBxOVihhd572RvV8kubx0bk/G6GdXVTAiBZ5Mt9VUrSwJPartBb2bZo5Elw4AI/3bSzPUxF5+P53Q=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJixgmQACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpSjg/+PufLm3aI1xfXMC5bmtG2vmUfClTNqPEB8GiLmB3wqzd2WyzO\r\nBZXG2zdq1ALQkkQpIcl9bx2U51SrpHVWzJNT5qzLjQ2wkQssThHMVw2F1PIs\r\nXmxNJJDZEVgBKoYrmZYAMFgOiv57vqaNKPnTirI35NzCYJcMe1HwDmYhhl85\r\nUxsOO4PMWHxMYZKxyeM9fJiYxpuMkBsqXyIo+UQotkWJmgHhwsbXhPe84X35\r\n80CUK0ppZCxaeTHzhaHVEmaLLiSya6SyUkl4fPc4jdClzBZ4JzpPuiaDsU3R\r\nxqB/fkU7z3JRECigl9q0N1iweapjXp53DpkiTLE1Jj2DAhywrvi7M9bs6LSd\r\nChzcnAnL3BA+62VsUj8C2vA3PWvMflVD5PMp+knrpQRZ+uiRSMrsvEbR5Lom\r\nRFYzMZBInUloLBObM74Apyf5x0Ldj5esp+2SUSVRVb+qpxCJOzBUJHRzJ9RJ\r\nxMHGAfWMmCLkqTpqs957+nU6Ix37RGILEbguXNFS5ejoK8A/IMqDIeZ0Tgwk\r\nqxvt+yOBpc4vcKOxReaIkq61m6D1X7UM5OuN4oEPgk3fr46frWRnCIxNOczT\r\nEYTlyH0S++Ckg9pqhy6KLEc3LC5Q4Hz2tsmbOlM26x9jMRwj/JLP0VGfQ+Mx\r\nVV0qlQy7tp1wvbyCf+STvhlGyGfOONPPrJk=\r\n=FUcJ\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.57962c1.0_1657145744377_0.3339133667701977"},"_hasShrinkwrap":false},"3.3.2":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"3.3.2","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"2.6.3","fusion-test-utils":"2.3.9","fusion-tokens":"2.2.8","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"2.6.3","fusion-tokens":"2.2.8"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-3.3.2.tgz","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@3.3.2","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-XEc6lbQnEfEbpv3fwgKYFsrxsN7KWT6FtVibPeWjqRihdmnQFxpwHJyjTWSC5qzq+z0QlsW461hieRS81uKCPQ==","shasum":"21dfbb534860bb0df4b103250808e2e15d9c176b","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-3.3.2.tgz","fileCount":25,"unpackedSize":65121,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIAHhIPvLWrOkjD3CznEM6/QEOlSJiBBPtZPphB+IGJP/AiEAkWvmeGTxZh3n6vxQ81Tx3Hf9fdMJYlrjue4p8kezkkg="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJi2Z30ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmr4YQ//VwZLKcfHyFiWlWc0Y1MA8loB9S2VHZO3WjIABLXGGlx9PCUp\r\nw8vKj8meLLRdU50Y+uTMnQ5cnmmBfUck3bXQxGXD9lFbA/esIcER51nOThFL\r\n8gKN9+43mWQxd/zynIL2+5FvcFHQVsO/b/ps73O1EIPmM59UszDlvxI2H3M+\r\n0XgFQq7Up9xF9XNkiZ4uIrn/E6N4P5IWIpSIFL622DDmpy3LezynhvBft5u+\r\nxkUJ+6GiySMNJssJXLpMLUdhg1dBlNDHHKZWRz7T8I5ecJVGBgRsonXi/vlw\r\n++RFjYXX8lJn8GLAIczLKa2TfQORnohqm2Fk9hMFYrzh+QjPVXVoqQ3K8YXN\r\nwZ2+zfgV8Tfu3Dgk6ukBmF+zw5ztrbY5pYd9TmDHV6v8QF0/rjD8SZgP/o+5\r\nQSSAgBAbqgRl/DQha7X6TLQxwvrkx9WRRlGaHcEyz8IYQvovTAHw38yZD0DX\r\nquJvvug54baCl32T8JDcUQCsZ6MC22sWQ2yt3a3T2jU4fH2qxgijtTHPTwSV\r\nEG0ILcLjbS/lI8XVgGPZ23NO7ukWlg8j75kHMcDKhJfHcLBgpsX6RJ7MDXCN\r\nzXsvyCrJWOjIJJW8NunmmvGV5RDLi21hgG+fcFvKkASZ62g5LbTQu4C65Kpz\r\nYSaOHCXc/gZ6f/pnDa/M5QmdceMZvgXareA=\r\n=Qcsd\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_3.3.2_1658428915896_0.5964854703652676"},"_hasShrinkwrap":false},"0.0.0-canary.a682711.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.a682711.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"0.0.0-canary.a682711.0","fusion-test-utils":"0.0.0-canary.a682711.0","fusion-tokens":"0.0.0-canary.a682711.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.a682711.0","fusion-tokens":"0.0.0-canary.a682711.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.a682711.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.a682711.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-0wG5NTlcNgxfjbvGkzG/gr3JV843eh1aoqGzOmdVSvRC3thhAAkG2HZIDqUj3bsuP+q81eqqKDwjuLYA+epPgA==","shasum":"2d6ed108c11bed4128d9f7b639c803d2db40758e","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.a682711.0.tgz","fileCount":25,"unpackedSize":65223,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQD8O2yv7mFgQlUf6PEHLPoLfIGGo0bo1+pLbmP1gCogrAIhAJ5/yH+XDbTnfKijBAwyNc+o++WoKaczLa/uFrHdgmzf"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJi/ACEACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrvHBAAkpcPBlEnw5qoMIy7SDwb59Q4uj/z46y/kZovaODpZpnExxnr\r\nM7V+pmuaVwpgM7xWsZfzYxGQ966kebglQw96yatzaQMHvLJ7gkpUegY7DpXj\r\nFsEatBOQ5j6f3tXUrLoKLq5KGPgn6frLkrRcr8Aqjy32XuJBMlxFc9zsYNg3\r\n56agOIWYenOIx1QCu63bL+82gEQQKqdzk0bvH1AYgyqSh5PuWxxnNIEsm/Lz\r\nqthNpBFhylxLcKZqEaa07vbBCU27A2A2LRnu69wwjNyS9Pw9dV9fXYQ2fBU3\r\ngT82uCS7vBgNbibdiQZtUvcFbRu14jlDDKquiwGXrs80XbY5sNj3uKtWKQus\r\nfXVgcaUi6jCZ7ze5po21at7RL3mf0RlIFunTHZ2spGYOp8IosyQeHwnvSHKf\r\nD4Tt0rURNkRJmGjOIoDhiZUPH7nUQJdJBj+bg/J4kc/j0PjDzvINXqvMYnek\r\nU9khRZQxPwbJEepGn+KeYyy9ZS8s42OPJs1OuvnbjvRhzIcXYDvEiTp0HE51\r\nx8aPI+F9kQI3p1KE4vdM8Gk3vr5D4Lq23us9JotKmBc4TRmAi87ZnAKacN5M\r\nU1wAeN5oMAKSqsZh7/N+c6gKowCyLZdfNTmjzPhb/CDrshsudGuV7hGlkjqo\r\nbXIu97PgMITQiAYzYKENVa4kYssyadyRo7o=\r\n=osEY\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.a682711.0_1660682372055_0.06992172575235833"},"_hasShrinkwrap":false},"0.0.0-canary.47148f0.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.47148f0.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"0.0.0-canary.47148f0.0","fusion-test-utils":"0.0.0-canary.47148f0.0","fusion-tokens":"0.0.0-canary.47148f0.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.47148f0.0","fusion-tokens":"0.0.0-canary.47148f0.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.47148f0.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.47148f0.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-I3oXPM7QNbIvBv7MUYRd5zZ889/qqs+QGK2WzWxCCfslAQyDxV6XOGjK4R5okrOEpL56r95qKvPd6eB8OiA8Ig==","shasum":"51b4d387adf0bab6a951632aa40404a308b98334","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.47148f0.0.tgz","fileCount":25,"unpackedSize":65223,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCju3W8XCyoCc8lcm9eOuLoeX/me0rolQtwisLkgtHuXAIgH6thiAysWntfCYUsHkX8xD+vm+A1q/mAHhBBb8cW2WE="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJi/VB6ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoJFg//T+wNnc1oH/+8B5mN1Rcnd95Rv8pkV0shpxpSnPsHV65IvjCS\r\nO5l6YmxwnraJRDDNdSVXIH1ChIx1rjZgLOAx1ji8f1P8ctSVqH1G+PhjVJgC\r\nhSgd3L4EJg25UQiSGPFWJYQEpRxXKZRor7EcuSDNfPSc/JxAyOqMZVl4jbl7\r\nsmuYMSvDbO1C+JalFLAuUsUe6pELCqybcCuTNidCuFWeM8LZqy3t5FdoR9Kz\r\nF4iHK3dVsjGos8E5bobfPIaubQxoUgTWJpyN4YSTYCFUvvlBGtnaRyGInfXw\r\n0sYPPGJzfDPgmi6NZbuQMEXD7RvLpPQIxZdxbTbhNNV69M+IIRWu9yYfmff+\r\nBgBPajSJVPVX6aK5pftneVVc5FQhRl18tg4hNV8VlF65mJk2+gUpCu4Gi8AN\r\nsedeAL9ym3RMNWffQuqBt20EANjAYoZCVzwIE4fA5owfHMSLautxUwpqhWcu\r\nqLCFpEQ6nQOKC+bQWQRZNnokxbPl2w2GAcDMKXWnx9x/TN8IrwQZbFzBVBVx\r\n6wbnaiwrttV5eUuj0toYx8eMPwxp9uDi/Fv/3tzzDcMg2VmXEtBV1ib2dlLC\r\nsw7Zbe7u2u5Rszd8UL97ofV+9Vg042wviO8TGTFJyysidv3X9QCVV/iolUm+\r\n1CDgiE1siL5OibRQN0BzS3uRXt8oV+Ikf1g=\r\n=6xIR\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.47148f0.0_1660768377950_0.9618836854155892"},"_hasShrinkwrap":false},"0.0.0-canary.2645e7a.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.2645e7a.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"0.0.0-canary.2645e7a.0","fusion-test-utils":"0.0.0-canary.2645e7a.0","fusion-tokens":"0.0.0-canary.2645e7a.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^25.1.0","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.2645e7a.0","fusion-tokens":"0.0.0-canary.2645e7a.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.2645e7a.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.2645e7a.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-8K5v+m3scnPlq2WPk+LVIdBYJKtbmgzGS93Ve0PID6W7+ghu6o9rEekH1aT88hqpYOSMc7OAGf6nJ+L1A7qhug==","shasum":"433c926b7f9a2eddc27593b490aa86fb2319bc86","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.2645e7a.0.tgz","fileCount":25,"unpackedSize":65223,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDvtDf015KN5NKGhOzfJAJwaSIRWvaDRNsaEDHmNfnnTAIgNVeKfdZ1YsuHkTqFp2HRNhoG+xxCsNfl60n4NQ2vtbw="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjBnF8ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmorvQ//dIoMvyf9a0nxh+j09q4qk8qDqg1NBlv5CNihMlusYI1G/2LI\r\na8UzWjfMx72JN33i5Z2LcK1eWA2gcghYyepKAb9vdAG6p9yq4Pjs6ezjhFOy\r\nfx+R9JSjzIPGtgMF3N/EmwL39bPnzXENW86hGZgAQR17defO1dNBoaEFd9OS\r\nfE0fyRrNrPyIG+7P8qLCXkrYX0m1Zxw72g3D7dTdkeA8ojkg4bOPjLuqB57o\r\nKxePhbfkKYX4jfGNxVWoeRqy/g89jDkEj0kOR0gmdK9+ZnUUY66NUPl43Rgs\r\ny9AUZwd9lOV8Ltn90mJl8Auf509i6QbltB8Pw3nbLcSHr7tHgQYBqtEWcX7C\r\n973uCF+VPAcU//ky1TrwmbqPaDTmQnz/3/lJ2PLre4AEFlyzYIomv3OP9IBJ\r\nCL6eJSVJwgTrfOKuexKdtX7oObZBJWwWBvRodzBcDsvG8BfeLCaENQ8hntSN\r\naRIIcKexnVuqGOSCR4BnM5MJvAIwPv4DVdRu+g0WlygVktZhFsk6HPapyN9o\r\n1knHTEOyanhZ1W10eKSVZ6MYATz6/gEMXgu3QNUbFzg6DXlgnnJFv7X2No20\r\nBysHdMmDs4oyZ9Jvf8+LVVtf/6F9yO1csLRMwEHQWV6GCI8zxayoE1cF7kB9\r\n/sXLj8U/EpeoxYInVOM2ScJmqiJVJXIY4b0=\r\n=C13A\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.2645e7a.0_1661366651859_0.0409936613422579"},"_hasShrinkwrap":false},"0.0.0-canary.38491b8.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.38491b8.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"2.6.3","fusion-test-utils":"2.3.9","fusion-tokens":"2.2.8","generic-session":"0.1.2","get-port":"^5.1.1","jest":"28.1.3","jest-environment-jsdom":"28.1.3","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"2.6.3","fusion-tokens":"2.2.8"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.38491b8.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.38491b8.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-y9ybKckxg3k7f65KJF8s8xYBqNDXl4KHYxBuf/88FXPOYTj/v/QLSNdHS4hR+ukoKqU/fLFJl0O+F0C+h20Rgg==","shasum":"4c465457e9f72125d40105996550360dd1eeebd0","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.38491b8.0.tgz","fileCount":25,"unpackedSize":65177,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCICeObYC6tlepW4ylWhwkucmIYtR3MhYZMPg8Lcq/hDt9AiAd//ml2+bmqPZio0kCwAoprJ1M3Re6/wTfPPvm0nBUog=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjF5UfACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrTWA/6AyyiGrfjLI2xjvtKSaCO/QRDWp0izWZLELENYMRln6b8NNmf\r\nmXYxOo/jzT/HkZ9sovcL5XU08ijiG2rBIr2yoQaaZdItOrHk/BOTs7dT6zHe\r\nSr+yAUIdpKFIF2QPYfgiljCHadjPL9OW9/RiNvyZHHYChEBwrmLk3NDnL/AL\r\nWYLg64q2bh3GjfY/eHz03pejkiFvHloOYoM6OCYJvxCzDFP7J2vWIR+o7qGb\r\nGOytHlyYv5O0dcFj1A/WV1jwtGtP0eooB0CoeETkKv+GkIso8kLJ9KL6sPRd\r\nZCjzcYh8GlWfD9njloyIKLHpJ/4T1oU4K5T+KzFDmILgx7x/OSp/na4vVNlf\r\nnSAPWeKPpJEqRMitRxqYCiiGUTocQ6HkpwDfjwcR4earplTg6sZ71uLfm5Ak\r\nqlPRby9B+enjHOEC9o1cRtYhLZJEHE4ooXnNqzPOSsws3WmnGsZvAl5+09tw\r\n2OMEEk+ePl5XJME3WjcY3YRW66NQtiERyI7bUwFoyaJAqBeQSj33ycumIwKf\r\nq7/FQKCGbd7gCt380Rn+LXr1lJNDhw3EgvbvJSNX7HIIC2ViX7Qz4OjytwGT\r\nGOwynO9buQ8hqVqSA7soDJ2Gd2CBA0tIUq9YXMLwRy1iyn6KaoI38bBvqcu9\r\n/8G6tCpHGFyiiCHYQnafP4Gpse3Qt7oKuoA=\r\n=0jjk\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.38491b8.0_1662489887197_0.35007714377531296"},"_hasShrinkwrap":false},"0.0.0-canary.38491b8.1":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.38491b8.1","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"2.6.3","fusion-test-utils":"2.3.9","fusion-tokens":"2.2.8","generic-session":"0.1.2","get-port":"^5.1.1","jest":"28.1.3","jest-environment-jsdom":"28.1.3","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"2.6.3","fusion-tokens":"2.2.8"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.38491b8.1.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.38491b8.1","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-zhjXqhnnnOpO+D19T8cGkLotR/CgxuH1g65/hGwsLiUNKU7wl3YCa7LRQHTAGpQi5+ZHyiMN3T2uvHbv8aTRrg==","shasum":"8fd4422f62372bfa0f9b369f207c122f3145445f","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.38491b8.1.tgz","fileCount":25,"unpackedSize":65177,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQC92ro6odAyptgbkS7seZ7Vx2STaTi9Cd6O5Dqdh1ZTjwIhALW/VZpjokptpDBbUyiNRpoOYstMFnH7Q18Ztuk8GwUH"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjF5UwACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmriqg/+JxlcHt+aEbPvKB8TVoiLr5yhUsOxc7ipH4GkRyM5Bekafd5d\r\ntLfbCdZoyNLPLyw/JjlHUTxxv9LfjaZUZFSs8wzQGCf7p93L55dEd2mv5IZ6\r\nPbqH413TuhJr/z4oF2eCLxhW16BlxNBs6RgoRyjjHugN/2RPqDFiMDbzLjiE\r\nrMhy99GQWyfjwn21dQkWhgLuBdmaoCQHBAkFexwdntItzkzmwoCW18RqL9J9\r\ni7ewTBWvVUKDSqNjQdfTBKrrzRwT3KpI7KPJs5b+AAiXP4OfA91D+WCcmyQX\r\ncApg8dnSb0HbuFA+N3pr4GNSyCLbAFxaBp7t3qGomBR/wUHAPdZkKZcm0CjG\r\nPNftf8n3m6Pp2QRRDCWDo6bCmzm22hAsVRg2QoUyteHPornUX+NnqnUNAACk\r\n5/5+mlZpuPx1t94mXgwowsn3jkhn0nxYmLLuZAc6x9jmX+HNXWgdctQdrPGW\r\nh/pe2XaX+mC2Wp/cmj89uaibq1OKa8BJ/wWRgTMMBFVSC1CfycXNgHOYHnnp\r\nlO43H7fGLm9QM+OjbWZtro5uJI18wpzm+OF6jqQSAZZxRUnN7adYeq3ZWFhb\r\nfkvmMeFXvhjRVUDGEgR6ZvuIRxDQ/4bEN6irJE2JTukm9aF8TO512BRY34bO\r\n4/HA6Mkdvmd4G0vZKEzQ+lEmRYsetCFpLbA=\r\n=PBIs\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.38491b8.1_1662489903980_0.5262746971606358"},"_hasShrinkwrap":false},"3.3.3":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"3.3.3","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"2.6.3","fusion-test-utils":"2.3.9","fusion-tokens":"2.2.8","generic-session":"0.1.2","get-port":"^5.1.1","jest":"28.1.3","jest-environment-jsdom":"28.1.3","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"2.6.3","fusion-tokens":"2.2.8"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-3.3.3.tgz","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@3.3.3","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-yfqxTv0zdKnyeevv5Am8+ZvFFq90/pd8+/rwpGyliIX/pgexLk5kHB8bFrfqmDzwQogAEmBNQKngzItAmaOikQ==","shasum":"74d6a906f24f05c860c8131dda204aa71250d685","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-3.3.3.tgz","fileCount":25,"unpackedSize":65160,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIFLCA+8DkRuUGsoE05uS+YhOpwTqFvjoK/8K40ilpl+RAiBx3yCs7HB6A3GLHpbvy2LPeGvsaRlzLA9sbgqjn6pMtA=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjF88kACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpXng/7BNijc6Au6zUj4uEtOszrFzWhig72xnZyjdGbAngcV5DkGq2o\r\nfw5ORl7GjS9vYqhn8DzGtdatXJy+eF+zGLwZp0IYYBlNgTsfuBY7BKDySm9C\r\nQ7cv/6G3ddS/SuRZvCscDzAZGuCcOsgkw7QdZG4IKGm9larDxKIWbNZru/NA\r\nIMKXw4pWh7L1JeVy4D0oaUrQo4Q7fWiUKEcVLf54Hlvw6+dAyDEmayD62MIo\r\nGxcaC/FHF/CUczY4TlD01KWcLIqLvgBIg5GA74fQI4CPSXuSzqYIgxPtL9D5\r\n71DcgPFSM5BvYccidGoKTTd/GYK2ulEt9U7rZD9tSqNIQD9YTC40Pl14mSc/\r\nB2ruJwfM1FO2UNX+mA7L76cWhIm1r8MljRZBe0s6Ou14njdJAzY0GKCHmoXq\r\nuawUOdqL53lwOtvvuADDf9cGFPALlBJUBcTvSbLT2tTiPnsZjXFCJ08runTb\r\nFidHnDK4zRVCzCOX6HmQvQheEK4np/xF0VKKwEs/Mf3s4VGyy9RnWTLdpzz9\r\nwY/2cTDc8st0cblh/uFCGwuXmw0DwQZ2mwGV/ZGX4BhDkIDzDX25eRL2h8FW\r\nEIfGcgH3jAokscHPPd1m2pfA9eyL+T/v1SOP+0Q468VCI8nlMse91akovgSp\r\np2aOtLESy3YrzCnG1ZViSk1wWacCxoJnzbY=\r\n=CB1x\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_3.3.3_1662504739821_0.673609212255994"},"_hasShrinkwrap":false},"0.0.0-canary.d248f7c.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.d248f7c.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"^0.131.0","fusion-core":"0.0.0-canary.d248f7c.0","fusion-test-utils":"0.0.0-canary.d248f7c.0","fusion-tokens":"0.0.0-canary.d248f7c.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"28.1.3","jest-environment-jsdom":"28.1.3","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.d248f7c.0","fusion-tokens":"0.0.0-canary.d248f7c.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.d248f7c.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.d248f7c.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-V7QJKL8+W3m8avK5cc+GGldU718E4p+xijol1BHlft+/esbmw4ScN0uUF3nO6fsHXyiAXBTpYHWeEiQSpGuWIg==","shasum":"c3966f0a2d0d8f176c6a0fa15506e96c76574201","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.d248f7c.0.tgz","fileCount":25,"unpackedSize":65262,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCoq6Le5m63TJFE7LOwIZKt9z6c8z03EjgrZNgmmf3e4QIhANTbFaDnC541qvwNwzJJyBf11BW9NdMg6wMXo/ERphcN"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjGTg/ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoCfw//afpBR19ZVulOL5dweF4Ocazs+jY0BTEy3ovebg3Ew6C5tPT/\r\nf/SR+pXs6wDEDA14DXM5j58AszcQY1HGyYPfuaJRi9/DG/USKNpovBw/jEa0\r\nS1Sj0VFfoD1meRGHF96z2b6c3/ipfSl4B78xfyikNGpZBrCujQyQ/jED5qXD\r\nIKC80JXf4UC7tuVNCfOYzEQuC7UQrgIXFlgi12hTCaPIM+b96iev3aW2qZAo\r\n8F+7KVACzJ0u1cMQv2T4jcGIpWDgtrHehS6ywOlqN8QpIQia3mxOyfhwT7Fq\r\n99ueThjcWCHVD/3J6djQvicWCF0ueBKEprrDLnSgWbZI2QhdnLpK1WKSbw2z\r\nz+0huneSFK0VBaUclXVWY/1K2pW0nauxT0UlTAJ4oybzgbSjbozpn+YwFGc8\r\nu5n0agP3e21wM4t8Hxdu8bhug1xuJMhZiv1H3ZpLVDQa11NUvlBKbFb5ORqN\r\nsUX/qOpli/S8L72FwykDse9P+PkTjCMX3HYbMEtowP3Mytvg1RRWUDPbkd6G\r\ng/bV0eDn/bNLPMFGn/83FAul3h4XNP6sWb0InTVsvvQBfN3wCawIJfpJEZ4P\r\naVGky1+EAEx91YsIwSx6nWYuj4CA3RutJRDnzo0l7PCDh0Jm6nnItVqA/chz\r\nuEWFhIaSpE09NJutLvPLlqE1zhH+o80yzvo=\r\n=78bG\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.d248f7c.0_1662597183393_0.5040869020444156"},"_hasShrinkwrap":false},"0.0.0-canary.c77e60d.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.c77e60d.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"0.131.0","fusion-core":"0.0.0-canary.c77e60d.0","fusion-test-utils":"0.0.0-canary.c77e60d.0","fusion-tokens":"0.0.0-canary.c77e60d.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"28.1.3","jest-environment-jsdom":"28.1.3","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.c77e60d.0","fusion-tokens":"0.0.0-canary.c77e60d.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.c77e60d.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.c77e60d.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-bmWZtHyCIdn0DyGgFbV7I8TDyNsqWUhXogg2kpfJEieJL4oNhVeNpzF2iwE/jtti1cW1YxMpBw9JkcX4nNuxfg==","shasum":"46ce5ea6ce8cc6aae03681ff337bf05a6c9a1853","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.c77e60d.0.tgz","fileCount":25,"unpackedSize":65261,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCXoqiRi1USlfeziqyFYze//8bb3bVLOhOrt7DhtmX+KQIhAJXT8tAyTbBDren85feY7ihh91Q36rfwqb24os4AGtBO"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjKjh/ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoX8w//e+cw/g9p/qLHrfyKXZGkiLjLzmv+4kNlyeqXOtZfuO8XnBmo\r\nGFMBFVmvBcmQc6YIFnMDq9xJ+31mY2VKPxWG+CW7exbdeNhvmoxC4l1GYtZs\r\nuDbPuIXmQkh0nU03GgTIZh/HiJcR/YNIdCc12TL9JtRUq34TJk45vaCltN2t\r\nZrAYYL/8znSO//gUPYI0YbyhfiJtIbVZ023hAGUZYxNbIgrSqwgkt5qHwID7\r\nDjaLlCjwdi3WxNWc/YJaeiGRBU8b0cqwS8SuBe0DmegzWSGh00OuUDzCT3JJ\r\ndxxBlxPsg+9vxVM8bdb4DgAnuOy8MsG3yxsK2ebJmKFk+xO7nuqVhtURq+5o\r\nwARm0YKcHC4sQCUbjpzDvtn1bfYGiDxnE/JJlY2Srsl5jYTRuj2Up1MO1OAM\r\n7PCxEEtP2upHM8Z9C9Qs9wPP7F5V+l+vbO+5ypMWt405+33VLLjLAhp9syZd\r\n6OylHpSjTN6Q32D/XmEdn7w/O0x5gm4pMA2GWFEcdR30cPctlKWQFgqaY+xg\r\nxRU3OwwUXoVrrvA50Q1N4BjR/H6ksgnuUlfHmqVgDhF9R10pdPvF+DMBRc/Q\r\n104p8SL+rLxneC4LG9j8vjDeGSeA5pKuJdQmkksbZ60VvZvuFtSUkuWXDMyX\r\n7EvAilk54/6yjNFxO68njizC36qsvaPHjj4=\r\n=7ZfV\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.c77e60d.0_1663711358845_0.9717956216549899"},"_hasShrinkwrap":false},"0.0.0-canary.5f297f6.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.5f297f6.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"0.131.0","fusion-core":"0.0.0-canary.5f297f6.0","fusion-test-utils":"0.0.0-canary.5f297f6.0","fusion-tokens":"0.0.0-canary.5f297f6.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"28.1.3","jest-environment-jsdom":"28.1.3","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.5f297f6.0","fusion-tokens":"0.0.0-canary.5f297f6.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.5f297f6.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.5f297f6.0","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-uKEfX9za6zIfBdkNKMrNpNBQWkOl+IMSp3ntXXaNsY9MMgMnl10ldq1I1MBADyCE+A4n/NsPnZA13FZJPv1dEA==","shasum":"a2cb271baac6eb6f23a080da122d1540c15a30be","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.5f297f6.0.tgz","fileCount":25,"unpackedSize":65261,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIAP1Jj6DUYmC4y8vkZTxSKNOUOOY9I44ZyFLU6tN1yDGAiBb74rMbb7pOQ3WXRfiBj/aUgP8yZbqltBqVgM6DBFVeg=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjKkF5ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmo6ow/+PH5IT/kC6d18zalGe+48xyl9eJdZkG6v80l2/xGAhhJvRWIK\r\nt40ymypgZoQqjG9H0Acj/44ueOilIf8EOx7pYhC1YQQu3YPKqulB1bXbR/MR\r\nBhO1YPELu8ghCzYVt+BsXdX1i1gKg/oOH8r6oPTxjCOBPxL14szs3+QVv66X\r\n7RS6WtuyXQrdxlCzlWdYZ8oW0LVWvnh90oJdK3SUlX6YmkpuVDMxOaLSAM/o\r\n+o49JkPP2+aXVxkFR3DBGOfI8Ols3s995/9J8E2GQjZujos3J8Ivw14PmIx0\r\n6hYM+EXzFXgm+WbVU64cSVBxzMhOx/H+LsDRMNBvLW9cI6ssTceiqRMyHEE1\r\nzhjiZeRXUGsym8+/ATehZIGhy0TuZdZFjtpQD8s+G5W4WMH5eUrpwuSi37e1\r\nEkR55dxbMg130sLPw3uIGeKkCK83Uh16nxHQJPFv7wC7anbbKuQ7PZI5OyK5\r\ncYd3qzLdOnTNd245XHy++gXdG/TdCTxnnHzPmQaZtf4Tv5dHz+AzlhER4Yzs\r\nHpjCqvqAAOCdVJ4oBpzLfjTsqYuLIJoKnQ60g4huA5Y0HRhtAOSXMAL46KWZ\r\n1F6gCExY5w03g4HnW1SLSIblwUEJg71DzN/3Oq1OgltBkbJ/LtSiR30vsCrV\r\n2F16Jt52n/fSrQTxUZ+ZnwyvjuDuc5/vkTQ=\r\n=ahH8\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.5f297f6.0_1663713657622_0.6069700783907743"},"_hasShrinkwrap":false},"3.3.4":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"3.3.4","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"0.131.0","fusion-core":"2.7.0","fusion-test-utils":"2.4.0","fusion-tokens":"2.2.9","generic-session":"0.1.2","get-port":"^5.1.1","jest":"28.1.3","jest-environment-jsdom":"28.1.3","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"2.7.0","fusion-tokens":"2.2.9"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-3.3.4.tgz","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@3.3.4","_nodeVersion":"16.13.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-FHhD5Nke1J55KHejlKfy9wy+AKgHr+mdaoSMscPWzswpODQtq7M3z6cNLhKdSVKSzL4xoYXFnGuEEs1/wHFD8Q==","shasum":"9baeea3278b58df650495ca7ea68d3dd8e7f90d7","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-3.3.4.tgz","fileCount":25,"unpackedSize":65159,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQD5AXgxkFAsz2X7lkDqyv8c5uCRdqpFcdvS8fcLzqqccgIhAOnvTwYhoQTiGLhv6WwDLeQQo+aO6W7gnyM6RJKqxXbw"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjPH0GACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpmAw/9FGYs793+JasVNpAGbUYH2Q+2oWVTGv7PjqhDnSLzonNohesS\r\ne+dmd3PbtkU06FkjsGYBAUgIs83IlIxYIUDUgKNXMeEvNS2zMBKUl5gDLE6a\r\nDVm2QIJQqVr5YBoWVPYELIaSQ6knSasDvezsu627TTKiazOm2GdEIX61kbE4\r\nNtbruwbyS8O16aZrGDf5F7RYx2tqJs2kgUu1LXsHvsNjnrSg5O6ErfjRuJzH\r\nbGEw3rdx5o9YFY1AUT4rsxhbQjQ0ZOhfWv7LnqC2dNGgxpEkjm5rcuKZ2Uxb\r\nNI0Xci/C6NaHfeMMUQ98xLZM83PaXIkqbT3SrUsUO2dnxG3iNM7kGN7KQosY\r\nVUOkcBrR+AunPOtwx9ioRjBUVGWkYwBANettjzA4u/yIj0bqQCwYV1uLCeI/\r\nu/R/CIqLsbufIt/HaRhH3XW032uamKxU3OURdbVO0osgh4uJeROpX/SbQt/X\r\nKcpayBSOTqwG0FDs7JbvuE/1J/b86zi8ncmutvzoQ8axOGn+qHyJoMu4SteM\r\no7y0ICLOJ5KyoapUbTvE2VjaKMZ81TH+HTdVAkMuHRLhFhKEWgcOQffgCbqa\r\nZcudUmc7g1Wskf1zdv27YzU7wi8oKUj0n3HcQ74xwT7gLEUqQMjNwM0OzZMX\r\nNUHNBz9cugcqP14bWappuSf47+MbOwFeSFQ=\r\n=isec\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_3.3.4_1664908550252_0.587545393331854"},"_hasShrinkwrap":false},"0.0.0-canary.df69099.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.df69099.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"0.131.0","fusion-core":"2.7.0","fusion-test-utils":"0.0.0-canary.df69099.0","fusion-tokens":"0.0.0-canary.df69099.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"28.1.3","jest-environment-jsdom":"28.1.3","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"2.7.0","fusion-tokens":"0.0.0-canary.df69099.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.df69099.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.df69099.0","_nodeVersion":"16.15.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-nwMgqQbEISWjGqvINnKnYxQpLp4tTfNxdr9a0bIQ1JDPaaUJ0qv7r0kUPtT6zrcyTdclaB6Ei8r1nPAnD5b2Og==","shasum":"77705cf3e69dfa0b8dc6c5c007316f87c8363c1d","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.df69099.0.tgz","fileCount":25,"unpackedSize":65227,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIBEhIapGhrCDh0XlnJo9vyeFvuURa3Pkm/TK32gCYgzcAiEA6tUxQT9rrpCpIvi4z4Xs7bnJaKBp/tQoD82cToDqD8o="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjRxstACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmq3yA/7BxxDKXIzwZoNTE54EmJIcRuQnRG4cXbIO+DER08nBT2IxoxI\r\nszg2g5lWk1av+hT941AlaiTjNRhdvNiuR1Ap1Vf1KoTwiiXj7VRQoNgP+WWO\r\n/flQvuzhfg2b18T9ugKenRtXmIi/d/hdO2nusteyYpHJ7lyyCgAKHhPk9cB3\r\nX7MBKPoUhYi10tTaoB/gkEHIoC2AbF4v9le+2/h8TyBuGuhrvjPmz3Pu1IH5\r\nEjm9e6r8VytgOPgvALY/u1HdkVKDuygrHBTGQRvDjPvfxdgwAOY/HSBA71xT\r\nI9077D1146HUSO7soclnTRVSXO3wfmufAzt/iWzbcQjicSLTFCGiR/+JRRGo\r\nH/Vmj4jADiUA/9IjcdVm6KO8+y3OpolUhLUX1vvlKbd2amZ1yGLVljFMWF8t\r\n+zhXA5/gvk9NU3I96L2UVQX3ndX6TDR3NF22XH8IIMe48k+x0r/lg2P8IT3j\r\nHDKxsc8u1cCZX3quAP13wxaKK9QAeOfo3zdPjk/QHW3x9p3EAtcLT+7259HR\r\nolHvrdzyugG91H0YJ9+yguZRRWYyYRTwAh/rZwmTLK4BDZ0JOzJc1JKBiHDV\r\nVE+vhM3kI5Vv9WD1a4sICwp2WoxAEliZeceR+P28X/BCNefsK/qv1YfTP3LK\r\nTsezonldz3gnyNxez+1UF9wZck3ihXpzE+c=\r\n=lf9M\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.df69099.0_1665604396977_0.24030887355072017"},"_hasShrinkwrap":false},"3.3.5":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"3.3.5","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"0.131.0","fusion-core":"2.7.0","fusion-test-utils":"2.4.1","fusion-tokens":"2.2.10","generic-session":"0.1.2","get-port":"^5.1.1","jest":"28.1.3","jest-environment-jsdom":"28.1.3","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"2.7.0","fusion-tokens":"2.2.10"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-3.3.5.tgz","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@3.3.5","_nodeVersion":"16.15.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-x3veVJgDZM4gptg/wpUazoMaOzV/mNrJ7jDQM74uhH08UdH01byleXe/Js6oktpfIcTggPKHrf2dCXv1H278GQ==","shasum":"3345b00fc1b0e01aaff726812bb9032f2eea9c37","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-3.3.5.tgz","fileCount":25,"unpackedSize":65161,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCi1I8fmcKSjTpScZm32xR6j7uT5rE0Yg9IJAYCzmHXsgIgNKWJS9b3ks/vI6/uFX7LdGjoYp5ixA0qugi25VdBZ/o="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjSbfAACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoUjxAAkymKJ7HHq/tNogX9cgmAnrwOd00es4hs3TTiCf5g+Xz+FluI\r\nQpVM2lf8jrZVBJUYnQ8iDwd5DKKU5umzCSrdhXiH9nCUFi+oeMGrzxG9uRKy\r\n1ulqByKqwONSZ8WMUftHf8sXRBd9ELvKlP8W5TEiZKrlF9Jv6WruHpzxk83B\r\n0jmExeafGbTx0evU1FyWdsNSK0zhpYkh7JcuxA4Q6QUZBYU7fS6Uy2RoiNvQ\r\nsat0Aw1h1jPwNxR6sEE02O14FjwAABz07FK0kAIY169VsSJ//9T67K49KUft\r\nPvV3sjDOk/NrWWFxOC8d+mwP5NcAV8KcCLtMAThozNkqx+K3Ae/YfMNyD6iV\r\nIXZqO8XS9FrSSPM5DU8g+tmgFFp8sufTl9T6BRWs8FYDqCHi/7gwIKiEo0lc\r\nwyceytpS05MTC+mjD6Ft1+EC7apNfPtYh7t7CgROwOgkbMwC4yBw3qIOuqus\r\naaFPCbXih2B7IEZmDFg3OVEd4xxDSarOcXnW9Ji7gDaYeyvk4+o9xLhKajlW\r\nQFITG35gfWnwE+TBZjMHN9RQGESn/NEphopxcGbQSiZtAQD+Y1f1AZE2DSan\r\n6U4nm2HIObfKzlO64PtoNv9Q7ubat+6nFmSaJRi+FGJIo6dTqBVk1yr7NbIZ\r\nLSZSGyaNlGGemuvZkArpIrhXe/mcccTIKeg=\r\n=Xo9H\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_3.3.5_1665775552214_0.7887343554478472"},"_hasShrinkwrap":false},"0.0.0-canary.7982e16.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.7982e16.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"0.131.0","fusion-core":"0.0.0-canary.7982e16.0","fusion-test-utils":"0.0.0-canary.7982e16.0","fusion-tokens":"0.0.0-canary.7982e16.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^28.1.3","jest-environment-jsdom":"^28.1.3","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.7982e16.0","fusion-tokens":"0.0.0-canary.7982e16.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.7982e16.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.7982e16.0","_nodeVersion":"16.15.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-vE85LGrEIJB8YIVthAsTMepnZmO3iVVIRtemXAjyu63u7Zn7feDxpycBxtLc7uCXY6pNVe9oxarh8m2ucb4OKw==","shasum":"d0f9313f91cfa34a980d568772e0591d6e160f44","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.7982e16.0.tgz","fileCount":25,"unpackedSize":65263,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIFhG9yDjQw5T8Au2XKnMjqLSBY93VeRgQ/UCHBOT29O5AiA9VIrj5egJJdqaf4OupiP0Q3hxvUbkCPTxC6ikijrJzA=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjYwdBACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmpr5g/+OPVyQLWGSDmixR9Unr0txh9p3Z3BhaHJ3iu8CXygi3igiK62\r\nLlHeWc4XsyS3IpFAFd3fGhsqQloUANg8dgkUqORw7UkLcz6FFaKef9cp20jI\r\nc+cnEh9sqSgDEtIgul2g8pRNH5rmwD6oB+vPe/axBaJpgwkta0Zq2qmAvg3x\r\n4uQT3BWF17JFQJqtHAEGh4Hpmq4H3U3i9zIk4uZOkmvSrT2Rn4aMqccbZ4Zd\r\n1pPGRkyvkuEEi/VF44fwE+WshjIXAMKDy0je4Pjmby0XZEY2lNxxtL7KV15C\r\nzIE+MkF92wYJ0i6dwKen1NI8MwKpveUkg5My6T1lyiF+ec3NEzZsPOVXNZ6v\r\nlffbla8U9qwuOmLY6CCT55NlmMFJdkwGzS42FzxDP9mPgPw072SGBhpwNt2l\r\nAbfpL6hnvJvLnGvXxZ0YF+cHf1i/5ErDQqcXvAbMQzhkRgv+OYqIHc3R98jD\r\nDDGWIcqhJ90avKvkGFZ6SQm5O5zg9uMpDoYJdJZhEQ2kT0J3Ya0NXu4QV/X/\r\n8Q9IqfUkpb6LiaQqfxw0JH5eFc71Mt+OJTfqUopLW/o+JDdw6s1Ce7hAEOkr\r\ndbPgF/TrRylYOrkRMv6RD3v8SL9h/eRyVtp0xP/b2R4xkneC6T3aTUU+HJaj\r\nUcfyUDM2OgsBVKJaLR0bVGVK5RphQbwUMyc=\r\n=f5Fh\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.7982e16.0_1667434304796_0.30140481311794476"},"_hasShrinkwrap":false},"3.3.6":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"3.3.6","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","body-parser":"^1.18.3","create-universal-package":"^4.1.2","express":"^4.16.4","flow-bin":"0.131.0","fusion-core":"2.7.1","fusion-test-utils":"2.4.2","fusion-tokens":"2.2.11","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^28.1.3","jest-environment-jsdom":"^28.1.3","prettier":"^2.3.0","sinon":"^7.1.1","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"2.7.1","fusion-tokens":"2.2.11"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","flow":"flow","lint":"yarn g:lint","prepack":"cup-build --force-flow","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-3.3.6.tgz","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@3.3.6","_nodeVersion":"16.15.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-1+cgM7aRW0PH32uCfV2mpSdN8w9rBkBwjl6q8e4l8LIOIZprsFdQd3464zeDabLUrL+wlTYbLEZQkLyHs2ctRw==","shasum":"cb9a634591eca45181deb1a2e12e9eba0d0000f7","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-3.3.6.tgz","fileCount":25,"unpackedSize":65163,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDdMAW/OUiqZtbm/K0z6tdM8PL4tRWA40+AMWo3gljksQIgeNKBkHoyCmmYtq81f9RuZb5EeJGn/2OacXGceyLMxV4="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjZZxQACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpBkA//TYrHb8YEqLdG3Q0qZzttAe64SPS/H7OqkX3gMwd+vKgCJ2SO\r\ngROlVDRJOKq0cWnR6zOMRIAr+sqc2pspVrrmMs2/J0dhmi0/3173NHjzlnX1\r\nDE75x1JUACO5eJQazkPbTe0ge9OEyvjeLyIDxd6Blb8BAalfVyrp50W2Ed4X\r\nLDSAKatuo2duOtRx2i6ZYu40dpR8KO9s6+JTOPNxefaaeZIBL2qfzp5pniKA\r\nZGCbTAX1+nsIceTvCGwONdtWspPpsLDjHOXxshKzLCiN1KYle3BXFGnTWQA6\r\nTAbe99bfBmkcPwol/fM/s3FPfQ09czZA8qCDqsHZgV/56B9yxrj1wC2pNVkb\r\nenhfOGdC5w+5t++kFrWOJ/3JuZUDC95CCFh25wUqUTQBWsUWMH516L6yG8g+\r\nysQW5yCptWg0CpYf+rLZgZpMvczxKh+KVpJzsx1w9vvxwx9UJYGE7dq601sW\r\niRMQ9/iOPPp3SYkRS8jM59j7oAzPZDUSgjg4FN5KrUMwY01IipqsM6YQz5+c\r\nhsZIYfisFxUnFoLlQGS88PyU+vOLCmVyOW15r+D2QwOUabZXZCEgLX5/wfCm\r\ne/EcrvJ1eMl7rTC3po29C6mHkxnlfwYUZmr3/MH6+mmi4rUbgXMWAxklIZhW\r\nWmhLZZFCh/k3e0QUtg0GzDTghWUJaUdT+BU=\r\n=bnJd\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_3.3.6_1667603535942_0.3547891712755744"},"_hasShrinkwrap":false},"0.0.0-canary.af83905.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.af83905.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","@babel/preset-typescript":"^7.15.0","@types/create-universal-package-env":"workspace:*","@types/jest":"^28.1.3","babel-jest":"^28.1.3","body-parser":"^1.18.3","create-universal-package":"^4.3.0","express":"^4.16.4","flow-bin":"0.131.0","fusion-core":"0.0.0-canary.af83905.0","fusion-test-utils":"0.0.0-canary.af83905.0","fusion-tokens":"0.0.0-canary.af83905.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^28.1.3","jest-environment-jsdom":"^28.1.3","prettier":"^2.5.1","sinon":"^7.1.1","typescript":"^4.8.4","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./lib/index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.af83905.0","fusion-tokens":"0.0.0-canary.af83905.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","lint":"yarn g:lint","prepack":"yarn tsc -b && cup-build","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.af83905.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.af83905.0","_nodeVersion":"16.15.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-37x07a3s1hgs7DHfC+J4GcrCHCvPRsp4hC6ae+d9O40jIrDy7+a1mS7Rs5a8awY/JkE/r8qNfib2U9lOuqQEEw==","shasum":"a439183cb51645acc24c6c54cb1530a9b8543941","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.af83905.0.tgz","fileCount":43,"unpackedSize":186318,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIClg+BXJgr/vumyb4CUVIWF2Tugx5auIK/HbUwUFQWtRAiEA7sZuQ7qrdofffOLZ2979Dp2tr6/tC2JsR8LZPen4c5M="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjh/9OACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmp1Dg//TtgwG16gebL7uqFPXRu6uNRXakEYuYelRUSvzHsbno27Sgjw\r\nb8j0Eal/cZgSRLrqBmz/ugImsYzVkBxWG/b8tqioEfLWiN8zh8c9y/GhSiLG\r\nK4NBn7JC/pjpXn+6M0TlsG9/NDhXzZRgBOuoqi2Qj9JPq7fL/Rr43yH995sy\r\nVLugecVk9WpudgGDjBCcljUViA5Kmo3VK1c4c5aJ4bvawD1v+Y4OF4aQ5hFm\r\nX+PQRQfaDPKCbL+s0xbFpHkoZ17T0LZ4PvJ+juEY5dpVTHuxGunn5AY/2uPz\r\nVTjOkt/6purdl1ikuuOkBQYQmWr5GSAojCksXzb8iwxnNUhoWTkIYSlfkUHE\r\nuhKeg6pFw6MnW7B0IrSq9E5aHhB9yriKSy3qJLo4FE+8fjqbYtWEl0KHY4xH\r\nQvHEimSo4oBBU/W5iBGHa0Tebuxm7Zlju7yUYkj/iZBYu0MUOCWUL5KrBE1Q\r\nJKwV73No81/1qBRl8DG952cVJViLeyHaWZ1XL4RvfDMHLBobo4fdtYppeB9a\r\nnv+qrGBT4n/FsK1TbJojwmfp0ITTDQ99OiSQ0Nv/fwF1J7BEZRY9dZU2duwa\r\njhzIGWugCyABsZxl1SyXbimwZW0VWIxg0IiWTqFfpRlI4R4IvK3PaEoqHTM6\r\nau81grkb5wN9bP9n74SipICzsx435FXFbSg=\r\n=UCZI\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.af83905.0_1669857102341_0.4750915820909489"},"_hasShrinkwrap":false},"3.4.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"3.4.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","@babel/preset-typescript":"^7.15.0","@types/create-universal-package-env":"workspace:*","@types/jest":"^28.1.3","babel-jest":"^28.1.3","body-parser":"^1.18.3","create-universal-package":"^4.3.0","express":"^4.16.4","flow-bin":"0.131.0","fusion-core":"2.8.0","fusion-test-utils":"2.5.0","fusion-tokens":"2.3.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^28.1.3","jest-environment-jsdom":"^28.1.3","prettier":"^2.5.1","sinon":"^7.1.1","typescript":"^4.9.3","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./lib/index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"2.8.0","fusion-tokens":"2.3.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","lint":"yarn g:lint","prepack":"yarn tsc -b && cup-build","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-3.4.0.tgz","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@3.4.0","_nodeVersion":"16.15.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-VAmf0ppP8l0d0ng9Qnr0qiZtmvSTnZYzHZUk6J7DeDd7SAtJJphu/b7J32rkLTCRjgvZy4F0pWgZL2NyjnAeWw==","shasum":"23c6071484ce22d42709bd7b9e4b72899d6a7fa7","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-3.4.0.tgz","fileCount":43,"unpackedSize":186208,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQC1hHW7r0//Ekqn13/KH3qHocSRGeWFKSLPggKlzcw9SAIhAIrm0GvIzn6vJqBm4r0zsMoAoOR7MC7YrU9nQMmCKSfx"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjjlXgACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpvOQ/7BlOYaPYbAmbQoaIPFizT8yLk918Ot5671BfLQREaPriNqxT1\r\ni4zL9iH6bRpbqs37H8Yv1H5NvS/kSIgQcsapYngvc8sQUTnwJR0QkJOUDDgo\r\nmUo0crKYMvxPB5xb0cQr8iSwku4T5anltN10zRjb2nXFK0cm/4+8DEbt1RRA\r\nY4VC54c650GeWCa2BEDHTOMvPOSxadFmc7XwQP9vUkJRUOs94i1aUefR4mLk\r\nGYgD4NXuoEtz7xNwMzqVeGKgZIPWOhJS6WUPpWGEqsXqDaeN3BblFppLf0Fy\r\nUirAjisBHMNNjGB8a3wyrmJLGRXJOUoJ8B+/yzaRHqpDF15e4pZmn2qIw7Ii\r\nrfRpdlrkEW/PT9EK2z/usTNRTfg/OxdyFyX6SwaWDrgyer4lbJFCogtujhQh\r\n6auSaCZ6owIQBgU3RZGwyvZKa6ugrjOlUqJMrNdW5SkSFAY8LkLxmkcUdG0Z\r\nmFn+9BslsRyz8G99EoWauy7jtlYHxRIpJmWnnSopWc6KShOoqNQwJTPmHF37\r\nrpvFft8GElkFNFeLc/jpQ//ZJRZiy27JRdQaLi512JGsaz2MznAMKo1iflxo\r\nW5vlXblH/DNLI3hZGETRHam59EI0vd7mzYYSrIF2yFrw8bLLACoP8ek+RUhV\r\nTGqF29/Cmig4Qigc3scHYrAAaLy7N8oHjKQ=\r\n=IeAQ\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_3.4.0_1670272479942_0.23043923948196965"},"_hasShrinkwrap":false},"0.0.0-canary.cc2fb77.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.cc2fb77.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","@babel/preset-typescript":"^7.15.0","@types/create-universal-package-env":"workspace:*","@types/jest":"^28.1.3","babel-jest":"^28.1.3","body-parser":"^1.18.3","create-universal-package":"^4.3.0","express":"^4.16.4","flow-bin":"0.131.0","fusion-core":"0.0.0-canary.cc2fb77.0","fusion-test-utils":"0.0.0-canary.cc2fb77.0","fusion-tokens":"0.0.0-canary.cc2fb77.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^28.1.3","jest-environment-jsdom":"^28.1.3","prettier":"^2.5.1","sinon":"^7.1.1","typescript":"^4.9.3","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./lib/index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.cc2fb77.0","fusion-tokens":"0.0.0-canary.cc2fb77.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","lint":"yarn g:lint","prepack":"yarn tsc -b && cup-build","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.cc2fb77.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.cc2fb77.0","_nodeVersion":"16.15.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-bE+ERPa0AODuVsxDQik2HEY2jTiijTBySbgHVAmWbkBz74ljcb+oNfMfUywQDSBDq+m0KdAl4kIvBSwbYtxbRg==","shasum":"e82d8c02a27d24aecc7969e1e8732f1c7295f3e3","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.cc2fb77.0.tgz","fileCount":43,"unpackedSize":186310,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIG9CWrLwpTQyzCL87NrfhQvD01Jus3ciS0P7ndME7MgnAiEA4SJommh77SVyIFRKsLlmJEMJGuWPhkCz7aGH4kDV5DU="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjjqVvACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrptQ//WBLJEtTpOPOlOYUzl4VNpfKxul5Vq2Gb5zigyxFDKeYGsP77\r\nv1RDLGjjC94kFPdOXTDa25/IUEZ+NEI652BUCC2T0rCWuRHGusfvEYFEcvgD\r\nH7yQQR3y977H1Kmyk7wJaWS9NmKnEbeNMjavxDViOBQKl9PhDceYDIOKF6Lb\r\nPmsnYYCksHG+QdfQ+JuXC8PEnaXeeb6TyJK5G3PFFebWa4j1KoiIeI4XRYy1\r\n8WMNSShbt+2igmuzFNe0T0+8bjDzLluY9ajT+V00BHnx5ri6MKk4CdHC5Zzh\r\nuyQbkgTF2RBO51sPM8mJJG6c+gaGg+GuJbpBYFREaV98hxQvlOC7StDzmUKz\r\n8IegZjfCbVFPtyOQhc2F9S3slWhSExnJjV9sXXGLexw3DBWuOM8lujrFAMol\r\npgBTi5y1kEMqjnV9FCBF+thvsEz5GFyGRChruosRq96pqr2sK68htcgIntJ1\r\ncE0+JI3oWCTNAoC4EjIBQeipH/FXhe+Ri1OSF0TTdSWrkr+cZlMvSLjnV/kk\r\nwecz7Pc5HMYeGRaIZm0BXMKUAhDJAjviWpJlQHIRlISEJQB/LHahNkF7xSI2\r\naHgbfLye5HV688SFT5tqGPyXojnO+QkZ6lLoSEUW8E8FNmOva9Oy8j20+2pR\r\nM+SUmmmK2GPElkXNeuAka7mT5Q+1x4Faez4=\r\n=J2DB\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.cc2fb77.0_1670292847104_0.804971773255952"},"_hasShrinkwrap":false},"0.0.0-canary.d18411f.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.d18411f.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","@babel/preset-typescript":"^7.15.0","@types/create-universal-package-env":"workspace:*","@types/jest":"^28.1.3","babel-jest":"^28.1.3","body-parser":"^1.18.3","create-universal-package":"^4.3.0","express":"^4.16.4","flow-bin":"0.131.0","fusion-core":"0.0.0-canary.d18411f.0","fusion-test-utils":"0.0.0-canary.d18411f.0","fusion-tokens":"0.0.0-canary.d18411f.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^28.1.3","jest-environment-jsdom":"^28.1.3","prettier":"^2.5.1","sinon":"^7.1.1","typescript":"^4.9.3","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./lib/index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.d18411f.0","fusion-tokens":"0.0.0-canary.d18411f.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","lint":"yarn g:lint","prepack":"yarn tsc -b && cup-build","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.d18411f.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.d18411f.0","_nodeVersion":"16.15.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-k5xtGSRs/SPQJrcDA0lZvh6T0rTyKb6dW9h2qhCetb/PcaG9AGVpVSAOEf8K7ifthGZdkruEBQL03p0rPcthag==","shasum":"bb5786d35a9c30574e49598276f396a4fef4e8ce","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.d18411f.0.tgz","fileCount":43,"unpackedSize":186310,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIH1dfQfSUFXSM4Lzt/v/nmTdYLqQBxPUHmx18SaFIgjyAiA5cy2ofFJ6wnxTNXO946lgqk15gS8UC9N6z8E05pnw2Q=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjjscsACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrEPQ//TZotYmVGl6iVmSmRu5t3iHfyyJBcU1hF+UTCa8eK2s7FAVRh\r\nzTywuTXrxrPTPEY14Z8U2WJeJQqQrQvMLVxTAGKarOQPJNJLbLMopeTKPl1A\r\nSDBNQSJHGawSN2gEecKZpicc+fmEZCD4UgcgerIiGeqhtyoVZ6ZyxOPSVHMW\r\nMaGdKpQJ0WZKUmYn6CgE9VriV/4Yo+TQGCcy0LCIqmyi4OMftbYFD64/Vz47\r\nHwDMB9Ivb2KDE4iZEH/mW0M6Dw5W46fQ/GREDLcng69FJgtq7z8gKkPq6K89\r\nB9VsZD0uZIFjnxeCwMH8HWM9ijvKwJy3sgguV28AT+BxwKjReFYhfHl5H5In\r\n7nAW5hKkkel02uIZ0T6Js+McgFzQIie1iCr0tsYCVXuCC1wbZziAPbsHAyQ2\r\ngHj3mKwPXXW+yYykaJGYbXSH6sr+LFfgeOCZqLYDW6r3UqHiuKGlYoeRnTxZ\r\nITDGaJsS97LV0Tyz+1S+vzFoYYPC/CUGtyCksiETMqTvO7xyTNkSJMKeTcXp\r\naX4af9rOQNikEmMmoNburokg9G2Mt3ski8qUDWDAFONKaGw0RrxpuuWhiacA\r\nAIuxRSEGiZ7NQUuTpZo2HGEWEa0X7RUB2b38LcNcbi5t/vaG8L+cYNyaFGxF\r\nga+GgkG290wnNlIf24UF1cedN91r0L1ALdk=\r\n=igpr\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.d18411f.0_1670301484627_0.4099963554927357"},"_hasShrinkwrap":false},"0.0.0-canary.7f1cb1f.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.7f1cb1f.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","@babel/preset-typescript":"^7.15.0","@types/create-universal-package-env":"workspace:*","@types/jest":"^28.1.3","babel-jest":"^28.1.3","body-parser":"^1.18.3","create-universal-package":"^4.3.0","express":"^4.16.4","flow-bin":"0.131.0","fusion-core":"0.0.0-canary.7f1cb1f.0","fusion-test-utils":"0.0.0-canary.7f1cb1f.0","fusion-tokens":"0.0.0-canary.7f1cb1f.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^28.1.3","jest-environment-jsdom":"^28.1.3","prettier":"^2.5.1","sinon":"^7.1.1","typescript":"^4.9.3","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./lib/index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.7f1cb1f.0","fusion-tokens":"0.0.0-canary.7f1cb1f.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","lint":"yarn g:lint","prepack":"yarn tsc -b && cup-build","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.7f1cb1f.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.7f1cb1f.0","_nodeVersion":"16.15.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-GeZeq5ynCGfXYPKjx6T3r/3w1RxtcOskefl/SQApdG5/F64j0UuG9BGjCClCkrvq9hwkhrqSdb74nXr8KR14MA==","shasum":"b86e498f7a07fb18df3d85681dc109ba6dd349a7","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.7f1cb1f.0.tgz","fileCount":43,"unpackedSize":186310,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIQC9Lsq0ksf7DxklQnjw1dOHML8uBGhfQqhNGKdj7rGQOgIfJrZ25D6vWZdB4SM7ddUqvft69OmqoR2f2AGjCU9wnw=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjjtwoACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqvpA//W2CDt2lo2D6OkqUoJ8ansTNoQF6ZfeQphO3pwA/40iElhiMz\r\nMDHKZsh3irRPlPDSirJD7K+4EIYM+C/g8IbveG/047w8KtEg8WsKpn+2Ivck\r\nCzlp4XAm6lx7KeSEgwlqSFhOCIgTrn69HjpWFEI2t7dy4XOR3mmYWPCTjBEb\r\n5WJsIRH17yD7EW9TNQDUWefQmb9Fg9NgoewKTTYlXtMY7fdpeZw4/qfxCtdh\r\njxP2b4xIF8p717JlkWUvU5k47VT40yvLMLC0YkdkZYogFOVin6ZKuS6/aokl\r\nuzOhm6Oy+mRt0SjQpGr3nWYKqMIu7/R/zv6wqLlpuQTfV4+MXgjM2aPVPmR6\r\nb0HfV/vreFs2YpwKGsssHXvP/yHAESCCugmKQm1sSudY3wIln57kW8B7fuHz\r\nt8VUed96xpeF2lhnLiO1ORCNLkl1FO8PXRt5YX+x+LBMMHIQxv71Mpvs3AzV\r\nx4kN4Wsm3VaFT0Mx8F33A5rXKYNrKUKQcLt9kfzekbJV2juhmroiwa6LuRdN\r\n7cKNZBPaJYd3D11AsWbihXLayB3GfV0FOKefCzfC/4DK+k8qhpRPsFY99kqa\r\ntHIM8Ibbf6QrcMG2hbaP3i/djfko4xrGR02zMD8iPrpApSq1m5bFvYFwPjYo\r\nJwvp6r8YMFiaUl3OJtZys0HyZqdJ2JQgDS8=\r\n=9zIP\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.7f1cb1f.0_1670306855865_0.3762809825881688"},"_hasShrinkwrap":false},"3.4.1":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"3.4.1","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","@babel/preset-typescript":"^7.15.0","@types/create-universal-package-env":"workspace:*","@types/jest":"^28.1.3","babel-jest":"^28.1.3","body-parser":"^1.18.3","create-universal-package":"^4.3.0","express":"^4.16.4","flow-bin":"0.131.0","fusion-core":"2.8.1","fusion-test-utils":"2.5.1","fusion-tokens":"2.3.1","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^28.1.3","jest-environment-jsdom":"^28.1.3","prettier":"^2.5.1","sinon":"^7.1.1","typescript":"^4.9.3","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./lib/index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"2.8.1","fusion-tokens":"2.3.1"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","lint":"yarn g:lint","prepack":"yarn tsc -b && cup-build","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-3.4.1.tgz","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@3.4.1","_nodeVersion":"16.15.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-EatK6LJZgOoxYpsMe8P4mmzdfzdKpjxPH8RzMIjT1NZmovlb3v5eZMHXMqYVys0+YzFhinHmYMjXXUMiBdLYPw==","shasum":"499212b63daa45ad3ca1bc387f84a7be19131681","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-3.4.1.tgz","fileCount":43,"unpackedSize":186208,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIBswbRQ+MPft4eEBJ8I8rlVdUcrDs7NX2Ljh68CgvX/QAiEAoLIaSsME3LCD2wM9YtO5WX2pkLOVS09MycZyXuE/WoQ="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjj/K3ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqMxA/8DDhqcusXkBakIm4O35ooDpnbjrYAQvojlADJOUMyQvsQMmvJ\r\nGEZz/PNg/r0c2+Tkx8ROsO5zgORnKJeb0rnhMCqLQ3DE4uUqI3k9F7n5CPWF\r\nLA1EkrsMDjBWDutXV4hi3PENdDVwoOfaoGZ2zdNFuQlA8q0Gwwcii22/8V2i\r\nSi1+IoxvhjqTdqpFqRQEwUrNcuPHSE8NhilJojpT1CjQEU9B9LCJccb9pB8c\r\nbHP5xsN+d05ydfWqcKbYSq5Y5/1IXqX/2k/pFKDWFiS/BayrSgTBIh+/oPUL\r\nBNboDei6Azb2/XzsvHvr48WAYAkCqKtZWxjK/DPGezT6iSabhhML5Y0cCLD5\r\noK2mw0gjJ8mq0y2Qk7/PjIXfABeZEy4KY4GVaxfNhKZWKalCtKVE0U/ptdV9\r\nmO49NkY14pcqYPApAIjSxjPMCYm29OE2xK+c6+Qu5e7dIwc0FnqjS7DQX/iT\r\nJJUodAtn/nlpvedZlycDIvfFBJoGqq+QFCN1QMq5CO+I66LlT0vPMLXeJpWz\r\nj4cSva/0C0PI9P2Be5JzfhxifP8tCJtC8IqjkEsQGdUSpaYnnEVEH22gkW+z\r\nDjygDbt8Lq6Necq6hD/7YdhdlH5LF9PSwxOS52Q1kY4DTKPmERHZEp8s45JR\r\nbWqgRWifmg9jt6DFCDymfsHmOMXvcMfZdVE=\r\n=DDzG\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_3.4.1_1670378167180_0.5525813696907012"},"_hasShrinkwrap":false},"0.0.0-canary.1ea3b4c.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.1ea3b4c.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","@babel/preset-typescript":"^7.15.0","@types/create-universal-package-env":"workspace:*","@types/jest":"^28.1.3","babel-jest":"^28.1.3","body-parser":"^1.18.3","create-universal-package":"^4.3.0","express":"^4.16.4","flow-bin":"0.131.0","fusion-core":"0.0.0-canary.1ea3b4c.0","fusion-test-utils":"0.0.0-canary.1ea3b4c.0","fusion-tokens":"0.0.0-canary.1ea3b4c.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^28.1.3","jest-environment-jsdom":"^28.1.3","prettier":"^2.5.1","sinon":"^7.1.1","typescript":"^4.9.3","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./lib/index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.1ea3b4c.0","fusion-tokens":"0.0.0-canary.1ea3b4c.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","lint":"yarn g:lint","prepack":"yarn tsc -b && cup-build","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.1ea3b4c.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.1ea3b4c.0","_nodeVersion":"16.15.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-iOppHzuWOa3eDi7xKbbHeuKImaw7zPgkIG3pTMjY+A5gLaSHLCHCsHtotvfxsODBacEvuyDNEk8XR83nvpFmow==","shasum":"f6053fb4faa8dbf0b31f837a256f258989b2ce30","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.1ea3b4c.0.tgz","fileCount":43,"unpackedSize":186310,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIBkKGo+XvPGNnF0yaeqDgFF91U9EcYol4y8WhUbihKaLAiA+ft85+nRxhoN7xH/Ihl4qufiO39byXIH0nfK5T213ow=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkPhUACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmreVQ//Yhzw81wfjg5XaLBZsphdV2vMdlopLnSNWKWZnOnbW64M0mUy\r\nVFt9ZdjSLKGiaavfTo0RK+3SX7Vv8XZPbU9zWAYxc42FhbSwKl95kTwLfc2b\r\nk59YvMLEJeKzT7CNlN0JZq+ME/W4FES59i+fUO/+WjJGoS4vgq/RjQvPZFcW\r\nHVwkuwBB8RyBES4HyJoTguOvDnIUkGb7fiLXKvmfFi0pwvtyR+C5Pa9bBxG1\r\nt41x64eGPmFV1olG3Illk2zKN3fMxR2hP9nbM6E66sZXy6Li1kkNXz46ktyT\r\nEtSy93A1jgaF4jGtdhEYx5pwTK66h/4mNDXI4RWOZJvbFuPxZFgA5JWYQedn\r\nWlEwjdEPOmEOLp4TN7KMG4W4bewQ/5vl8nbXAfhN4QieH6aShbMFwIdR8N0H\r\nfUcJ7TlKOxZ7i2h44SBwDrrV5UTnR5rVgfsS36c3Gx8iFiEz/1ORJSiKvpKx\r\ntUCVTjw/SFT48EhJdBurGgyUD3miRhS186rbOfVisNgcIvkGn2MGMgKoduxR\r\nYF7qpZP0BZSfgxoJjYSxVNwpF7JQBJHVWmnN7UIND5At4TXFbbUU992L1Ou5\r\nxZuj/HuQkGXc0/gu+BWuVVzeDMAjt+lUI4sdYh5Iv/alkMKTngtyzR6q1q+U\r\njh+ePfteJAxQZvJK6LR2UXsK+VYVECenhss=\r\n=1Cwa\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.1ea3b4c.0_1670445140484_0.8889271535881023"},"_hasShrinkwrap":false},"3.4.2":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"3.4.2","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.15.0","@babel/plugin-transform-flow-strip-types":"^7.14.5","@babel/preset-env":"^7.15.0","@babel/preset-react":"^7.14.5","@babel/preset-typescript":"^7.15.0","@types/create-universal-package-env":"workspace:*","@types/jest":"^28.1.3","babel-jest":"^28.1.3","body-parser":"^1.18.3","create-universal-package":"^4.3.0","express":"^4.16.4","flow-bin":"0.131.0","fusion-core":"2.8.2","fusion-test-utils":"2.5.2","fusion-tokens":"2.3.2","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^28.1.3","jest-environment-jsdom":"^28.1.3","prettier":"^2.5.1","sinon":"^7.1.1","typescript":"^4.9.3","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./lib/index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"2.8.2","fusion-tokens":"2.3.2"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","lint":"yarn g:lint","prepack":"yarn tsc -b && cup-build","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-3.4.2.tgz","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@3.4.2","_nodeVersion":"16.15.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-+yiXfy6aEcF8msJsiGaEDplR5gGpWt66B7IT6Ep8JfesOvbNzZUQZFbuKsg+/jOZYvGgq+NYuyf/yEdf4au6pg==","shasum":"9fa2bc5151bd6b2a37e80c7d48a6cf099aaa73cc","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-3.4.2.tgz","fileCount":43,"unpackedSize":186208,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCEY2vHhMcscke87q9piPt290I6UWSMAbCBvzbCoQAkywIhAITUN9RnIYOWA3w/NC8JMzsCgWgQv2AacWBdZv7q9TaV"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkTQgACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmo8ZA/+KgiNuvBf96Zr6D3q5DdchadSfmaqgHjv6FEnQo8dx5hAuGzK\r\nTPjMoMdWYtFjvHhHK6hNE/iZByN7Nbg2kGVuOBnx9aKz1i3mCkzQPQZ1dXyj\r\nvqJvje5Wlkmo8HaMaUZdWT5tbe0A63qO1tC9HadQPn22QS44ZFBopzOl7X1v\r\npYDpsQR3VViGFxKFwfxhtNK81q9YVm1vNvVTaoCMxAo/1CO2SLVwXxzgEj/x\r\nPzT6ER+HvFftKaf/bZtpypfUdzTmfI0nLb39BBwf1+Jx7XaqzBG47jPezJtX\r\nud2FRE5ptF58LDRXISVjlPppLzU0PNLLo4y1QOZ90azAs2WqSvjVXDQ1wy7+\r\nkJHPxqvfU7bn6rm0fvW3/ZQqiPY1lXLaT0keNiUcAgSTOIZ7vGavfV8g8gs7\r\nfhWmgoSseFvpKLvhPBmvpu6AvaA3CwYiKOjXOMe09knMv/GorhpEzxe9UH+W\r\noXVQVUKnQ/WoL/9tPfUkO3+u3pCxfq2U+dSpQbITzZGw5nERW+o42Y1VJ0I8\r\n59gvyO/aqmR7LTFP5K+UbVx1KscGNPMrqAmOob599CLl9Rtjsz11HFPacwRr\r\ng5Smf23EZqwnqNanqgiaJbsPgPDtADBSkZ2YqKXZTfD6PMIjHI708VjxPpI1\r\nmLBLyyH3shCjThHrCREDwLxSlhgDZ9hvadE=\r\n=gRms\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_3.4.2_1670460448107_0.9629738184994008"},"_hasShrinkwrap":false},"0.0.0-canary.f1ab874.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.f1ab874.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.20.5","@babel/plugin-transform-flow-strip-types":"^7.19.0","@babel/preset-env":"^7.20.2","@babel/preset-react":"^7.18.6","@babel/preset-typescript":"^7.18.6","@types/create-universal-package-env":"workspace:*","@types/jest":"^28.1.3","babel-jest":"^28.1.3","body-parser":"^1.18.3","create-universal-package":"^4.3.0","express":"^4.16.4","flow-bin":"0.131.0","fusion-core":"0.0.0-canary.f1ab874.0","fusion-test-utils":"0.0.0-canary.f1ab874.0","fusion-tokens":"0.0.0-canary.f1ab874.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^28.1.3","jest-environment-jsdom":"^28.1.3","prettier":"^2.5.1","sinon":"^7.1.1","typescript":"^4.9.3","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./lib/index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.f1ab874.0","fusion-tokens":"0.0.0-canary.f1ab874.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","lint":"yarn g:lint","prepack":"yarn tsc -b && cup-build","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.f1ab874.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.f1ab874.0","_nodeVersion":"16.15.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-MTF4UIbdamSOfsIUDNbdq7KpCvvn9rx9Lomdydu3uZDiDYq3Z8b5cvryGjGywoRzjEyitO0xix7DCV04WhcyvQ==","shasum":"56ff388247712e3512ac3ebd03a18494a942e10e","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.f1ab874.0.tgz","fileCount":43,"unpackedSize":186310,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCTQnFdpCi+yEw4xU4cgabsGNkV6C9jNg4SraduoI9aPAIhAMNur5jEkayyFcGG0vO2INNWYqhmgQkREIsLT8D2sk4E"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjl4pXACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmopKhAAlj8eHE5CqgRfDqKxg41NKR9njFPNGNM81QrpBE8GrSvjCIht\r\nxTqjY86HpA7Givtwt1FSRiNhkBgEWdbMai44eqnxr5vNEvcQYiVjCHcoXDm4\r\nnooUoyAR74ZiaZesOXbKTC2nhrfj4JMpc6s4vO/sckakcIykQWVtia1o8+QD\r\nGSjq0GNy39tgBdWdpKhJIxuEGBRDFcj/aqSKVwIVXj/xAWgW8t37I2iqj1eq\r\nYCFaREZjQVC9ppRuyyKQYXOy5afUeTK7Y+HZf8/OBRwdq0atWkVTVzu1GRLz\r\nfYqSWNXNQt+mN2aPfStgpjR5BRmjQjQXIQ2VQ6N0lGfXDwBZZtExao6eOcgy\r\nQADqGVeA+lO2PenrVvb9rLSD2kex/5XZQ1OgAQHhB2KihQyrdg+osKus4ZsL\r\nOb3fyp67ynMnvvK5+OKGWXl/bPM0xGkF2ZQNYxwgAcv8+oVXroNnmApeoMc4\r\n/7p5druSqlOzi54XKzmAEXSIQFHE+g9wYJD7PirnnEdThGfM7ZziS0TPJPGG\r\nox/LHfQNXAvgewMBYdUMxMagIEoSVtb9g/THvAk/5PM4TnkuaLmI0t1gOk5+\r\n1bwsHNBYtmvjrXVgEShp/Xa8wkqF5BN7zuuG+wdgJoQeY3Q+arQSXIUNT7X0\r\ntrHFBlEJgvEwqjeCprP29SyeBz0RQqez+dI=\r\n=n4Uh\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.f1ab874.0_1670875735581_0.21544221005385022"},"_hasShrinkwrap":false},"3.4.3":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"3.4.3","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.20.5","@babel/plugin-transform-flow-strip-types":"^7.19.0","@babel/preset-env":"^7.20.2","@babel/preset-react":"^7.18.6","@babel/preset-typescript":"^7.18.6","@types/create-universal-package-env":"workspace:*","@types/jest":"^28.1.3","babel-jest":"^28.1.3","body-parser":"^1.18.3","create-universal-package":"^4.3.0","express":"^4.16.4","flow-bin":"0.131.0","fusion-core":"2.8.3","fusion-test-utils":"2.5.3","fusion-tokens":"2.3.3","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^28.1.3","jest-environment-jsdom":"^28.1.3","prettier":"^2.5.1","sinon":"^7.1.1","typescript":"^4.9.3","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./lib/index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"2.8.3","fusion-tokens":"2.3.3"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","lint":"yarn g:lint","prepack":"yarn tsc -b && cup-build","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-3.4.3.tgz","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@3.4.3","_nodeVersion":"16.15.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-mZV6Sp498ztPHA4fy64O8yk3YFaYpLil5bpwxMQJGyde2vl7ou5nw2p2GLx2thcCAtgkNmKamnIVY6t1EHrhrA==","shasum":"7fcd40950b08d1f86b39f6293ace2f996f863a62","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-3.4.3.tgz","fileCount":43,"unpackedSize":186208,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDJQeVn+Urox0dQTBIRxQmMS10VSPyUV6sOCG3ollncAgIhAPD1hN7wVH4dYToqXVZqXCPjY8Y1OAycBr8HXfYhFL7D"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjnPN0ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoedA/5AeXY7/6rXD+UJNLeH5WrqiZhnFCgQZrDyLLHh61h6vbCJ9hk\r\nuPkSpoIDEDp3MyfEU5HByAG1NAXplYn+6Vywnjr9wqNfdg0LwgJw/VhejlTQ\r\nS+PqSm7OPg8BVrv6cWrfTf9p4a2DKco+px2aXdW7ElLOikGZ1QZ24xD9LRTQ\r\n3RbIwYfdL5ho1mz5EolsjSbqHKt/CcWLKbeJlnNR0AgwGnLgBowGQ8yXh+4G\r\nrsf+2+3/ksDawzpoDzH101YqYnVP2Mnb6KL3DVhdf9B291U8Axlt+jgIiBWr\r\nP+NJ/5zXqtcsiSJBACXaC8W933Iwh+qsnITqC6IVLsaITM0EpNMWaoku3JyM\r\nH4lJzaMPVWjvm6BA1ErQxeCu2c0M2bm9orMWnnre8FlIifujJsKT93DkXQRz\r\nZD1nWUKbXDgrFLwec/u3K85da637DHwosUFpfDPIYO4R4guFEOa7EjKN1PI2\r\n7xNYsrNnrwiqGvCXSJgIiCqzZ8pj7HOVCqlM5cC/1Ki/QXkPF0OYrd0CJm3+\r\niruCgyPhmSh8T1OSMiZ/PA6X2SIOxSWgbQ66nIdrFhWZytgyFHTyTLwpXTqw\r\np/f+WRghub/Sb5CyS+sPii0kahp2H63UVEtewMAkq8kQ8YImXylBCCPsnH3i\r\nF8UwJXGstWIbQ6FMIpk/y6/9mPjEFw4GtuA=\r\n=U5V6\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_3.4.3_1671230324415_0.6734666878555062"},"_hasShrinkwrap":false},"3.4.4":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"3.4.4","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.20.5","@babel/plugin-transform-flow-strip-types":"^7.19.0","@babel/preset-env":"^7.20.2","@babel/preset-react":"^7.18.6","@babel/preset-typescript":"^7.18.6","@types/create-universal-package-env":"workspace:*","@types/jest":"^28.1.3","babel-jest":"^28.1.3","body-parser":"^1.18.3","create-universal-package":"^4.3.0","express":"^4.16.4","flow-bin":"0.131.0","fusion-core":"2.9.0","fusion-test-utils":"2.5.4","fusion-tokens":"2.4.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^28.1.3","jest-environment-jsdom":"^28.1.3","prettier":"^2.5.1","sinon":"^7.1.1","typescript":"^4.9.3","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./lib/index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"2.9.0","fusion-tokens":"2.4.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","lint":"yarn g:lint","prepack":"yarn tsc -b && cup-build","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-3.4.4.tgz","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@3.4.4","_nodeVersion":"16.15.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-2c4z7WZDVHqtw7RL7cCp+IgGe/jCUIsra0mhKlu8Vw1/kOtIWprKoJeW2heGdOtzZXcuOgZzY41jAqCv1vhVPg==","shasum":"261f9e8fe456449b70d4c58c712b47e539a6cb6d","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-3.4.4.tgz","fileCount":43,"unpackedSize":186823,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIHu1mduDTMoqRhqZE7EPkATUP38Ge3rDE6lnmNLQENpiAiEA7+zBW+2b+OrF6Zrot3vOW4AvYY0lp5nS6xrdBtgiIdU="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJj0H1rACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmoa9A//ZtGBId2bgWcRhPDtZZ+VsyL06w8gSXpD4aLqQmsHop6bKDd/\r\ngovmTY1WqAp6PA4SwfDUt1bktJyNP0+52H3ZPM2V66EoEGPgohUCAhV8GYli\r\nNqc1E/dtNQr3Q8m7Wc3lVxa+9d0QsXec152pXMRVNeuxUT0scJ4ujWdgEkc5\r\nxAE8dReXkYfYlKA5RTUu+8rArWJA9Dv8AmaebQ+UvgavsvN7mVfUY7opfN+X\r\noDX8EQmhUR/Is3yLUrbz4iUuDVleUuP6sgjk1BDmXg0hPgpXdtBsNtN4qPrO\r\nfK3H8t+0ZnbJxYebsyMAeLlwgqLKKzzlDE6YerVHCeEHdPRjTrYIGNwWOy+P\r\nirB9uWCHKsIz6X8Yf1lJ0ahqYyPe0zIjujdUFNN/ASYnvhbHXUCiU8Qq9p0R\r\n1PKnOKjlWj8w3jZtjHitfctTTaIoWZU/eVP9jeEzZgkpXZ7Ej+p7nA9qEJbM\r\nkmFrQWS4WTrkqWxvm+vmcyOPZuTqq6AfO0rzAnq7+wXTgFchefk1pYU9rVj2\r\nVoX1ofC5HyRbMEhAe+SvRsJdzVEI/uh5GUzRe+Ht6t5qrYdkHP7qOV8K6umg\r\nLdsELD50HZvFQOgTxw6PQsOR17OIlPz5g3yz3qC4nWq9MNgB87i2bBkxxXpD\r\nfbthLZ1tdgk8po+WO3f9ipv5Ha0J2SmyVc0=\r\n=3rlm\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_3.4.4_1674607979634_0.6230112647554151"},"_hasShrinkwrap":false},"3.4.5":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"3.4.5","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.20.5","@babel/plugin-transform-flow-strip-types":"^7.19.0","@babel/preset-env":"^7.20.2","@babel/preset-react":"^7.18.6","@babel/preset-typescript":"^7.18.6","@types/create-universal-package-env":"workspace:*","@types/jest":"^28.1.3","babel-jest":"^28.1.3","body-parser":"^1.18.3","create-universal-package":"^4.3.0","express":"^4.16.4","flow-bin":"0.131.0","fusion-core":"2.9.0","fusion-test-utils":"2.6.0","fusion-tokens":"3.0.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^28.1.3","jest-environment-jsdom":"^28.1.3","prettier":"^2.5.1","sinon":"^7.1.1","typescript":"^4.9.3","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./lib/index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"2.9.0","fusion-tokens":"3.0.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","lint":"yarn g:lint","prepack":"yarn tsc -b && cup-build","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-3.4.5.tgz","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@3.4.5","_nodeVersion":"16.15.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-cvabOiQfOxft4u5HdLvUfS7p1b1UlV2x5XCDEO4GCImNWn9ldlTVIFVcgxYH9fBS5LxaEqjq6wc6UXPVpdySZQ==","shasum":"9246c067640e1aebdc8785b90aeeafab5cf2c754","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-3.4.5.tgz","fileCount":43,"unpackedSize":186823,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQC1RE4kzt4xx2MEfGtjv1XxffA848gIjubV1xtNQa25OgIgJGM8C8Uc1vQyGIJFmwfpn9D3xIIaooC9gNcPeoWhBXg="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJj2tOMACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmo5HQ/9EdfWe90VRDZUEuEdLSocRdk1VRPrgyJRFydHUPdGdrUoQaR8\r\nDu9FNvnblI2eA62mJnBsF3DPjWqIetLeBq4U0plFQPhOrC/Oyh+IX/BT6PjV\r\nMYT8pN4i139TIhLT5uVK4YSVOOGNANF+h6gz4MADpUDmpXco9qjRDzl6Zmbc\r\naDX9dv5VdcaO1mkFvO+dN/cz9jx5QNMQHbEmY5m19SlHFnROIt1NuocmDKmF\r\nV8xGpvBHSygEWzV3aM0Y4NJqhq19QDl9CIUY9W81Ggd6kR4rMBUctY1Z6yEQ\r\nXJyL9IXd762xwDl8Uo0rrtFPMVPFT9zQX4sYb1XGUsAU2dH9nyRE4ZCPoWmg\r\ndFZEmvFrgLs6hj63uKIlPiVA25H9TvXK+SQuVtJl0SR18qTC5Io2nJQLwnlR\r\n6XFTw4MAwcDbFFWjV7vCLheWwxpphAPflorK+976SQ2XkW/hce4+Gv9m0BMr\r\nBIPMvUGeDhixnxfeL3eY7DGRlP3zx2v1q2r7lvrjs68jma7IWbWqeJiMPZZC\r\n2hgKzQlbhS+7oHvYAEjGuecH+qPS01j6G5RKE+Rorbr91P97Lx+8vITycxIA\r\nmObUC9AHJbs6p2pMARr+FL5jVZRobcc3YbGsczwYZ5iJEyEi88RHHHC2W7HX\r\nvVY5Ere622Fr5Rm727v0eRhf6GMtA9JIFOk=\r\n=KSj4\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_3.4.5_1675285388730_0.7996806586703658"},"_hasShrinkwrap":false},"3.4.6":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"3.4.6","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.20.5","@babel/plugin-transform-flow-strip-types":"^7.19.0","@babel/preset-env":"^7.20.2","@babel/preset-react":"^7.18.6","@babel/preset-typescript":"^7.18.6","@types/create-universal-package-env":"workspace:*","@types/jest":"^28.1.3","babel-jest":"^28.1.3","body-parser":"^1.18.3","create-universal-package":"^4.3.0","express":"^4.16.4","flow-bin":"0.131.0","fusion-core":"2.10.0","fusion-test-utils":"2.6.1","fusion-tokens":"3.0.1","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^28.1.3","jest-environment-jsdom":"^28.1.3","prettier":"^2.5.1","sinon":"^7.1.1","typescript":"^4.9.3","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./lib/index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"2.10.0","fusion-tokens":"3.0.1"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","lint":"yarn g:lint","prepack":"yarn tsc -b && cup-build","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-3.4.6.tgz","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@3.4.6","_nodeVersion":"16.15.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-u+If5kcuFmMkNkXtXkDomzQ5tX4aekg8mNrnauvkRratfItKgy4OW7kNFAF4+j5lcAS24uGJLEchfNfJsySyGA==","shasum":"6699e4511331ad59d6e495649822315b7738d1e0","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-3.4.6.tgz","fileCount":43,"unpackedSize":186825,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIEpMQLQ0Viy6qRXMIGhWPaFQkJAGgyAognseaneduFXRAiEAgLgADxtgnBgN40JydZe8etK/n3M93sh3D37o8h57mqM="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJj5E8cACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmoj0BAAlzfb+o2/wnDMr1knXANvt7ULPg+HYEDb8Hq5Rp4dKY9fIJ3+\r\njrphE7CrgGEkScXXNiqgQCfzftQR5LlR6pSBUJ0zwsaku8EReIA1nsVowOf+\r\nBEt7AiYtQzvVY3sdH4SfXBimza3sCoDtg7Uo0/nEUkT6dWbNatiD6d60fL4m\r\nIrvhwso51frohj8YUFeD0LJY6hRBo32UQeb/cCXgWyXTFVVLwUjWPJLP67eh\r\no9rbZx6eUZc2p1uvPpga+rIRJPXzHJR0lbjwu1e6ceb+ckFUrIsw+dVhkqbe\r\n4eJUnKoPuBcbF+Q5L4G4pJWSgJELADLP+ExodjMKGGNETMN+slqtBRt8Xt7e\r\nRAhMG/mB/B1qOBU+KOZUsBvs/RbUJFGx+iNehpZrndvs22gdEVtj6xUqgSA6\r\nDZkb14P70P6dIfBd/HVfILxSPbuEwS1zFUYLotTqqw8qPRot/xXB5JfEJhwY\r\nj7Xs1iWAAx6nDmEz+zFGmyONEbCXqCv5iYTwkY1P+MEb0xGITyUldS1HbcBi\r\nZK9XfpNf4w7yp5J5hB1jN8D7WlG2ghXlKE2Qm9yy4KV4i7ZROk2CDOQ4bJxa\r\n/lmqaZ3Mn8OYROZTvyx+PvX1EWKUIGQK8Tqwl+zUDcyk9pNsYXFyZKiwEB2D\r\nAqYeUsWuEygwsQg430QXyo+aXfhddn39JC0=\r\n=OX13\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_3.4.6_1675906844165_0.6917907149347786"},"_hasShrinkwrap":false},"0.0.0-canary.1cbe20f.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.1cbe20f.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.20.5","@babel/plugin-transform-flow-strip-types":"^7.19.0","@babel/preset-env":"^7.20.2","@babel/preset-react":"^7.18.6","@babel/preset-typescript":"^7.18.6","@types/create-universal-package-env":"workspace:*","@types/jest":"^28.1.3","babel-jest":"^28.1.3","body-parser":"^1.18.3","create-universal-package":"^4.3.0","express":"^4.16.4","flow-bin":"0.131.0","fusion-core":"0.0.0-canary.1cbe20f.0","fusion-test-utils":"0.0.0-canary.1cbe20f.0","fusion-tokens":"0.0.0-canary.1cbe20f.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^28.1.3","jest-environment-jsdom":"^28.1.3","prettier":"^2.5.1","sinon":"^7.1.1","typescript":"^4.9.3","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./lib/index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.1cbe20f.0","fusion-tokens":"0.0.0-canary.1cbe20f.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","lint":"yarn g:lint","prepack":"yarn tsc -b && cup-build","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.1cbe20f.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.1cbe20f.0","_nodeVersion":"16.15.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-OvUAtXWRE2PibyaAedEWA1n76UY7ukPUvI3XRjjYzh1WlezvJCDMcYwqykmSWOudc4HLHX27Em9zCYCwaTFSNA==","shasum":"1794ac26ddb4c1054d38bc56f40fde31f4ab302e","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.1cbe20f.0.tgz","fileCount":43,"unpackedSize":186925,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIE/McOENenoZgdjc5ekqRU/Gw17aStkngaqtseSa39/lAiAg30ippAYGBi5WXyiCmDm33SSF0wGyyFx4adY7foxN+Q=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJj8BWhACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmqdwg/+J2s+KkXytMBA8PUDLv89F3rd+12dwrVQbPfL34BgCwldEX76\r\njMX9orfHRl+B770grpjC01uxRRoyJgWTUZyBPx5Fn4UWPgSrh5ai0JDluUs2\r\ntSLmBLRuqzgACFTpzzpLj1kIttXSF5MPvXAb76U/i17X+z4Ehyrj9B3ek3y0\r\nP849/ItuiZ3wz2vuFaMNEbps2qYfvYBSY/c9tdu/seQ/4FwCiAxkmem9H23Q\r\nRk8GGzX28l6cqfh2pG16NbN24u2bVvpNmpg6h11LuVA01GXcRC1zMghvr8Kl\r\n+ZLH07fKOHmDwG1V+JxrS7AEtJVYQaxbyEIf3DsEDRkL1yyR+54kS7d10Q6c\r\ny0poZyjxuauoMTfJ4eUvWCsJCqpW6Rm2GEq2uWLcjysBI/MKWmpoWu4zY+rI\r\n5UUKlViySCgKQlnlnAoETfL0z4MEwgyfx6LNHsFw6LdGJ3B27uPr+XbUNOy+\r\nqJzXyEya0/QLmgUbbshAOW6bi2zdMBM3NIiPS3MJ2F/+P+VNFJUxfsTrcrPE\r\nZmzxcLvYydB34Ikh8Snaoc/EydO/+exxlywLswH2wB1Yzj711k5LoSXNi1LN\r\n4AGfrs8nCYJ9i4XXBwOtha2jfL9cIpMC0n1BlDuQZVWwq7UNIItuvyD7V15n\r\njR3Yd0ETDwoxKD0eHlK8cdVR3ysmXXoL9Yk=\r\n=SEit\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.1cbe20f.0_1676678561260_0.8953918308902227"},"_hasShrinkwrap":false},"0.0.0-canary.52f9d6c.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.52f9d6c.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.20.5","@babel/plugin-transform-flow-strip-types":"^7.19.0","@babel/preset-env":"^7.20.2","@babel/preset-react":"^7.18.6","@babel/preset-typescript":"^7.18.6","@types/create-universal-package-env":"workspace:*","@types/jest":"^28.1.3","babel-jest":"^28.1.3","body-parser":"^1.18.3","create-universal-package":"^4.3.0","express":"^4.16.4","flow-bin":"0.131.0","fusion-core":"0.0.0-canary.52f9d6c.0","fusion-test-utils":"0.0.0-canary.52f9d6c.0","fusion-tokens":"0.0.0-canary.52f9d6c.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^28.1.3","jest-environment-jsdom":"^28.1.3","prettier":"^2.5.1","sinon":"^7.1.1","typescript":"^4.9.3","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./lib/index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.52f9d6c.0","fusion-tokens":"0.0.0-canary.52f9d6c.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","lint":"yarn g:lint","prepack":"yarn tsc -b && cup-build","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.52f9d6c.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.52f9d6c.0","_nodeVersion":"16.15.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-F1h/FyDc8gEOTJTFvdYwOXDERh7Bjrw34eAXUQvOzxESgXDdOrVOkyNn/RaawbHIxx7cJWOwVT3OOVjJGlGnWg==","shasum":"950f1d0c3785ec27f197674acf848d00026a2b06","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.52f9d6c.0.tgz","fileCount":43,"unpackedSize":186925,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIGHS7clUfG3LIZQZZzjXubFa8tW2VqeNPqn04lwueY/iAiBZwpVFN+7k+NJZimW5MOn2RPHtAIheGioZiyca4aYc9Q=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJj8Da/ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqB+Q/+LVq+ObxAsfXokfxRaXfZmKDGuwsmw90iZ6o1mwGYDm6mmgyc\r\na0tMe/sFiwmzLXayCwX0gPQQ4R1W+0/kunRKVhQyYtI6mmFElLyPGQPzTcj5\r\nQVoHW6snmBsV+iXG4/1MueIuNkqsOOPMCipasRgV4k2h3oPAcUCCOh/livAw\r\nC7eGVCToOzHxw0yfF5tD5O2+isSAOr6iYWKgyUJGr89vdntMmFLxmfc83twu\r\nI3GIUasdCCatP8wKjTgEDiCH/IWdj/XfeE7z1EOj4BmnSF+O+/64+HCS6QQu\r\nlyhau1aqnAatgSSP/hB0nwTKRQnfgxafB/qfwWrWbrYpjvcKI+MQJyaksHqr\r\n08FTEhtdHTEoqOm8wmzKBggD6OG0b0ACZrneEFSk5nM9trW3D2ow4mgo2H4Y\r\nx2l50B5DXvgA8ojQH5e1SgPbc+6aDMXbbfCENDZiUNxN02A7KExJpxdr4lTJ\r\nBmnAHA4s+jKHiUmm1Z4rg+lOuvED8hBu8ANq8DvyyA0qwdmhD9qDDakXEHs0\r\nN0pHrvlHeldDEE7S7PUJAAoss10kjnWxP6iwN7GmhHV5BqhgUJVQkqcpW8iy\r\n4Grf/LuVnvdSkeWtMxec8xLB9NDntzKqmM7YlwIkqu/Se1ustqxeaRh4fwJ1\r\nrQZhxR7IXEHT1AFNxGzuQL5rFBubY8x45AY=\r\n=Iwz6\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.52f9d6c.0_1676687039100_0.8816995376273804"},"_hasShrinkwrap":false},"3.4.7":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"3.4.7","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.20.5","@babel/plugin-transform-flow-strip-types":"^7.19.0","@babel/preset-env":"^7.20.2","@babel/preset-react":"^7.18.6","@babel/preset-typescript":"^7.18.6","@types/create-universal-package-env":"workspace:*","@types/jest":"^28.1.3","babel-jest":"^28.1.3","body-parser":"^1.18.3","create-universal-package":"^4.3.0","express":"^4.16.4","flow-bin":"0.131.0","fusion-core":"2.11.0","fusion-test-utils":"2.6.2","fusion-tokens":"3.0.2","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^28.1.3","jest-environment-jsdom":"^28.1.3","prettier":"^2.5.1","sinon":"^7.1.1","typescript":"^4.9.3","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./lib/index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"2.11.0","fusion-tokens":"3.0.2"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","lint":"yarn g:lint","prepack":"yarn tsc -b && cup-build","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-3.4.7.tgz","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@3.4.7","_nodeVersion":"16.15.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-5CTa2Pst3a8OLunZM69bKrwGsjcySBv6BxYHTR1yar8AVLQjGsl1BkHAypgvWOAkDIsy4BR9Nm7V/kKsrpwtqg==","shasum":"c9972aa92253bce4b8b43dd499520c8aeb264e53","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-3.4.7.tgz","fileCount":43,"unpackedSize":186825,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDXGCFT3HirC7c5rEcrOTs4Sj4bycaAJkCQTCP2UI1LdwIhAOj9OUCWlwGPvEQlzJMc8wIP+sF0DSTPNcSTzlIzWnOb"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJj89tIACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoS0A/7BN30jCHzoWSk2+9M9jWV96N0Zln00HOY2L+92PIRzHEWiGXy\r\nQ5oIdA4ie304RnGBTDlmyOgqcdTYhzjQYAC9J+7fyuwMH2CeI5kVp1KNmH8p\r\nTT/Sg7TumLVHv6GnxEXZG3Mu5gnP0ISCym//t9vhj5HZmDmBZQAxVd7kp3lb\r\n4T9CSvgfif+t3oYzagu1JCGYQeQqIlR5n6BEds1GConkLqr8bUTQQ3i1Rewy\r\n+hXQSnXq+5miwqM+8/2apfdmZpaWOfmY0rHEFHBSHitMJ4cm8iTEGZC6gRCf\r\nt/iQcpQUTzOHqvrBfE3V6EtRjwnTCDjwHSUbBL6mqlmkYSq9kE15SzGIjHd2\r\nIE4TLI5WqjLOldDBd4Gt6m49KtGF3no4S6ctOiEXBdy040jwARWQtaMopZ7m\r\n73GncKP1wZWzLcMtlBUTCz+aN6neZ3IYC+1UHlyrZ3GWAn8pG+8FdTuzs0W1\r\njMb7IgUtgeBWvkLpWRzJR1UfW6R2rDC6ZVDOVxa+8+6QL0D9rh4Br7fhHKkq\r\n/iOGzE7j4Z7lr4qVobDKanC4iISyOQhurraDq2JrFFBLrrIqhcyVnbJwtsA/\r\nSjoZY6PJ6lIF2n5GHjllDI6wCxzK5EGLyggt70F255MmnNXClzpkgmyj6/sd\r\nIZD5FxoxV17rwFoIYEwgiht2FPY2DfTw09E=\r\n=h/qZ\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_3.4.7_1676925768521_0.02270856516609543"},"_hasShrinkwrap":false},"0.0.0-canary.ca778ef.0":{"name":"fusion-plugin-csrf-protection","description":"Generic CSRF-protection utility for use with any session manager or csrf secret/token generator","version":"0.0.0-canary.ca778ef.0","browser":{"./dist-node-cjs/index.js":"./dist-browser-cjs/index.js","./dist-node-esm/index.js":"./dist-browser-esm/index.js"},"dependencies":{"base64-url":"^2.2.0"},"devDependencies":{"@babel/core":"^7.20.5","@babel/plugin-transform-flow-strip-types":"^7.19.0","@babel/preset-env":"^7.20.2","@babel/preset-react":"^7.18.6","@babel/preset-typescript":"^7.18.6","@types/create-universal-package-env":"workspace:*","@types/jest":"^28.1.3","babel-jest":"^28.1.3","body-parser":"^1.18.3","create-universal-package":"^4.3.0","express":"^4.16.4","flow-bin":"0.131.0","fusion-core":"0.0.0-canary.ca778ef.0","fusion-test-utils":"0.0.0-canary.ca778ef.0","fusion-tokens":"0.0.0-canary.ca778ef.0","generic-session":"0.1.2","get-port":"^5.1.1","jest":"^28.1.3","jest-environment-jsdom":"^28.1.3","prettier":"^2.5.1","sinon":"^7.1.1","typescript":"^4.9.3","whatwg-fetch":"3.0.0"},"engines":{"node":">=8.9.4","npm":">=5.0.0","yarn":">=1.0.0"},"homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","main":"./dist-node-cjs/index.js","types":"./lib/index.d.ts","module":"./dist-node-esm/index.js","peerDependencies":{"fusion-core":"0.0.0-canary.ca778ef.0","fusion-tokens":"0.0.0-canary.ca778ef.0"},"repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"scripts":{"clean":"cup-clean","lint":"yarn g:lint","prepack":"yarn tsc -b && cup-build","test":"jest"},"sideEffects":false,"_resolved":"","_integrity":"","_from":"file:fusion-plugin-csrf-protection-0.0.0-canary.ca778ef.0.tgz","readme":"# fusion-plugin-csrf-protection\n\n[![Build status](https://badge.buildkite.com/7a82192275779f6a8ba81f7d4a1b0d294256838faa1dfdf080.svg?branch=master)](https://buildkite.com/uberopensource/fusionjs)\n\nProvides a modified `fetch` that is automatically secure against CSRF attacks for non-idempotent HTTP methods.\n\nThis enhancer handles CSRF protection by adding a server side middleware that checks for a valid CSRF token on\nrequests for non-idempotent HTTP methods (e.g. POST).\n---\n\n### Table of contents\n\n* [Installation](#installation)\n* [Usage](#usage)\n* [Setup](#setup)\n* [API](#api)\n  * [Registration API](#registration-api)\n    * [`CsrfProtection`](#csrfprotection)\n    * [`FetchToken`](#fetchtoken)\n  * [Dependencies](#dependencies)\n    * [`CsrfIgnoreRoutesToken`](#csrfignoreroutestoken)\n  * [Service API](#service-api)\n\n---\n\n### Installation\n\n```sh\nyarn add fusion-plugin-csrf-protection\n```\n\n### Usage\n\n```js\nimport {createPlugin} from 'fusion-core';\nimport {FetchToken} from 'fusion-tokens';\n\nconst pluginUsingFetch = createPlugin({\n  deps: {\n    fetch: FetchToken,\n  },\n  provides: ({fetch}) => {\n    return {\n      getUser: () => {\n        return fetch('/get-user');\n      }\n    }\n  },\n});\n```\n\n### Setup\n\n```js\n// src/main.js\nimport React from 'react';\nimport {FetchToken} from 'fusion-tokens';\nimport App from 'fusion-react';\nimport CsrfProtectionEnhancer, {\n  CsrfIgnoreRoutesToken,\n} from 'fusion-plugin-csrf-protection';\nimport fetch from unfetch;\n\nexport default () => {\n  const app = new App(<div></div>);\n  app.register(FetchToken, fetch);\n  app.enhance(FetchToken, CsrfProtectionEnhancer);\n  // optional\n  __NODE__ && app.register(CsrfIgnoreRoutesToken, []);\n}\n```\n\n### Usage with React\n\nAssuming this plugin has already been registered, `fetch` can be consumed from React via `useService` (React v16.8+ required):\n\n```js\nimport {useService} from 'fusion-react';\nimport {FetchToken} from 'fusion-tokens';\n\nfunction Component() {\n  const fetch = useService(FetchToken);\n\n  // ...\n}\n```\n\nSee `useService` docs in `fusion-react` for more information.\n\n### API\n\n#### Registration API\n\n##### `CsrfProtectionEnhancer`\n\n```js\nimport CsrfProtectionEnhancer from 'fusion-plugin-csrf-protection';\n```\n\nThe CSRF protection enhancer. Typically, it should be used to enhance the [`FetchToken`](#fetchtoken).\n\nThis enhances the `FetchToken` and provides the [fetch api](#service-api) and a server side middleware for validating CSRF requests.\n\n##### `FetchToken`\n\n```js\nimport {FetchToken} from 'fusion-tokens';\n```\nThe canonical token for an implementation of `fetch`. This CSRF plugin is generally registered as an enhancer on that token.\nFor more, see [the fusion-tokens repo](https://github.com/fusionjs/fusionjs/tree/master/fusion-tokens#fetchtoken).\n\n#### Dependencies\n\n##### `CsrfIgnoreRoutesToken`\n\n```js\nimport {CsrfIgnoreRoutesToken} from 'fusion-plugin-csrf-protection';\n```\n\nA list of routes to ignore csrf protection on. This is rarely needed and should be used with caution.\n\n**Types**\n\n```js\ntype CsrfIgnoreRoutes = Array<string>;\n```\n\n**Default value**\n\nEmpty array `[]`\n\n#### Service API\n\n```js\nconst response: Response = fetch('/test', {\n  method: 'POST',\n})\n```\n\n`fetch: (url: string, options: Object) => Promise` - Client-only. A decorated `fetch` function that automatically does pre-flight requests for CSRF tokens if required.\n\nSee https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API for more on the fetch api.\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"},"_id":"fusion-plugin-csrf-protection@0.0.0-canary.ca778ef.0","_nodeVersion":"16.15.0","_npmVersion":"6.14.15","dist":{"integrity":"sha512-r7fxuB2X1Lag2+zOftsy2kuwChge2Q0MmqeWfsQrXyGmZosuL6QIYo/gCyuFGFmGLk+ymr1jKoxXTfWW7TXxcQ==","shasum":"cfe1986b928f0d691ab01e10dd08bf7ca1e89e1a","tarball":"https://registry.npmjs.org/fusion-plugin-csrf-protection/-/fusion-plugin-csrf-protection-0.0.0-canary.ca778ef.0.tgz","fileCount":43,"unpackedSize":186925,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCICP6CRNe35xcu75Na3bAh8llHDdRMeVUaCQQo+lV93f+AiArjcmyTJIkLySwKUcq8YZJ8ngkdpi3jSNInstIJny4XQ=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJj/9SzACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqxVQ//eHYqTrezBmfl/uI7lxTyiw+Q+rImtA+F7wPFp7z0Hufet8bc\r\nmxsvo7i2ZYjbN4MyUjccnUqmlX5hrHCI+fDoKTNG1vGK24dO9J9OPb2Ylvg+\r\n9dEjsiP7nWWNdxEuy1w9ZNwbbBvoCjdG0FfyQNvX11NlhpSOIhnTIzmI4PDc\r\nPKG1DPn+WC6hXgA1llqEGUC4PkmZOIzaNpJyI3GSF8sBQOloytodrgb51bC/\r\nvF+a4wClcvAigc0EQWBsro0DW5NJ8G6DADYixSLjftC2lbAZbalsu71nX3Y/\r\nTYK9ILlbfCmdybgEDznutGcd+O6OLob/OG12Ncg15d/JVFGCx6vA9r3BQEcZ\r\nRGHl9g/hnvcvR/xNpXiOPPScQ/08/FKZIxbSZ6fF51wkU0AejpCwUb4PaSW5\r\n0ikzbnGgDVIo/RFPcIoVQnhzNG9sOU3BQvC4iGB3yBuAR5fJ4eOxfYpWDckj\r\nDhAalDaSsP78+S9dwYoJP5vK/In+PRrI8ck0AXf1G+eOjm7Ae8rpoGGrpGo1\r\n1TzUQjr+Z6tTvVU75l+iMt0Rp87fe8CxImMQ1vm6maHFbbjMVtrdLTRqvuot\r\niL2vz42WshmqI0jF8yhgEU0sePuwT1dzn7DntdN2gB5vKXVrkQShakSyYg3B\r\nnyRRuAaPRsteb6eeE2x2dADshKgUv/4N02c=\r\n=1fyH\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"fusion-ci","email":"fusionjs+ci@uber.com"},"directories":{},"maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fusion-plugin-csrf-protection_0.0.0-canary.ca778ef.0_1677710515155_0.6871268852723795"},"_hasShrinkwrap":false}},"readme":"","maintainers":[{"name":"fusion-ci","email":"fusionjs+ci@uber.com"}],"time":{"modified":"2023-03-01T22:41:55.443Z","created":"2017-10-31T19:47:59.451Z","0.1.0":"2017-10-31T19:47:59.451Z","0.1.1":"2017-10-31T20:25:22.649Z","0.1.2":"2017-11-01T00:13:05.525Z","0.1.3":"2017-11-01T01:29:43.890Z","0.1.4":"2017-11-01T19:48:27.574Z","0.1.8":"2017-11-03T02:18:09.845Z","0.2.0":"2017-11-04T01:35:33.641Z","0.2.1":"2017-11-15T21:33:57.927Z","0.2.2":"2017-12-08T19:00:47.551Z","0.3.0":"2018-01-17T22:20:00.041Z","0.3.1":"2018-01-26T21:33:31.825Z","0.3.2":"2018-01-29T21:27:05.151Z","0.3.3":"2018-01-30T22:51:23.238Z","0.3.4":"2018-02-02T19:38:22.287Z","1.0.0":"2018-02-09T22:40:00.716Z","1.0.1":"2018-02-12T18:43:08.912Z","1.0.2":"2018-02-12T22:42:17.707Z","1.0.3":"2018-05-02T22:05:59.822Z","1.0.4":"2018-07-27T00:06:46.840Z","1.0.5":"2018-08-21T06:24:11.892Z","1.0.6-1":"2018-09-01T04:49:00.537Z","1.0.6":"2018-09-07T22:58:50.048Z","1.0.7-0":"2018-09-12T20:20:09.804Z","1.0.7":"2018-09-18T00:20:58.287Z","2.0.0-0":"2018-11-02T02:32:23.371Z","2.0.0":"2018-11-13T18:09:32.966Z","2.0.1-0":"2019-03-18T20:51:38.824Z","2.0.1":"2019-03-18T23:49:49.314Z","0.0.0-canary.309a1d1.0":"2019-05-23T00:52:24.656Z","0.0.0-canary.309a1d1.1":"2019-05-23T01:32:17.996Z","0.0.0-canary.9941505.0":"2019-05-23T01:53:49.719Z","0.0.0-canary.3811188.0":"2019-05-23T22:47:07.931Z","3.0.0":"2019-05-23T23:03:42.173Z","0.0.0-canary.872b547.0":"2019-05-24T17:13:43.776Z","0.0.0-canary.fd5a750.0":"2019-06-06T18:36:16.646Z","0.0.0-canary.4e310bc.0":"2019-06-06T20:08:00.355Z","0.0.0-canary.5bf099f.0":"2019-06-06T23:35:50.425Z","0.0.0-canary.2fb1140.0":"2019-06-07T18:02:33.909Z","0.0.0-canary.d9a277c.0":"2019-06-07T18:25:10.099Z","0.0.0-canary.9b5e4cf.0":"2019-06-08T00:43:00.302Z","0.0.0-canary.43352f4.0":"2019-06-10T18:55:50.393Z","0.0.0-canary.43352f4.1":"2019-06-10T18:57:39.170Z","0.0.0-canary.4fb3fa6.0":"2019-06-10T19:04:16.061Z","0.0.0-canary.4fb3fa6.1":"2019-06-10T23:31:19.422Z","0.0.0-canary.72a6835.0":"2019-06-11T00:26:39.167Z","0.0.0-canary.af0fe55.0":"2019-06-11T16:58:34.412Z","0.0.0-canary.af0fe55.1":"2019-06-11T18:21:19.909Z","0.0.0-canary.1131efb.0":"2019-06-11T18:40:20.171Z","0.0.0-canary.2fcf0b5.0":"2019-06-11T20:18:20.389Z","0.0.0-canary.2fcf0b5.1":"2019-06-11T20:23:12.725Z","0.0.0-canary.c237758.0":"2019-06-12T00:19:01.320Z","0.0.0-canary.8c0849b.0":"2019-06-12T03:24:20.851Z","0.0.0-canary.0b1303b.0":"2019-06-12T16:49:59.073Z","0.0.0-canary.7cfc88b.0":"2019-06-12T17:03:23.762Z","0.0.0-canary.b7caf15.0":"2019-06-12T21:06:07.232Z","0.0.0-canary.b7caf15.1":"2019-06-12T21:25:54.924Z","0.0.0-canary.8ae44a5.0":"2019-06-12T22:19:56.388Z","0.0.0-canary.8ae44a5.1":"2019-06-12T22:25:54.866Z","0.0.0-canary.51752cd.0":"2019-06-13T00:12:32.741Z","0.0.0-canary.27245f3.0":"2019-06-13T17:41:31.558Z","0.0.0-canary.3703af8.0":"2019-06-14T03:04:18.928Z","0.0.0-canary.3703af8.1":"2019-06-14T15:16:48.708Z","0.0.0-canary.d93b398.0":"2019-06-14T16:36:31.013Z","0.0.0-canary.d0b5703.0":"2019-06-14T21:48:14.093Z","0.0.0-canary.801e47f.0":"2019-06-17T16:26:15.514Z","0.0.0-canary.63145f9.0":"2019-06-18T00:17:09.819Z","3.0.1":"2019-06-18T00:37:09.125Z","0.0.0-canary.407b8e4.0":"2019-06-26T20:30:13.236Z","0.0.0-canary.ed79452.0":"2019-06-27T18:54:13.517Z","0.0.0-canary.3e2cc31.0":"2019-06-28T17:48:30.832Z","0.0.0-canary.5c3b351.0":"2019-07-01T21:39:19.598Z","0.0.0-canary.16ee004.0":"2019-07-01T23:16:04.408Z","0.0.0-canary.69d2497.0":"2019-07-03T18:12:43.562Z","0.0.0-canary.69d2497.1":"2019-07-03T18:16:45.419Z","3.0.2":"2019-07-03T22:18:47.545Z","0.0.0-canary.98adb08.0":"2019-07-08T22:04:26.868Z","0.0.0-canary.016f954.0":"2019-07-09T00:34:29.263Z","0.0.0-canary.1ddabc1.0":"2019-07-09T18:22:24.338Z","0.0.0-canary.1ddabc1.1":"2019-07-09T18:25:53.340Z","0.0.0-canary.40eb0a5.0":"2019-07-09T20:04:08.743Z","0.0.0-canary.40eb0a5.1":"2019-07-09T20:07:49.899Z","0.0.0-canary.fbfd207.0":"2019-07-10T18:26:33.976Z","0.0.0-canary.4c30d33.0":"2019-07-10T21:09:04.437Z","0.0.0-canary.4cb9c2b.0":"2019-07-11T17:13:25.508Z","0.0.0-canary.b0e5994.0":"2019-07-11T23:24:33.641Z","0.0.0-canary.50aa07c.0":"2019-07-12T16:18:22.985Z","0.0.0-canary.0a4669b.0":"2019-07-12T19:53:42.959Z","0.0.0-canary.0a4669b.1":"2019-07-12T20:15:26.199Z","0.0.0-canary.3b5ed2f.0":"2019-07-12T20:44:05.176Z","0.0.0-canary.db655de.1":"2019-07-16T01:07:10.091Z","0.0.0-canary.396f8bb.0":"2019-07-16T18:16:04.105Z","0.0.0-canary.66cfac0.0":"2019-07-16T19:07:01.350Z","0.0.0-canary.403f456.0":"2019-07-17T00:54:43.674Z","0.0.0-canary.ec8188c.0":"2019-07-17T15:54:15.712Z","0.0.0-canary.e9f07ef.0":"2019-07-22T16:56:38.672Z","0.0.0-canary.fc2bf62.0":"2019-07-22T20:09:44.539Z","0.0.0-canary.a8de467.0":"2019-07-22T22:12:14.905Z","0.0.0-canary.a8de467.1":"2019-07-22T22:18:14.538Z","0.0.0-canary.02195f4.0":"2019-07-23T03:17:39.525Z","0.0.0-canary.da2cfec.0":"2019-07-23T16:34:58.383Z","0.0.0-canary.14b4f0e.0":"2019-07-23T17:38:33.097Z","0.0.0-canary.0953f07.0":"2019-07-23T21:50:29.379Z","0.0.0-canary.471a10b.0":"2019-07-24T17:13:36.753Z","0.0.0-canary.9dc742c.0":"2019-07-24T17:13:46.268Z","0.0.0-canary.fbc7ca5.0":"2019-07-24T21:47:06.056Z","0.0.0-canary.08790d0.0":"2019-07-24T22:57:01.326Z","0.0.0-canary.17cfc1d.0":"2019-07-24T22:58:04.918Z","0.0.0-canary.d0e4cd8.0":"2019-07-24T22:58:50.008Z","0.0.0-canary.6499178.0":"2019-07-25T01:04:33.279Z","0.0.0-canary.47d3251.0":"2019-07-25T06:08:32.078Z","0.0.0-canary.1b63aac.0":"2019-07-25T20:33:32.643Z","0.0.0-canary.675492e.0":"2019-07-25T22:44:27.974Z","0.0.0-canary.a8af54e.0":"2019-07-26T03:08:46.488Z","0.0.0-canary.4a47f03.0":"2019-07-26T18:43:04.888Z","0.0.0-canary.88403d8.0":"2019-07-30T23:57:14.095Z","0.0.0-canary.96b08c1.0":"2019-07-31T20:38:25.908Z","0.0.0-canary.631e52a.0":"2019-08-01T16:12:07.230Z","3.0.3":"2019-08-01T18:03:46.932Z","0.0.0-canary.bdd94ac.0":"2019-08-01T18:37:10.941Z","0.0.0-canary.ca9c1e7.0":"2019-08-02T19:09:36.107Z","0.0.0-canary.36c6897.0":"2019-08-05T20:10:17.999Z","0.0.0-canary.87693bb.0":"2019-08-06T17:59:52.363Z","0.0.0-canary.87693bb.1":"2019-08-06T18:00:17.870Z","0.0.0-canary.73b3b7a.0":"2019-08-06T21:08:34.012Z","0.0.0-canary.3a6c203.0":"2019-08-06T22:21:46.317Z","0.0.0-canary.b30cfc9.0":"2019-08-06T23:12:12.936Z","0.0.0-canary.d1e11d1.0":"2019-08-06T23:34:55.876Z","0.0.0-canary.d1e11d1.1":"2019-08-06T23:40:18.635Z","0.0.0-canary.465e7e1.0":"2019-08-07T00:11:09.709Z","0.0.0-canary.465e7e1.1":"2019-08-07T00:15:19.930Z","0.0.0-canary.465e7e1.2":"2019-08-07T00:16:01.022Z","0.0.0-canary.bd48967.0":"2019-08-07T23:29:13.283Z","0.0.0-canary.aa5bec0.0":"2019-08-08T01:52:19.909Z","0.0.0-canary.4c8e718.0":"2019-08-09T19:31:55.027Z","0.0.0-canary.e3270dd.0":"2019-08-12T17:40:31.457Z","0.0.0-canary.73f956e.0":"2019-08-13T19:13:48.610Z","0.0.0-canary.1e7190d.0":"2019-08-14T23:20:24.228Z","0.0.0-canary.b102bb9.0":"2019-08-15T20:22:47.061Z","0.0.0-canary.ffb0ab3.0":"2019-08-19T16:28:10.505Z","3.0.4":"2019-08-19T21:23:27.711Z","0.0.0-canary.e2fcadb.0":"2019-08-22T21:24:42.959Z","0.0.0-canary.d767d28.0":"2019-08-23T18:18:46.154Z","0.0.0-canary.c189a42.0":"2019-08-23T20:29:33.117Z","0.0.0-canary.aa40d96.0":"2019-08-27T01:42:33.673Z","0.0.0-canary.a9d6e7c.0":"2019-08-27T17:01:40.556Z","0.0.0-canary.f608c58.0":"2019-08-27T20:37:18.717Z","0.0.0-canary.9d5ef83.0":"2019-08-29T17:31:05.894Z","0.0.0-canary.096185d.0":"2019-08-29T21:10:33.551Z","0.0.0-canary.d78b7bb.0":"2019-08-29T21:44:37.630Z","0.0.0-canary.2a2b83b.0":"2019-08-30T19:55:22.105Z","0.0.0-canary.a0f0132.0":"2019-09-04T22:53:55.159Z","0.0.0-canary.109b061.0":"2019-09-05T16:37:12.288Z","0.0.0-canary.66d82db.0":"2019-09-05T16:37:59.922Z","3.0.5":"2019-09-05T20:13:53.398Z","0.0.0-canary.413f404.0":"2019-09-16T18:37:22.069Z","0.0.0-canary.c0ad947.0":"2019-09-16T20:31:18.694Z","0.0.0-canary.08011c5.0":"2019-09-16T20:55:17.869Z","0.0.0-canary.a27ac53.0":"2019-09-16T22:22:13.602Z","0.0.0-canary.ff793d9.0":"2019-09-17T00:06:40.478Z","0.0.0-canary.2925a25.0":"2019-09-18T04:42:46.785Z","0.0.0-canary.49d4d79.0":"2019-09-19T22:58:59.220Z","0.0.0-canary.d4b0b6c.0":"2019-09-19T23:46:40.875Z","0.0.0-canary.5be6a00.0":"2019-09-20T00:28:00.205Z","0.0.0-canary.dd07585.0":"2019-09-20T01:08:48.958Z","0.0.0-canary.22593cf.0":"2019-09-20T01:15:24.683Z","0.0.0-canary.a911dd9.0":"2019-09-20T17:20:23.968Z","0.0.0-canary.67e33d8.0":"2019-09-20T18:30:35.774Z","0.0.0-canary.d787a1d.0":"2019-09-23T19:32:43.959Z","0.0.0-canary.a399454.0":"2019-09-24T17:35:45.277Z","3.0.6":"2019-09-24T18:38:38.622Z","0.0.0-canary.acb5af0.0":"2019-09-25T21:14:38.776Z","0.0.0-canary.d7c5910.0":"2019-10-30T20:45:51.515Z","0.0.0-canary.f12f055.0":"2019-10-30T22:11:22.679Z","0.0.0-canary.0b935d0.0":"2019-10-30T22:11:41.358Z","0.0.0-canary.37af1b2.0":"2019-11-05T05:28:06.115Z","0.0.0-canary.e3078c3.0":"2019-11-05T21:28:22.795Z","0.0.0-canary.f8e4f0b.0":"2019-11-11T19:15:50.841Z","0.0.0-canary.0af264b.0":"2019-11-12T01:40:18.819Z","0.0.0-canary.78c977f.0":"2019-11-12T17:51:49.609Z","0.0.0-canary.0af264b.1":"2019-11-12T20:27:27.881Z","0.0.0-canary.cdf3e91.0":"2019-11-12T21:07:11.777Z","0.0.0-canary.55945c5.0":"2019-11-13T00:00:00.655Z","3.0.7":"2019-11-13T20:29:17.468Z","0.0.0-canary.08a30a3.0":"2019-11-19T20:07:54.375Z","0.0.0-canary.602f682.0":"2019-11-20T23:33:25.946Z","0.0.0-canary.b4d0561.0":"2019-11-21T01:30:36.224Z","0.0.0-canary.f16f299.1":"2019-11-22T20:02:07.260Z","0.0.0-canary.9dca7da.0":"2019-11-23T01:51:57.803Z","3.0.8":"2019-11-25T19:57:01.721Z","0.0.0-canary.2dbfb1d.0":"2019-11-25T22:51:07.652Z","0.0.0-canary.777f2cc.0":"2019-11-26T00:37:07.354Z","0.0.0-canary.6e4e073.0":"2019-12-05T18:18:35.374Z","0.0.0-canary.b7558a7.0":"2019-12-06T00:12:53.330Z","0.0.0-canary.f55f645.0":"2019-12-06T17:49:33.920Z","0.0.0-canary.a1f34dc.0":"2019-12-06T19:49:59.878Z","0.0.0-canary.17b7929.0":"2019-12-09T21:22:22.275Z","0.0.0-canary.e266b31.0":"2019-12-09T21:27:49.480Z","0.0.0-canary.2e98cc9.0":"2019-12-11T03:43:47.340Z","0.0.0-canary.c4b78ee.0":"2019-12-11T20:22:04.198Z","0.0.0-canary.87d361c.0":"2019-12-12T00:45:39.037Z","0.0.0-canary.32cd5ea.0":"2019-12-14T01:21:10.864Z","0.0.0-canary.8057c37.0":"2019-12-17T18:11:50.518Z","0.0.0-canary.4d95fad.1":"2019-12-19T23:15:37.913Z","0.0.0-canary.39fc7dc.0":"2019-12-26T21:35:38.042Z","0.0.0-canary.549dba2.0":"2020-01-07T01:02:09.490Z","0.0.0-canary.69f275d.0":"2020-01-07T23:48:37.708Z","0.0.0-canary.1d2aed6.0":"2020-01-09T00:10:58.282Z","0.0.0-canary.7ed789a.0":"2020-01-09T01:20:53.333Z","0.0.0-canary.cd789cd.0":"2020-01-10T21:12:39.903Z","0.0.0-canary.ee6892e.0":"2020-01-10T21:59:41.857Z","0.0.0-canary.abffccd.0":"2020-01-11T00:42:07.344Z","0.0.0-canary.b94debb.0":"2020-01-11T01:22:38.235Z","3.0.9":"2020-01-14T00:45:13.869Z","0.0.0-canary.659c743.0":"2020-01-22T19:47:49.234Z","0.0.0-canary.df13289.0":"2020-01-23T01:56:20.226Z","0.0.0-canary.79c5c12.0":"2020-01-23T19:25:07.220Z","0.0.0-canary.3a8e24a.0":"2020-01-23T22:51:31.724Z","0.0.0-canary.55e2075.0":"2020-01-24T00:52:02.411Z","0.0.0-canary.294feb4.0":"2020-01-24T22:30:11.307Z","0.0.0-canary.5c80f83.0":"2020-01-27T18:58:31.752Z","0.0.0-canary.cdb104d.0":"2020-01-28T00:26:40.351Z","0.0.0-canary.1db323f.0":"2020-01-28T00:45:06.194Z","0.0.0-canary.aaaf2fa.0":"2020-01-28T02:29:58.321Z","0.0.0-canary.fed6152.0":"2020-01-28T07:49:35.242Z","0.0.0-canary.971253d.0":"2020-01-28T08:06:44.098Z","0.0.0-canary.659c743.1":"2020-01-28T08:54:31.473Z","0.0.0-canary.dcf8c03.1":"2020-01-28T23:05:37.710Z","0.0.0-canary.4fc2099.0":"2020-01-29T06:24:28.358Z","0.0.0-canary.2917daa.0":"2020-01-29T17:57:56.288Z","3.1.0":"2020-01-29T19:52:06.539Z","0.0.0-canary.97698d3.0":"2020-01-29T22:25:09.984Z","0.0.0-canary.69bc71d.0":"2020-01-31T03:02:30.035Z","0.0.0-canary.fa2f39f.0":"2020-01-31T19:22:37.136Z","0.0.0-canary.1d3504b.0":"2020-01-31T22:00:38.813Z","0.0.0-canary.2effc34.0":"2020-01-31T22:44:51.407Z","0.0.0-canary.deed5b0.0":"2020-02-01T02:19:00.933Z","0.0.0-canary.3088ca8.0":"2020-02-03T21:13:37.979Z","0.0.0-canary.9a71266.0":"2020-02-03T21:21:26.293Z","0.0.0-canary.9a71266.1":"2020-02-03T21:42:31.809Z","0.0.0-canary.9a71266.2":"2020-02-03T22:07:22.995Z","0.0.0-canary.d07e1e4.0":"2020-02-04T18:48:06.379Z","0.0.0-canary.05b1cf5.0":"2020-02-04T18:57:18.165Z","0.0.0-canary.986cea9.0":"2020-02-04T21:39:36.338Z","0.0.0-canary.b8a6237.0":"2020-02-05T18:29:52.053Z","0.0.0-canary.2c705b4.0":"2020-02-05T20:59:36.537Z","0.0.0-canary.4b659af.0":"2020-02-05T21:16:56.681Z","0.0.0-canary.96e8674.0":"2020-02-05T21:26:53.838Z","0.0.0-canary.96e8674.1":"2020-02-05T21:36:50.968Z","0.0.0-canary.96e8674.2":"2020-02-05T21:48:07.364Z","0.0.0-canary.b640602.0":"2020-02-05T23:21:54.553Z","0.0.0-canary.b640602.1":"2020-02-05T23:34:32.946Z","0.0.0-canary.2ef1293.0":"2020-02-05T23:54:21.587Z","0.0.0-canary.2ef1293.1":"2020-02-06T01:15:44.611Z","0.0.0-canary.2467727.0":"2020-02-06T19:13:57.849Z","0.0.0-canary.ccad833.0":"2020-02-06T19:52:56.925Z","0.0.0-canary.e70cabc.0":"2020-02-07T22:35:21.333Z","0.0.0-canary.ed74fa2.0":"2020-02-08T00:10:45.786Z","0.0.0-canary.b127562.0":"2020-02-11T01:19:57.337Z","0.0.0-canary.fee0408.0":"2020-02-11T20:50:24.820Z","0.0.0-canary.9dededf.0":"2020-02-11T21:48:11.162Z","0.0.0-canary.9dededf.1":"2020-02-11T21:52:44.152Z","0.0.0-canary.9dededf.2":"2020-02-11T21:59:57.571Z","0.0.0-canary.9dededf.3":"2020-02-11T22:02:29.774Z","0.0.0-canary.a0a3534.0":"2020-02-13T00:24:33.722Z","0.0.0-canary.513dcf4.0":"2020-02-13T00:47:48.558Z","0.0.0-canary.b276aaf.0":"2020-02-13T18:59:10.353Z","0.0.0-canary.a8e624c.0":"2020-02-14T00:13:50.846Z","0.0.0-canary.2661049.0":"2020-02-14T01:40:04.147Z","0.0.0-canary.2661049.1":"2020-02-14T01:49:16.205Z","0.0.0-canary.7eb4e1e.0":"2020-02-14T20:17:21.262Z","0.0.0-canary.5e59509.0":"2020-02-19T00:14:22.388Z","0.0.0-canary.062c690.0":"2020-02-19T01:44:54.956Z","0.0.0-canary.c9627c1.0":"2020-02-19T02:17:50.127Z","0.0.0-canary.48ddc5e.0":"2020-02-19T23:33:30.410Z","0.0.0-canary.119a885.0":"2020-02-20T19:04:14.313Z","0.0.0-canary.9908539.0":"2020-02-20T22:59:59.700Z","0.0.0-canary.5386f4d.0":"2020-02-24T16:26:54.563Z","3.1.1":"2020-02-25T19:06:44.077Z","0.0.0-canary.74cf916.0":"2020-04-09T20:34:10.669Z","0.0.0-canary.5a76e33.0":"2020-04-14T01:21:08.745Z","0.0.0-canary.8de64d7.0":"2020-04-14T19:53:59.299Z","0.0.0-canary.d9ad58b.0":"2020-04-15T06:37:27.618Z","0.0.0-canary.9049f58.0":"2020-04-16T04:19:31.663Z","0.0.0-canary.1f389e4.0":"2020-04-16T17:40:55.132Z","0.0.0-canary.952803d.0":"2020-04-16T19:09:36.542Z","0.0.0-canary.0813b9b.0":"2020-04-18T00:13:32.454Z","0.0.0-canary.0cd5338.0":"2020-04-20T21:50:18.451Z","0.0.0-canary.e8742f5.0":"2020-04-20T22:53:50.294Z","0.0.0-canary.e794932.0":"2020-04-20T22:56:10.198Z","0.0.0-canary.e8742f5.1":"2020-04-20T22:59:29.098Z","0.0.0-canary.7debfaa.0":"2020-04-20T23:53:33.041Z","0.0.0-canary.840675c.0":"2020-04-21T02:08:02.865Z","0.0.0-canary.a3a7eac.0":"2020-04-21T17:13:53.280Z","0.0.0-canary.f69e6b0.0":"2020-04-22T18:44:31.616Z","0.0.0-canary.1850336.0":"2020-04-22T22:13:16.326Z","0.0.0-canary.2dbdc73.0":"2020-04-23T00:27:50.003Z","0.0.0-canary.7379dad.0":"2020-04-23T00:48:21.062Z","0.0.0-canary.22b9ab8.0":"2020-04-24T19:25:07.034Z","0.0.0-canary.69f59b4.0":"2020-04-24T20:59:45.568Z","0.0.0-canary.3d209a6.0":"2020-04-24T21:54:13.182Z","0.0.0-canary.70b95a2.0":"2020-04-24T23:48:26.427Z","0.0.0-canary.99a4452.0":"2020-04-25T18:30:42.068Z","0.0.0-canary.649174e.0":"2020-04-27T20:27:06.186Z","0.0.0-canary.99a4452.2":"2020-04-28T18:50:03.980Z","0.0.0-canary.649174e.1":"2020-04-28T18:51:32.919Z","0.0.0-canary.2450eb8.0":"2020-04-28T19:03:07.286Z","0.0.0-canary.2450eb8.1":"2020-04-28T19:04:19.478Z","0.0.0-canary.3b3b756.0":"2020-04-29T00:29:25.443Z","0.0.0-canary.3b3b756.3":"2020-04-29T01:54:10.404Z","0.0.0-canary.45a5f32.0":"2020-04-30T22:10:22.327Z","0.0.0-canary.45a5f32.1":"2020-05-04T17:54:55.339Z","3.1.2":"2020-05-04T22:50:38.888Z","0.0.0-canary.4e80a7c.0":"2020-08-27T22:23:33.095Z","0.0.0-canary.4d0772e.0":"2020-08-29T00:06:22.001Z","0.0.0-canary.8a530ea.0":"2020-08-29T01:16:13.998Z","0.0.0-canary.3915f48.0":"2020-09-04T21:10:12.894Z","0.0.0-canary.b3c0cf8.0":"2020-09-09T17:39:17.117Z","0.0.0-canary.42048ff.0":"2020-09-11T07:30:51.467Z","3.1.4":"2020-09-16T23:16:52.064Z","0.0.0-canary.a457e26.0":"2020-09-18T16:19:35.736Z","0.0.0-canary.a457e26.1":"2020-09-18T16:25:32.653Z","0.0.0-canary.877a3bd.1":"2020-09-18T21:48:51.855Z","0.0.0-canary.877a3bd.0":"2020-09-21T17:16:58.290Z","0.0.0-canary.4c67dce.0":"2020-09-23T20:58:05.270Z","0.0.0-canary.ffc634d.0":"2020-09-29T22:22:54.576Z","3.1.5":"2020-09-30T20:19:27.879Z","0.0.0-canary.4123cce.0":"2020-10-22T20:57:31.010Z","0.0.0-canary.17e330d.0":"2020-10-27T00:16:56.255Z","0.0.0-canary.318c08c.0":"2020-10-30T17:13:35.489Z","0.0.0-canary.e74b783.0":"2020-11-04T19:05:22.634Z","0.0.0-canary.a33a9c8.0":"2020-11-06T19:59:40.407Z","0.0.0-canary.5a2a7a7.0":"2020-11-07T00:06:20.832Z","0.0.0-canary.77061d0.0":"2020-11-09T19:06:16.819Z","0.0.0-canary.89ca12c.0":"2020-11-10T19:45:14.501Z","3.1.6":"2020-11-13T19:12:34.248Z","0.0.0-canary.770d485.0":"2020-11-13T21:24:42.869Z","0.0.0-canary.6d664ad.0":"2020-12-16T22:50:30.656Z","0.0.0-canary.579111b.0":"2020-12-17T03:11:06.457Z","0.0.0-canary.2eb76df.0":"2020-12-17T03:50:28.427Z","3.1.7":"2021-01-05T03:06:12.673Z","0.0.0-canary.4cee1e1.0":"2021-01-05T21:46:56.375Z","0.0.0-canary.b936566.0":"2021-01-20T20:17:26.033Z","0.0.0-canary.7d3770e.0":"2021-01-20T20:58:52.752Z","0.0.0-canary.c848126.0":"2021-01-28T21:28:23.751Z","0.0.0-canary.7eef88a.0":"2021-03-10T17:41:21.347Z","3.1.8":"2021-03-12T00:54:17.091Z","0.0.0-canary.5086770.0":"2021-03-12T03:27:14.146Z","0.0.0-canary.243e09c.0":"2021-03-18T23:31:07.284Z","0.0.0-canary.156446a.0":"2021-04-02T22:38:40.507Z","0.0.0-canary.bda3eb5.0":"2021-04-07T20:53:45.338Z","0.0.0-canary.7852906.0":"2021-04-08T22:16:20.370Z","0.0.0-canary.36c1f93.0":"2021-04-12T14:53:01.664Z","0.0.0-canary.147decc.0":"2021-04-13T17:11:00.550Z","0.0.0-canary.481456c.0":"2021-04-13T21:59:26.000Z","0.0.0-canary.4d2f7e5.0":"2021-04-13T23:16:49.600Z","0.0.0-canary.9158df6.0":"2021-04-14T14:26:59.226Z","0.0.0-canary.c68f2d4.0":"2021-04-14T19:04:14.013Z","0.0.0-canary.fa4dd7d.0":"2021-04-14T22:01:43.925Z","3.1.9":"2021-04-16T22:16:17.781Z","0.0.0-canary.60586e2.0":"2021-05-17T15:04:16.341Z","0.0.0-canary.b3081dd.0":"2021-05-21T22:00:52.002Z","3.1.10":"2021-05-25T00:36:11.261Z","0.0.0-canary.9b92a54.0":"2021-06-03T23:20:31.700Z","0.0.0-canary.d88c6ff.0":"2021-06-04T01:10:41.535Z","0.0.0-canary.f50f438.0":"2021-06-12T00:06:13.085Z","0.0.0-canary.dc6dd20.0":"2021-06-14T19:46:05.253Z","0.0.0-canary.66de151.0":"2021-06-15T02:27:03.994Z","3.1.11":"2021-06-16T21:38:04.847Z","0.0.0-canary.cc30c9b.0":"2021-07-27T01:41:58.282Z","0.0.0-canary.e5a3019.0":"2021-07-27T23:38:54.245Z","0.0.0-canary.74b8151.0":"2021-07-28T01:36:14.854Z","0.0.0-canary.53b58e6.0":"2021-07-28T18:26:33.455Z","0.0.0-canary.53b58e6.1":"2021-07-29T05:01:15.642Z","0.0.0-canary.d9ecd19.0":"2021-07-30T19:00:21.047Z","0.0.0-canary.f0b60b1.0":"2021-08-12T22:23:31.400Z","3.1.12":"2021-08-17T17:39:11.222Z","0.0.0-canary.0833d86.0":"2021-08-31T17:57:41.079Z","0.0.0-canary.009cb5f.0":"2021-09-01T01:22:34.928Z","0.0.0-canary.34f1f86.0":"2021-09-01T21:07:45.437Z","0.0.0-canary.0f75d56.0":"2021-09-01T22:18:16.200Z","0.0.0-canary.addd6fb.0":"2021-09-02T00:55:37.129Z","0.0.0-canary.e938140.0":"2021-09-08T17:23:40.208Z","0.0.0-canary.04ebbff.0":"2021-09-10T17:13:25.549Z","0.0.0-canary.77d64ce.0":"2021-09-16T22:02:20.883Z","3.2.0":"2021-09-17T16:58:21.316Z","0.0.0-canary.a5335ef.0":"2021-11-08T21:56:06.941Z","0.0.0-canary.99bcfaa.0":"2021-11-15T22:38:06.661Z","0.0.0-canary.858e9e0.0":"2021-11-16T00:45:14.256Z","0.0.0-canary.940ae04.0":"2021-11-17T00:17:01.694Z","0.0.0-canary.61befa0.0":"2021-11-17T21:50:06.758Z","0.0.0-canary.358ea34.0":"2021-11-23T14:25:45.091Z","0.0.0-canary.0585b99.0":"2021-11-23T19:50:21.146Z","0.0.0-canary.4d4635d.0":"2021-11-23T21:01:40.517Z","0.0.0-canary.4457a44.0":"2021-11-23T21:24:49.426Z","3.2.1":"2021-11-24T22:34:50.580Z","0.0.0-canary.69a107c.0":"2021-12-06T23:43:45.342Z","0.0.0-canary.c638cb0.0":"2021-12-07T21:51:02.224Z","3.2.2":"2021-12-09T20:46:23.387Z","0.0.0-canary.6c63a07.0":"2022-01-03T21:52:25.048Z","0.0.0-canary.2fa3949.0":"2022-01-04T22:08:29.769Z","3.2.3":"2022-01-28T19:32:03.493Z","0.0.0-canary.2961969.0":"2022-03-22T18:07:05.548Z","0.0.0-canary.5dafecb.0":"2022-03-23T22:58:25.199Z","0.0.0-canary.f10290c.0":"2022-03-24T03:07:31.114Z","0.0.0-canary.4b95c4d.0":"2022-03-27T08:18:23.594Z","0.0.0-canary.ba7901a.0":"2022-03-28T04:43:57.052Z","0.0.0-canary.53e71c9.0":"2022-03-28T05:38:05.123Z","3.2.4":"2022-03-31T00:11:31.195Z","0.0.0-canary.04f01d4.0":"2022-03-31T16:24:35.990Z","0.0.0-canary.0115aaa.0":"2022-03-31T21:53:03.544Z","0.0.0-canary.3fd760c.0":"2022-04-01T16:55:41.793Z","0.0.0-canary.d90d4e6.0":"2022-04-01T18:31:14.805Z","0.0.0-canary.0c6b102.0":"2022-04-05T01:58:59.808Z","0.0.0-canary.a48714f.0":"2022-04-05T20:13:14.468Z","0.0.0-canary.48261a2.0":"2022-04-05T21:51:05.043Z","0.0.0-canary.e4a0af5.0":"2022-04-05T22:48:31.161Z","0.0.0-canary.a5387d7.0":"2022-04-06T16:13:32.018Z","0.0.0-canary.4f43ddb.0":"2022-04-11T04:08:57.348Z","0.0.0-canary.f865478.0":"2022-04-12T06:02:34.644Z","0.0.0-canary.901e6a9.0":"2022-04-12T06:30:02.950Z","0.0.0-canary.5f75a67.0":"2022-04-12T06:47:09.819Z","0.0.0-canary.66acb26.0":"2022-04-18T05:59:56.080Z","0.0.0-canary.0abc031.0":"2022-04-18T22:58:11.593Z","0.0.0-canary.4fa95ac.0":"2022-04-19T22:00:22.962Z","0.0.0-canary.483ee52.0":"2022-04-20T20:16:49.368Z","0.0.0-canary.c2e995a.0":"2022-04-21T00:24:29.009Z","0.0.0-canary.03b7f8c.0":"2022-04-21T17:59:13.794Z","3.2.5":"2022-04-25T22:01:54.498Z","0.0.0-canary.d9125fa.0":"2022-04-26T00:27:40.632Z","0.0.0-canary.9081ecc.0":"2022-05-01T03:48:35.804Z","0.0.0-canary.82afe51.0":"2022-05-04T01:12:16.518Z","0.0.0-canary.3afacb1.0":"2022-05-04T07:39:22.523Z","0.0.0-canary.dc38594.0":"2022-05-06T01:34:02.534Z","0.0.0-canary.9bf73bd.0":"2022-05-09T00:10:37.508Z","0.0.0-canary.0d8f1cb.0":"2022-05-10T01:46:38.242Z","3.3.0":"2022-05-16T22:24:40.730Z","0.0.0-canary.441c97e.0":"2022-05-17T01:06:35.926Z","0.0.0-canary.94de910.0":"2022-05-17T07:57:26.933Z","0.0.0-canary.a8535bf.0":"2022-05-17T21:24:41.834Z","0.0.0-canary.7805140.0":"2022-05-18T02:48:30.792Z","0.0.0-canary.c454879.0":"2022-05-19T19:36:39.412Z","3.3.1":"2022-05-20T01:39:00.927Z","0.0.0-canary.234cdec.1":"2022-05-26T04:02:04.627Z","0.0.0-canary.ce07ef1.0":"2022-05-29T07:39:12.628Z","0.0.0-canary.6d29913.0":"2022-06-03T06:07:41.459Z","0.0.0-canary.eac89e2.0":"2022-06-03T07:25:31.858Z","0.0.0-canary.c36b35a.0":"2022-06-03T22:13:41.450Z","0.0.0-canary.7c27df5.0":"2022-06-14T20:19:27.175Z","0.0.0-canary.8894dd7.0":"2022-06-15T23:00:27.520Z","0.0.0-canary.5378c1f.0":"2022-06-24T23:07:33.869Z","0.0.0-canary.e08ad19.0":"2022-07-06T01:05:05.649Z","0.0.0-canary.57962c1.0":"2022-07-06T22:15:44.648Z","3.3.2":"2022-07-21T18:41:56.088Z","0.0.0-canary.a682711.0":"2022-08-16T20:39:32.273Z","0.0.0-canary.47148f0.0":"2022-08-17T20:32:58.150Z","0.0.0-canary.2645e7a.0":"2022-08-24T18:44:12.042Z","0.0.0-canary.38491b8.0":"2022-09-06T18:44:47.439Z","0.0.0-canary.38491b8.1":"2022-09-06T18:45:04.294Z","3.3.3":"2022-09-06T22:52:20.033Z","0.0.0-canary.d248f7c.0":"2022-09-08T00:33:03.541Z","0.0.0-canary.c77e60d.0":"2022-09-20T22:02:39.041Z","0.0.0-canary.5f297f6.0":"2022-09-20T22:40:57.804Z","3.3.4":"2022-10-04T18:35:50.469Z","0.0.0-canary.df69099.0":"2022-10-12T19:53:17.207Z","3.3.5":"2022-10-14T19:25:52.415Z","0.0.0-canary.7982e16.0":"2022-11-03T00:11:45.008Z","3.3.6":"2022-11-04T23:12:16.157Z","0.0.0-canary.af83905.0":"2022-12-01T01:11:42.525Z","3.4.0":"2022-12-05T20:34:40.114Z","0.0.0-canary.cc2fb77.0":"2022-12-06T02:14:07.310Z","0.0.0-canary.d18411f.0":"2022-12-06T04:38:04.863Z","0.0.0-canary.7f1cb1f.0":"2022-12-06T06:07:36.113Z","3.4.1":"2022-12-07T01:56:07.325Z","0.0.0-canary.1ea3b4c.0":"2022-12-07T20:32:20.647Z","3.4.2":"2022-12-08T00:47:28.275Z","0.0.0-canary.f1ab874.0":"2022-12-12T20:08:55.790Z","3.4.3":"2022-12-16T22:38:44.618Z","3.4.4":"2023-01-25T00:52:59.854Z","3.4.5":"2023-02-01T21:03:08.941Z","3.4.6":"2023-02-09T01:40:44.381Z","0.0.0-canary.1cbe20f.0":"2023-02-18T00:02:41.471Z","0.0.0-canary.52f9d6c.0":"2023-02-18T02:23:59.274Z","3.4.7":"2023-02-20T20:42:48.714Z","0.0.0-canary.ca778ef.0":"2023-03-01T22:41:55.315Z"},"readmeFilename":"","homepage":"https://fusionjs.com/api/fusion-plugin-csrf-protection","repository":{"directory":"fusion-plugin-csrf-protection","type":"git","url":"git+https://github.com/fusionjs/fusionjs.git"},"bugs":{"url":"https://github.com/fusionjs/fusionjs/issues"}}